IP Library Granted Patent US 10,790,984
Granted Patent B1
US 10,790,984 · App. 15/927,323 · Granted Sep 29, 2020

Probabilistic set membership using partial prefix matching

Inventor: Adam J. Stiles (Altadena, CA)
Assignee: ALTIRIS, INC.
H04L9/3242G06F16/2255G06F16/955G06F21/31G06F21/46G06F21/602G06F21/6245H04L9/14H04L9/3226
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,790,984
App. No.
15/927,323
Granted
Sep 29, 2020
Kind
B1
Abstract

A method for user credential location using prefix matching is described. In one embodiment, the method may include enabling a user to generate remotely a cryptographic hash of a user credential of the user, receiving a portion of the cryptographic hash from the user, comparing the portion of the cryptographic hash with a plurality of cryptographic hashes of user credentials stored at a database, determining whether a match exists between the portion of the cryptographic hash and at least one of the plurality of cryptographic hashes, and transmitting a notification to the user indicating whether the user credential is stored at the database based at least in part on a result of the comparing.

Claims (44)

1. A method for locating user credentials in databases, the method being performed by one or more computing devices with each computing device comprising at least one processor, the method comprising:

enabling a user to generate remotely a truncated length first cryptographic hash of a user credential of the user, the user credential comprising a user name or a password, or both, associated with the user;

receiving a portion of the first cryptographic hash from the user;

comparing the portion of the first cryptographic hash with each of a plurality of cryptographic hashes of user credentials stored at a database;

determining whether a match exists between the portion of the first cryptographic hash and at least one of the plurality of cryptographic hashes stored at the database;

determining a false positive error rate based at least in part on determining the portion of the first cryptographic hash matches at least one of the plurality of cryptographic hashes;

transmitting a notification to the user indicating the determined false positive error rate and whether the user credential is stored at the database based at least in part on a result of the comparing.

2. The method of claim 1 , further comprising:

enabling the user to generate remotely an increased length cryptographic hash of the user credential to lower the false positive error rate; and

determining a quantity of the plurality of cryptographic hashes stored at the database, wherein the notification includes an indication of the false positive error rate.

3. The method of claim 2 , wherein the determined false positive error rate is based at least in part on a number of bits associated with the portion of one or more of the first cryptographic hash and the increased length cryptographic hash.

4. The method of claim 1 , wherein the portion of the first cryptographic hash comprises a subset of a predetermined maximum number of bits for each cryptographic hash.

5. The method of claim 1 , wherein a location of the portion of the first cryptographic hash is selected by the user.

6. The method of claim 5 , wherein the selected location includes at least one of a beginning portion of the first cryptographic hash, a middle portion of the first cryptographic hash, or an ending portion of the first cryptographic hash, or any combination thereof.

7. The method of claim 1 , wherein the truncated length first cryptographic hash includes a non-contiguous portion of bits of an untruncated version of the first cryptographic hash.

8. The method of claim 1 , wherein a size or location, or both size and location, of the portion of the first cryptographic hash is selected randomly by a computing device.

9. The method of claim 1 , wherein the first cryptographic hash and each of the plurality of cryptographic hashes comprise at least 128 bits.

10. The method of claim 1 , wherein only the user has access to an untruncated version of the first cryptographic hash.

11. A computing device configured for locating user credentials in databases, comprising:

a processor;

memory in electronic communication with the processor, wherein the memory stores computer executable instructions that when executed by the processor cause the processor to perform the steps of:

enable a user to generate remotely a truncated length first cryptographic hash of a user credential of the user, the user credential comprising a user name or a password, or both, associated with the user;

receive a portion of the first cryptographic hash from the user;

compare the portion of the first cryptographic hash with each of a plurality of cryptographic hashes of user credentials stored at a database;

determine whether a match exists between the portion of the first cryptographic hash and a portion of at least one of the plurality of cryptographic hashes stored at the database;

determine a false positive error rate based at least in part on determining the portion of the first cryptographic hash matches at least one of the plurality of cryptographic hashes;

transmit a notification to the user indicating the determined false positive error rate and whether the user credential is stored at the database based at least in part on a result of the comparing.

12. The computing device of claim 11 , wherein the instructions are executable by the processor to:

enable the user to generate remotely an increased length cryptographic hash of the user credential to lower the false positive error rate; and

determining a quantity of the plurality of cryptographic hashes stored at the database, wherein the notification includes an indication of the false positive error rate.

13. The computing device of claim 12 , wherein the determined false positive error rate is based at least in part on a number of bits associated with the portion of one or more of the first cryptographic hash and the increased length cryptographic hash.

14. The computing device of claim 11 , wherein the portion of the first cryptographic hash comprises a subset of a predetermined maximum number of bits for each cryptographic hash.

15. The computing device of claim 11 , wherein a location, of the portion of the first cryptographic hash is selected by the user.

16. The computing device of claim 15 , wherein the selected location includes at least one of a beginning portion of the first cryptographic hash, a middle portion of the first cryptographic hash, or an ending portion of the first cryptographic hash, or any combination thereof.

17. The computing device of claim 11 , wherein the truncated length first cryptographic hash includes a non-contiguous portion of bits of an untruncated version of the first cryptographic hash.

18. The computing device of claim 11 , wherein a size or location, or both size and location, of the portion of the first cryptographic hash is selected randomly by the computing device.

19. The computing device of claim 11 , wherein the first cryptographic hash and each of the plurality of cryptographic hashes comprise at least 128 bits.

20. A non-transitory computer-readable storage medium storing computer executable instructions that when executed by a processor cause the processor to perform the steps of:

enabling a user to generate remotely a truncated length first cryptographic hash of a user credential of the user, the user credential comprising a user name or a password, or both, associated with the user;

receiving a portion of the first cryptographic hash from the user;

comparing the portion of the first cryptographic hash with each of a plurality of cryptographic hashes of user credentials stored at a database;

determining whether a match exists between the portion of the first cryptographic hash and at least one of the plurality of cryptographic hashes stored at the database;

determining a false positive error rate based at least in part on determining the portion of the first cryptographic hash matches at least one of the plurality of cryptographic hashes;

transmitting a notification to the user indicating the determined false positive error rate and whether the user credential is stored at the database based at least in part on a result of the comparing.

Assignments (6)
MERGER Recorded Mar 8, 2022
From: ALTIRIS, INC.
To: LEXISNEXIS RISK SOLUTIONS FL INC.
Reel/Frame 059193/0413 →
PARTIAL RELEASE OF SECURITY INTEREST Recorded Feb 25, 2020
From: JPMORGAN CHASE BANK, N.A.
To: NORTONLIFELOCK, INC. (F/K/A SYMANTEC CORPORATION)
Reel/Frame 052006/0115 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 9, 2020
From: NORTONLIFELOCK INC.
To: ALTIRIS, INC.
Reel/Frame 051471/0877 →
CHANGE OF NAME Recorded Jan 9, 2020
From: SYMANTEC CORPORATION
To: NORTONLIFELOCK INC.
Reel/Frame 051554/0598 →
SECURITY AGREEMENT Recorded Nov 4, 2019
From: SYMANTEC CORPORATION; BLUE COAT LLC; LIFELOCK, INC,; SYMANTEC OPERATING CORPORATION
To: JPMORGAN, N.A.
Reel/Frame 050926/0560 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 21, 2018
From: STILES, ADAM J.
To: SYMANTEC CORPORATION
Reel/Frame 045301/0314 →
Cited By (1)
US 12,561,304