IP Library Granted Patent US 10,055,575
Granted Patent B2
US 10,055,575 · App. 15/135,849 · Granted Aug 21, 2018

Smart random password generation

Inventors: Neil Patrick Adams (Waterloo, CA); Lukas Sydorowski (Toronto, CA)
Assignee: BlackBerry Limited
G06F21/46H04L63/06H04L63/0823H04W12/04
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,055,575
App. No.
15/135,849
Granted
Aug 21, 2018
Kind
B2
Abstract

A method for generating a password for accessing a password-protected service is disclosed. A password requirements database and default password generation requirements are stored in a memory of a computing device. The password requirements database includes one or more service profiles, where each service profile includes an identifier for a service and an associated indication of requirements of valid passwords for the service. If the password requirements database includes a service profile associated with the password-protected service, the password is randomly generated to comply with requirements of valid passwords indicated in the service profile associated with the password-protected service; otherwise, the password is randomly generated to comply with the default password generation requirements.

Claims (63)

1. A method for generating a password, the method comprising:

storing information pertaining to one or more password requirements and one or more default password generation requirements, the information pertaining to one or more password requirements including one or more service profiles, each of the one or more service profiles including an identifier for a service and an associated indication of one or more requirements of a valid password for the service;

determining an identity of a password-protected first service based on contextual data associated with the first service that is received at a computing device;

in response to determining that the one or more password requirements include a service profile associated with the first service:

determining whether the one or more password requirements indicated in the service profile associated with the first service are up-to-date;

in response to determining that the one or more password requirements are not up-to-date, sending a request to a remote resource associated with the first service to transmit current password requirements for the first service to the computing device; and

randomly generating, by a processor of the computing device, a password to comply with the current password requirements for the first service as received from the remote resource.

2. The method of claim 1 , further comprising, if the one or more password requirements does not include a service profile associated with the first service:

generating a new service profile for the password-protected service based on the identifying information; and

storing the generated new service profile as part of the information pertaining to one or more password requirements.

3. The method of claim 2 , further comprising:

polling one or more remote resources to obtain current requirements of valid passwords for services associated with at least one of the service profiles; and

updating the information pertaining to one or more password requirements to indicate the current requirements of valid passwords for the services associated with the at least one of the service profiles.

4. The method of claim 3 , wherein the one or more remote resources are polled periodically.

5. The method of claim 3 , further comprising, prior to polling the one or more remote resources, establishing secure connections to the one or more remote resources by verifying digital certificates associated with the one or more remote resources.

6. The method of claim 1 , wherein requirements of valid passwords for a service comprise one or more rules relating to at least one of:

password length;

presence of specific types of characters in a password;

perceived password strength;

prohibited elements in a password; or

user password history.

7. The method of claim 1 , wherein randomly generating the password comprises generating the password based, at least in part, on user-defined criteria.

8. The method of claim 1 , further comprising transmitting the generated password to the password-protected service to register the generated password.

9. The method of claim 1 , further comprising receiving an input instruction via a user interface to generate the password and wherein generating the password is performed in response to receiving the input instruction.

10. An electronic device, comprising:

an input interface;

a memory;

a processor coupled to the input interface and the memory; and

a password manager for generating a password, the password manager including processor-executable instructions that, when executed, cause the processor to:

store, information pertaining to one or more password requirements and one or more default password generation requirements, the information pertaining to one or more password requirements including one or more service profiles, each of the one or more service profiles including an identifier for a service and an associated indication of one or more requirements of a valid password for the service;

determine an identity of a password-protected service first service based on contextual data associated with the first service that is received at an electronic device;

if the one or more password requirements include a service profile associated with the first service:

determine whether the one or more password requirements indicated in the service profile associated with the first service are up-to-date;

in response to determining that the one or more password requirements are not up-to-date, sending a request to a remote resource associated with the first service to transmit current password requirements for the first service to the electronic device;

randomly generate a password that complies with the current password requirements for the first service as received from the remote resource; and

if the one or more current password requirements does not include a service profile associated with the first service, randomly generate a password that complies with the default password generation requirements.

