IP Library Granted Patent US 11,914,698
Granted Patent B2
US 11,914,698 · App. 17/411,376 · Granted Feb 27, 2024

Unique password policy creation

Inventors: Cesar Augusto Rodriguez Bravo (Alajuela, CR); David Alonso Campos Batista (Aurora, CR); John Richard Feezell (Pikeville, TN); Faraz Ahmad (Noida, IN); Anto Ajay Raj John (Bangalore, IN)
Assignee: KYNDRYL, INC.
G06F21/46G06F21/31G06F21/604
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,914,698
App. No.
17/411,376
Granted
Feb 27, 2024
Kind
B2
Abstract

A random password policy for a specific user associated with an entity is generated based on a global password requirement. A new password created by the specific user based on the generated random password policy is identified. That the new password complies with a set of requirements specified by the generated random password policy is confirmed.

Claims (88)

1. A method, the method comprising:

retrieving, by one or more computer processors, a global password requirement associated with an entity from a policy database;

generating, by the one or more computer processors, a random password policy for a specific user associated with the entity based on the global password requirement, wherein the global password requirement defines minimum password requirements mandated by the entity for all users associated with the entity, and the random password policy is a subset of the global password requirement;

identifying, by the one or more computer processors, a new password created by the specific user based on the generated random password policy; and

confirming, by the one or more computer processors, that the new password complies with a set of requirements specified by the generated random password policy.

2. The method of claim 1 , wherein the step of generating, by one or more computer processors, a random password policy for a specific user associated with an entity based on a global password requirement, comprises:

receiving, by the one or more computer processors, at least one of a first indication of the specific user creating a new password and a second indication of the specific user changing a default password;

wherein the entity is selected from the group consisting of an organization, a company, an Internet website, and an operating system; and

generating, by the one or more computer processors, the random password policy for the specific user associated with the entity based on the retrieved global password requirement.

3. The method of claim 1 , further comprising:

storing, by the one or more computer processors, the generated random password policy for the specific user to an available memory;

creating, by the one or more computer processors, an association between the generated random password policy and the specific user, wherein the created association is also stored to the available memory;

implementing, by the one or more computer processors, the generated random password policy across all entity domains utilized by the specific user; and

transmitting, by the one or more computer processors, the generated random password policy to the specific user.

4. The method of claim 1 , wherein responsive to confirming that the new password fails to comply with the set of requirements specified by the generated random password policy:

a notification is transmitted to the specific user indicating that the new password fails to comply with the set of requirements;

one or more errors in the new password are provided to the specific user in the notification; and

the specific user is informed via the notification to create another new password which meets the set of requirements.

5. The method of claim 1 , further comprising:

receiving, by the one or more computer processors, a request from the specific user that the specific user is changing a first password created by the specific user;

identifying, by the one or more computer processors, a new password resulting from the specific user changing the first password; and

confirming, by the one or more computer processors, that the identified new password complies with the random password policy associated with the specific user.

6. The method of claim 5 , wherein the step of confirming, by one or more computer processors, that the identified new password complies with the random password policy associated with the specific user, comprises:

identifying, by the one or more computer processors, the specific user based on the received request;

retrieving, by the one or more computer processors, the random password policy associated with the identified specific user;

transmitting, by the one or more computer processors, the retrieved random password policy to the identified specific user; and

confirming, by the one or more computer processors, that the identified new password complies with the transmitted random password policy associated with the specific user.

7. The method of claim 6 , wherein the received request includes an identification of the specific user.

8. A computer program product, the computer program product comprising:

one or more computer readable storage media; and

program instructions stored on the one or more computer readable storage media, the program instructions comprising:

program instructions to retrieve a global password requirement associated with an entity from a policy database;

program instructions to generate a random password policy for a specific user associated with the entity based on the global password requirement, wherein the global password requirement defines minimum password requirements mandated by the entity for all users associated with the entity and the random password policy must meet at least the global password requirement;

program instructions to identify a new password created by the specific user based on the generated random password policy; and

program instructions to confirm that the new password complies with a set of requirements specified by the generated random password policy.

9. The computer program product of claim 8 , wherein the program instructions to generate a random password policy for a specific user associated with an entity based on a global password requirement, comprises:

program instructions to receive at least one of a first indication of the specific user creating a new password and a second indication of the specific user changing a default password;

wherein the entity is selected from the group consisting of an organization, a company, an Internet website, and an operating system; and

program instructions to generate the random password policy for the specific user associated with the entity based on the retrieved global password requirement.

