IP Library Granted Patent US 10,797,870
Granted Patent B1
US 10,797,870 · App. 16/000,920 · Granted Oct 6, 2020

Systems and methods for generating passwords

Inventors: Duong Nguyen-Huu (Los Angeles, CA); Bruce McCorkendale (Manhattan Beach, CA)
Assignee: NortonLifeLock Inc.
H04L9/0861G06F16/9038G06F21/46H04L63/083H04L67/306
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,797,870
App. No.
16/000,920
Granted
Oct 6, 2020
Kind
B1
Abstract

The disclosed computer-implemented method for generating passwords may include (i) accessing a vault of confidential information describing a user, (ii) extracting, from the vault, a set of multiple items of confidential information describing the user, (iii) executing a programmed heuristic on the set of multiple items of confidential information to generate multiple candidate passwords that each derives from a respective semirandom permutation of the multiple items of confidential information, and (iv) displaying electronically the multiple candidate passwords to the user to enable the user to select a password from the multiple candidate passwords as a specific password for accessing a protected computing resource. Various other methods, systems, and computer-readable media are also disclosed.

Claims (39)

1. A computer-implemented method for generating passwords, at least a portion of the method being performed by a computing device comprising at least one processor, the method comprising:

accessing a vault of confidential information describing a user;

extracting, from the vault, a set of multiple items of confidential information describing the user;

executing a programmed heuristic on the set of multiple items of confidential information to generate multiple candidate passwords that each derives from a respective semirandom permutation of the multiple items of confidential information; and

displaying electronically the multiple candidate passwords to the user to enable the user to select a password from the multiple candidate passwords as a specific password for accessing a protected computing resource;

wherein:

the multiple candidate passwords respectively comprise different permutations of concatenating the multiple items of confidential information that were extracted from an identity theft prevention service.

2. The computer-implemented method of claim 1 , wherein deriving the multiple candidate passwords from the respective semirandom permutation of the multiple items of confidential information describing the user increases a memorability of the multiple candidate passwords in comparison to candidate passwords that do not describe the user.

3. The computer-implemented method of claim 1 , wherein basing the multiple candidate passwords on confidential information rather than public information increases a strength of the selected specific password.

4. The computer-implemented method of claim 1 , wherein accessing the vault of confidential information describing the user is performed in response to the user granting access to the vault of confidential information.

5. The computer-implemented method of claim 1 , wherein the vault of confidential information is maintained by an identity theft protection service.

6. The computer-implemented method of claim 1 , wherein executing the programmed heuristic on the set of multiple items of confidential information to generate multiple candidate passwords comprises testing items in an initial larger set of multiple candidate passwords for password strength.

7. The computer-implemented method of claim 6 , further comprising filtering a subset of the initial larger set of multiple candidate passwords from the initial larger set of multiple candidate passwords based on the subset failing the test for password strength.

8. The computer-implemented method of claim 1 , wherein executing the programmed heuristic on the set of multiple items of confidential information comprises checking whether each item in the set of multiple items of confidential information has been publicly revealed.

9. The computer-implemented method of claim 8 , further comprising filtering a subset of the multiple items of confidential information from the multiple items of confidential information based on a determination that the subset has been publicly revealed.

10. The computer-implemented method of claim 1 , further comprising performing a security action to protect the protected computing resource based on the selected specific password.

11. A system for generating passwords, the system comprising:

an accessing module, stored in memory, that accesses a vault of confidential information describing a user;

an extraction module, stored in memory, that extracts, from the vault, a set of multiple items of confidential information describing the user;

an execution module, stored in memory, that executes a programmed heuristic on the set of multiple items of confidential information to generate multiple candidate passwords that each derives from a respective semirandom permutation of the multiple items of confidential information;

a displaying module, stored in memory, that displays electronically the multiple candidate passwords to the user to enable the user to select a password from the multiple candidate passwords as a specific password for accessing a protected computing resource; and

at least one physical processor configured to execute the accessing module, the extraction module, the execution module, and the displaying module;

wherein:

the multiple candidate passwords respectively comprise different permutations of concatenating the multiple items of confidential information that were extracted from an identity theft prevention service.

12. The system of claim 11 , wherein the execution module derives the multiple candidate passwords from the respective semirandom permutation of the multiple items of confidential information describing the user such that a memorability of the multiple candidate passwords is increased in comparison to candidate passwords that do not describe the user.

13. The system of claim 11 , wherein the execution module bases the multiple candidate passwords on confidential information rather than public information such that a strength of the selected specific password is increased.

14. The system of claim 11 , wherein the accessing module accesses the vault of confidential information describing the user in response to the user granting access to the vault of confidential information.

15. The system of claim 11 , wherein the vault of confidential information is maintained by an identity theft protection service.

16. The system of claim 11 , wherein the execution module executes the programmed heuristic on the set of multiple items of confidential information to generate multiple candidate passwords by testing items in an initial larger set of multiple candidate passwords for password strength.

17. The system of claim 16 , wherein the execution module further filters a subset of the initial larger set of multiple candidate passwords from the initial larger set of multiple candidate passwords based on the subset failing the test for password strength.

18. The system of claim 11 , wherein the execution module executes the programmed heuristic on the set of multiple items of confidential information by checking whether each item in the set of multiple items of confidential information has been publicly revealed.

19. The system of claim 18 , wherein the execution module filters a subset of the multiple items of confidential information from the multiple items of confidential information based on a determination that the subset has been publicly revealed.

20. A non-transitory computer-readable medium comprising one or more computer-readable instructions that, when executed by at least one processor of a computing device, cause the computing device to:

access a vault of confidential information describing a user;

extract, from the vault, a set of multiple items of confidential information describing the user;

execute a programmed heuristic on the set of multiple items of confidential information to generate multiple candidate passwords that each derives from a respective semirandom permutation of the multiple items of confidential information; and

display electronically the multiple candidate passwords to the user to enable the user to select a password from the multiple candidate passwords as a specific password for accessing a protected computing resource;

wherein:

the multiple candidate passwords respectively comprise different permutations of concatenating the multiple items of confidential information that were extracted from an identity theft prevention service.

Assignments (6)
CHANGE OF NAME Recorded Feb 6, 2023
From: NORTONLIFELOCK INC.
To: GEN DIGITAL INC.
Reel/Frame 062714/0605 →
NOTICE OF SUCCESSION OF AGENCY (REEL 050926 / FRAME 0560) Recorded Sep 13, 2022
From: JPMORGAN CHASE BANK, N.A.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 061422/0371 →
SECURITY AGREEMENT Recorded Sep 13, 2022
From: NORTONLIFELOCK INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062220/0001 →
CHANGE OF NAME Recorded Feb 14, 2020
From: SYMANTEC CORPORATION
To: NORTONLIFELOCK INC.
Reel/Frame 051935/0228 →
SECURITY AGREEMENT Recorded Nov 4, 2019
From: SYMANTEC CORPORATION; BLUE COAT LLC; LIFELOCK, INC,; SYMANTEC OPERATING CORPORATION
To: JPMORGAN, N.A.
Reel/Frame 050926/0560 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 13, 2018
From: NGUYEN-HUU, DUONG; MCCORKENDALE, BRUCE
To: SYMANTEC CORPORATION
Reel/Frame 046075/0569 →
Cited By (2)
US 12,399,970 US 12,406,040