IP Library Granted Patent US 11,055,398
Granted Patent B2
US 11,055,398 · App. 16/178,636 · Granted Jul 6, 2021

Monitoring strength of passwords

Inventors: Naveen Sunkavally (Cary, NC); Salah E. Machani (Medford, MA)
Assignee: RSA Security LLC
G06F21/46G06F21/31H04L63/0428H04L63/102
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,055,398
App. No.
16/178,636
Granted
Jul 6, 2021
Kind
B2
Abstract

A method is used in monitoring strength of passwords. A a request is received from a user to use a user password. A password score is determined for the user password. The password score indicates quality of the user password. Based on the password score, the strength of the user password is evaluated in a privacy preserving manner. The privacy preserving manner indicates avoiding storing information regarding the user password after strength of the user password has been evaluated.

Claims (53)

1. A method of controlling access to resources by monitoring a strength of a password, the method comprising:

receiving a first request from a user to access a first resource;

receiving, after receiving the first request, a user password from the user as a condition of determining whether access to the first resource should be granted;

successfully authenticating the received user password, wherein the user password has been authenticated at least one additional time in the past;

determining a password score for the user password after successfully authenticating the user password, wherein the password score indicates quality of the user password;

based on the determined password score, evaluating strength of the user password in a privacy preserving manner, wherein the privacy preserving manner indicates avoiding storing information in a memory or a processor regarding the user password after the strength of the user password has been evaluated;

denying access to the first resource because the strength of the user password does not exceed a first threshold score;

receiving a second request from the user to access a second resource;

receiving the user password from the user as a condition of determining whether access to the second resource should be granted;

successfully authenticating the user password in connection with the second request;

determining a second password score for the user password after successfully authenticating the user password, wherein the second password score indicates quality of the user password;

based on the second password score, evaluating strength of the user password; and

granting access to the second resource because the second password score exceeds a second threshold score.

2. The method of claim 1 , wherein the second password score is different than the first password score.

3. The method of claim 1 , wherein a client module resides within a web application, on a mobile device, or a computing device.

4. The method of claim 1 , wherein determining the password score and evaluation of strength of the user password is performed by a password scorer module.

5. The method of claim 1 , wherein a client module and a password scorer module reside within a single device.

6. The method of claim 5 , wherein the user password is sent to a password scorer module over a secure connection.

7. The method of claim 1 , wherein strength of the user password changes overtime.

8. The method of claim 1 , further comprising prohibiting access to a network if the threshold score is below a threshold level.

9. A system for controlling access to resources by monitoring a strength of a password, the system comprising a memory and a processor configured to:

receive a first request from a user to access a first resource;

receive, after receiving the first request, a user password from the user as a condition of determining whether access to the first resource should be granted;

successfully authenticate the received user password, wherein the user password has been authenticated at least one additional time in the past;

determine a password score for the user password after successfully authenticating the user password, wherein the password score indicates quality of the user password;

based on the determined password score, evaluate strength of the user password in a privacy preserving manner, wherein the privacy preserving manner indicates avoiding storing information regarding the user password in the memory or the processor after strength of the user password has been evaluated;

deny access to the first resource because the strength of the user password does not exceed a first threshold score;

receive a second request from the user to access a second resource;

receive the user password from the user as a condition of determining whether access to the second resource should be granted;

successfully authenticate the user password in connection with the second request;

determine a second password score for the user password after successfully authenticating the user password, wherein the second password score indicates quality of the user password;

based on the second password score, evaluate strength of the user password; and

grant access to the second resource because the second password score exceeds a second threshold score.

10. The system of claim 9 , wherein the second password score is different than the first password score.

11. The system of claim 9 , wherein a client module resides within a web application, on a mobile device, or a computing device.

12. The system of claim 9 , wherein determining the password score and evaluation of strength of the user password is performed by a password scorer module.

13. The system of claim 9 , wherein a client module and a password scorer module reside within a single device.

14. The system of claim 13 , wherein the user password is sent to a password scorer module over a secure connection.

15. The system of claim 9 , wherein strength of the user password changes over time.

16. The system of claim 9 , further comprising prohibiting access to a network if the score is below a threshold level.

17. A computer program product comprising a non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code when executed by at least one processing device causes the at least one processing device to:

receive a first request from a user to access a first resource;

receive, after receiving the first request, a user password from the user as a condition of determining whether access to the first resource should be granted;

successfully authenticate the received user password wherein the user password has been authenticated at least one additional time in the past;

determine a password score for the user password after successfully authenticating the user password, wherein the password score indicates quality of the user password;

based on the determined password score, evaluate strength of the user password in a privacy preserving manner, wherein the privacy preserving manner indicates avoiding storing information in the non-transitory, processor readable storage medium or a memory coupled thereto regarding the user password after strength of the user password has been evaluated;

deny access to the first resource because the strength of the user password does not exceed a first threshold score;

receive a second request from the user to access a second resource;

receive the user password from the user as a condition of determining whether access to the second resource should be granted;

successfully authenticate the user password in connection with the second request;

determine a second password score for the user password after successfully authenticating the user password, wherein the second password score indicates quality of the user password;

based on the second password score, evaluate strength of the user password; and

grant access to the second resource because the second password score exceeds a second threshold score.

Assignments (16)
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56098/0534 Recorded Mar 5, 2026
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: RSA SECURITY LLC
Reel/Frame 075041/0175 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 70587/0885 Recorded Mar 5, 2026
From: JPMORGAN CHASE BANK, N.A.
To: RSA SECURITY LLC; RSA SECURITY USA LLC
Reel/Frame 075031/0394 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Mar 21, 2025
From: RSA SECURITY LLC; RSA SECURITY USA LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 070587/0885 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY USA, LLC
Reel/Frame 069762/0529 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY LLC
Reel/Frame 069762/0401 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 054155, FRAME 0815 Recorded Apr 29, 2021
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056104/0841 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 053666, FRAME 0767 Recorded Apr 29, 2021
From: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056095/0574 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 056098/0534 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 7, 2020
From: EMC IP HOLDING COMPANY LLC
To: RSA SECURITY LLC
Reel/Frame 053717/0020 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (049452/0223) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054250/0372 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054191/0287 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: JEFFERIES FINANCE LLC
Reel/Frame 053666/0767 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 054155/0815 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 2, 2018
From: SUNKAVALLY, NAVEEN; MACHANI, SALAH E.
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 047390/0192 →