10. The computer program product of claim 8 , further comprising program instructions stored on the one or more computer readable storage media, to:

store the generated random password policy for the specific user to an available memory;

create an association between the generated random password policy and the specific user, wherein the created association is also stored to the available memory;

implement the generated random password policy across plural domains of the entity utilized by the specific user; and

transmit the generated random password policy to the specific user.

11. The computer program product of claim 8 , wherein responsive to confirming that the new password fails to comply with the set of requirements specified by the generated random password policy:

a notification is transmitted to the specific user indicating that the new password fails to comply with the set of requirements;

one or more errors in the new password are provided to the specific user in the notification; and

the specific user is informed via the notification to create another new password which meets the set of requirements.

12. The computer program product of claim 8 , further comprising program instructions stored on the one or more computer readable storage media, to:

receive a request from the specific user that the specific user is changing a first password created by the specific user;

identify a new password resulting from the specific user changing the first password; and

confirm that the identified new password complies with the random password policy associated with the specific user.

13. The computer program product of claim 12 , wherein the program instructions to confirm that the identified new password complies with the random password policy associated with the specific user, comprises:

program instructions to identify the specific user based on the received request;

program instructions to retrieve the random password policy associated with the identified specific user;

program instructions to transmit the retrieved random password policy to the identified specific user; and

program instructions to confirm that the identified new password complies with the transmitted random password policy associated with the specific user.

14. The computer program product of claim 13 , wherein the received request includes an identification of the specific user.

15. A computer system, the computer system comprising:

one or more computer processors;

one or more computer readable storage media; and

program instructions stored on the one or more computer readable storage media for execution by at least one of the one or more computer processors, the program instructions comprising:

program instructions to retrieve a global password requirement associated with an entity from a policy database;

program instructions to generate a random password policy for a specific user associated with the entity based on the global password requirement, wherein the global password requirement defines minimum password requirements mandated by the entity for all users associated with the entity and the random password policy must meet at least the global password requirement;

program instructions to identify a new password created by the specific user based on the generated random password policy; and

program instructions to confirm that the new password complies with a set of requirements specified by the generated random password policy.

16. The computer system of claim 15 , wherein the program instructions to generate a random password policy for a specific user associated with an entity based on a global password requirement, comprises:

program instructions to receive at least one of a first indication of the specific user creating a new password and a second indication of the specific user changing a default password;

wherein the entity is selected from the group consisting of an organization, a company, an Internet website, and an operating system; and

program instructions to generate the random password policy for the specific user associated with the entity based on the retrieved global password requirement.

17. The computer system of claim 15 , further comprising program instructions stored on the one or more computer readable storage media for execution by at least one of the one or more computer processors, to:

store the generated random password policy for the specific user to an available memory;

create an association between the generated random password policy and the specific user, wherein the created association is also stored to the available memory;

implement the generated random password policy across plural domains of the entity utilized by the specific user, wherein the plural domains of the entity are selected from a group consisting of: application programs; computing devices; and databases; and

transmit the generated random password policy to the specific user.

18. The computer system of claim 15 , wherein responsive to confirming that the new password fails to comply with the set of requirements specified by the generated random password policy:

a notification is transmitted to the specific user indicating that the new password fails to comply with the set of requirements;

one or more errors in the new password are provided to the specific user in the notification; and

the specific user is informed via the notification to create another new password which meets the set of requirements.

19. The computer system of claim 15 , further comprising program instructions stored on the one or more computer readable storage media for execution by at least one of the one or more computer processors, to:

receive a request from specific user that the specific user is changing a first password created by the specific user;

identify a new password resulting from the specific user changing the first password; and

confirm that the identified new password complies with the random password policy associated with the specific user.

20. The computer system of claim 19 , wherein the program instructions to confirm that the identified new password complies with the random password policy associated with the specific user, comprises:

program instructions to identify the specific user based on the received request;

program instructions to retrieve the random password policy associated with the identified specific user;

program instructions to transmit the retrieved random password policy to the identified specific user; and

program instructions to confirm that the identified new password complies with the transmitted random password policy associated with the specific user.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 18, 2021
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: KYNDRYL, INC.
Reel/Frame 058213/0912 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2021
From: RODRIGUEZ BRAVO, CESAR AUGUSTO; CAMPOS BATISTA, DAVID ALONSO; FEEZELL, JOHN RICHARD; AHMAD, FARAZ; JOHN, ANTO AJAY RAJ
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 057283/0714 →
Cited By (2)
US 12,493,683 US 12,602,456