IP Library Granted Patent US 10,594,487
Granted Patent B2
US 10,594,487 · App. 15/661,018 · Granted Mar 17, 2020

Password management and verification with a blockchain

Inventors: Debbie Anglin (Williamson, TX); Howard Anglin (Leander, TX); Su Liu (Austin, TX); Yu Liu (Beijing, CN)
Assignee: International Business Machines Corporation
H04L9/3226G06F9/54H04L9/3236H04L9/3242H04L2209/38
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,594,487
App. No.
15/661,018
Granted
Mar 17, 2020
Kind
B2
Abstract

An example operation may include one or more of determining whether one or more password strings are related to a password, the password strings are transmitted from a user device, hashing the one or more password strings to create one or more password hash values, determining whether the one or more password hash values match any internal password hash values of an internal password history chain stored in an internal blockchain, determining whether the one or more password hash values match any external password hash values of an external password history chain stored in an external blockchain, and responsive to determining the one or more password hash values do not match any internal password hash value and any external password hash values, storing a new password in one or more of the internal blockchain and the external blockchain.

Claims (52)

1. A method, comprising:

determining whether one or more password strings are related to one or more existing passwords, wherein the one or more password strings are transmitted from a user device;

hashing the one or more password strings to create one or more respective password hash values;

determining whether the one or more password hash values match any internal password hash values of an internal password history chain stored in an internal blockchain;

determining whether the one or more password hash values match any external password hash values of an external password history chain stored in an external blockchain; and

responsive to the determining that the one or more password hash values do not match any internal password hash values or any external password hash values, storing the one or more password hash values as a new password in a block of one or more of the internal blockchain and the external blockchain, wherein all password hash values for all user devices that utilize the one or more of the internal blockchain and the external blockchain are stored in the block.

2. The method of claim 1 , further comprising:

identifying an account associated with the one or more password strings; and

retrieving the internal password hash values from the password history chain of the internal blockchain based on the account.

3. The method of claim 1 , further comprising:

transmitting a warning message to the user device when the one or more password hash values match a previously stored password hash value stored in one or more of the internal blockchain and the external blockchain.

4. The method of claim 1 , further comprising:

monitoring for the one or more password strings sent from the user device, wherein the monitoring comprises monitoring for a plurality of passwords associated with a plurality of accounts associated with the user device.

5. The method of claim 1 , further comprising:

monitoring a password application programming interface (API) for one or more password values.

6. The method of claim 1 , further comprising:

storing a new block comprising the one or more password hash values in the internal blockchain.

7. An apparatus, comprising:

a hardware processor configured to:

determine whether one or more password strings are related to one or more existing passwords, wherein the one or more password strings are transmitted from a user device,

hash the one or more password strings to create one or more respective password hash values,

determine whether the one or more password hash values match any internal password hash values of an internal password history chain stored in an internal blockchain,

determine whether the one or more password hash values match any external password hash values of an external password history chain stored in an external blockchain,

and

responsive to the determining that the one or more password hash values do not match any internal password hash value and any external password hash values, store the one or more password hash values as a new password in a block of one or more of the internal blockchain and the external blockchain, wherein all password hash values for all user devices that utilize the one or more of the internal blockchain and the external blockchain are stored in the block.

8. The apparatus of claim 7 , wherein the hardware processor is further configured to:

identify an account associated with the one or more password strings; and

retrieve the internal password hash values from the password history chain of the internal blockchain based on the account.

9. The apparatus of claim 7 , wherein the hardware processor is further configured to:

transmit a warning message to the user device when the one or more password hash values match a previously stored password hash value stored in one or more of the internal blockchain and the external blockchain.

10. The apparatus of claim 7 , wherein the hardware processor is further configured to:

monitor for the one or more password strings sent from the user device, and monitor for a plurality of passwords associated with a plurality of accounts associated with the user device.

11. The apparatus of claim 7 , wherein the hardware processor is further configured to:

monitor a password application programming interface (API) for one or more password values.

12. The apparatus of claim 7 , wherein the hardware processor is further configured to:

store a new block comprising the one or more password hash values in the internal blockchain.

13. A non-transitory computer readable storage medium storing instructions that, when executed, are configured to cause a processor to perform:

determining whether one or more password strings are related to one or more existing passwords, wherein the one or more password strings are transmitted from a user device;

hashing the one or more password strings to create one or more respective password hash values;

determining whether the one or more password hash values match any internal password hash values of an internal password history chain stored in an internal blockchain;

determining whether the one or more password hash values match any external password hash values of an external password history chain stored in an external blockchain; and

responsive to the determining that the one or more password hash values do not match any internal password hash value and any external password hash values, storing the one or more password hash values as a new password in a block of one or more of the internal blockchain and the external blockchain, wherein all password hash values for all user devices that utilize the one or more of the internal blockchain and the external blockchain are stored in the block.

14. The non-transitory computer readable storage medium of claim 13 , wherein the instructions are further configured to cause the processor to perform:

identifying an account associated with the one or more password strings; and

retrieving the internal password hash values from the password history chain of the internal blockchain based on the account.

15. The non-transitory computer readable storage medium of claim 13 , wherein the instructions are further configured to cause the processor to perform:

transmitting a warning message to the user device when the one or more password hash values match a previously stored password hash value stored in one or more of the internal blockchain and the external blockchain.

16. The non-transitory computer readable storage medium of claim 13 , wherein the instructions are further configured to cause the processor to perform:

monitoring for the one or more password strings sent from the user device, wherein the monitoring comprises monitoring for a plurality of passwords associated with a plurality of accounts associated with the user device.

17. The non-transitory computer readable storage medium of claim 13 , wherein the instructions are further configured to cause the processor to perform:

monitoring a password application programming interface (API) for one or more password values; and

storing a new block comprising the one or more password hash values in the internal blockchain.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2024
From: GREEN MARKET SQUARE LIMITED
To: WORKDAY, INC.
Reel/Frame 067801/0892 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2024
From: GREEN MARKET SQUARE LIMITED
To: WORKDAY, INC.
Reel/Frame 067556/0783 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 22, 2021
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: GREEN MARKET SQUARE LIMITED
Reel/Frame 055078/0982 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 27, 2017
From: ANGLIN, DEBBIE; ANGLIN, HOWARD; LIU, SU; LIU, YU
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 043108/0397 →
Continuity (1)
Related Publication 20190036696A1 · Jan 31, 2019