11. The electronic device of claim 10 , wherein the instructions, when executed, further cause the processor to, if the one or more password requirements does not include a service profile associated with the first service:

generate a new service profile for the password-protected service based on the identifying information; and

store the generated new service profile in the memory.

12. The electronic device of claim 11 , wherein the instructions, when executed, further cause the processor to:

poll one or more remote resources to obtain current requirements of valid passwords for services associated with at least one of the service profiles; and

update the memory to indicate the current requirements of valid passwords for the services associated with the at least one of the service profiles.

13. The electronic device of claim 12 , wherein the one or more remote resources are polled periodically.

14. The electronic device of claim 12 , wherein the instructions, when executed, further cause the processor to, prior to polling the one or more remote resources, establish secure connections to the one or more remote resources by verifying digital certificates associated with the one or more remote resources.

15. The electronic device of claim 10 , wherein requirements of valid passwords for a service comprise one or more rules relating to at least one of:

password length;

presence of specific types of characters in a password;

perceived password strength;

prohibited elements in a password; or

user password history.

16. The electronic device of claim 10 , wherein randomly generating the password comprises generating the password based, at least in part, on user-defined criteria.

17. The electronic device of claim 10 , wherein the instructions, when executed, further cause the processor to transmit the generated password to the password-protected service to register the generated password.

18. The electronic device of claim 10 , wherein the instructions, when executed, further cause the processor to receive, via the input interface, user instruction to generate the password and wherein the determining step is performed in response to receiving the user instruction.

19. The electronic device of claim 10 , wherein each service profile includes a password expiration policy for a respective service and wherein the instructions, when executed, further cause the processor to, if the one or more password requirements include a service profile associated with the identifying information, determine that a current password, stored in the memory, for accessing the password-protected service has expired based on a password expiration policy in the service profile associated with the identifying information.

20. The electronic device of claim 19 , wherein the instructions, when executed, further cause the processor to present a notification on the electronic device indicating that the current password has expired.

21. A non-transitory computer-readable medium storing processor-executable instructions for generating a password, wherein the instructions, when executed, cause an electronic device to:

store information pertaining to one or more password requirements and default password generation requirements, the information pertaining to one or more password requirements including one or more service profiles, each of the one or more service profiles including an identifier for a service and an associated indication of one or more requirements of a valid password for the service;

determine an identity of a password-protected first service based on contextual data associated with the first service that is received at a computing device;

if the one or more password requirements include a service profile associated with the first service:

determine whether the one or more password requirements indicated in the service profile associated with the first service are up-to-date;

in response to determining that the one or more password requirements are not up-to-date, sending a request to a remote resource associated with the first service to transmit current password requirements for the first service to the electronic device;

randomly generate a password to comply with the current password requirements for the first service as received from the remote resource; and

if the one or more current password requirements does not include a service profile associated with the first service, randomly generate a password to comply with the default password generation requirements.

Assignments (5)
NUNC PRO TUNC ASSIGNMENT Recorded Jun 19, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064271/0199 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2023
From: BLACKBERRY LIMITED
To: MALIKIE INNOVATIONS LIMITED
Reel/Frame 064104/0103 →
CHANGE OF NAME Recorded Jun 18, 2018
From: RESEARCH IN MOTION LIMITED
To: BLACKBERRY LIMITED
Reel/Frame 046377/0527 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 28, 2016
From: ADAMS, NEIL PATRICK
To: BLACKBERRY LIMITED
Reel/Frame 039278/0661 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 28, 2016
From: SYDOROWSKI, LUKAS
To: RESEARCH IN MOTION LIMITED
Reel/Frame 039278/0781 →
Continuity (1)
Related Publication 20170308695A1 · Oct 26, 2017
Cited By (2)
US 12,267,321 US 12,406,052