IP Library Granted Patent US 12,547,701
Granted Patent B2
US 12,547,701 · App. 18/752,533 · Granted Feb 10, 2026

Method and system for creation of compliant password by inplace feedback to password composition policy

Inventors: Manish Shukla (Pune, IN); Sreecharan Bojja (Pune, IN); Vijayanand Mahadeo Banahatti (Pune, IN); Sachin Premsukh Lodha (Pune, IN)
Assignee: TATA CONSULTANCY SERVICES LIMITED
G06F21/46G06F3/04886G06F21/316
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,547,701
App. No.
18/752,533
Granted
Feb 10, 2026
Kind
B2
Abstract

There is a need for design and implementation of interfaces for providing user-friendly feedback while creating and updating compliant passwords. This disclosure relates to a method of creating compliant password by in-place feedback to a password composition policy (PCP). A policy-enabled-virtual keyboard (PKBD) receives input from a user and is processed based on parameters associated with the PCP to identify accessible and inaccessible keys on the PKBD with in-place feedback. The in-place feedback is provided to highlight accessible keys of the PKBD for the user, if class associated with character, or mandated number of characters by the PCP are received are covered. Alternatively, the keys of the PKBD are disabled for access to the user by validating if class associated with character received are not covered, and a deviation of the parameters. A compliant password is created based on the PCP by providing in-place feedback for a resultant validation.

Claims (44)

1 . A processor-implemented method, comprising:

initializing, via one or more hardware processors, one or more data structures based on one or more configuration file;

configuring, via the one or more hardware processors, one or more keys of a policy-enabled-virtual keyboard (PKBD) based on a predefined password-composition policy (PCP);

receiving, via the one or more hardware processors, at least one input from a user, wherein the at least one input corresponds to one or more keys pressed at the PKBD;

processing, via the one or more hardware processors, the at least one input from the user based on one or more parameters associated with the predefined PCP to identify one or more accessible keys and one or more inaccessible keys on the PKBD with one or more in-place feedbacks, wherein the step of processing comprises:

(a) providing, via the one or more hardware processors, a first in-place feedback to highlight one or more accessible keys of the PKBD for the user, if a class associated with at least one character, or at least one mandated number of character by the PCP are received as the input from the user are covered, wherein at least one mandated number of character corresponds to at least one lower case character, or

(b) disabling, via the one or more hardware processors, the one or more keys of the PKBD for access to the user with a second in-place feedback by validating if a class associated with at least one character received as the input from the user are not covered, and a deviation of the one or more parameters; and

creating, via the one or more hardware processors, at least one compliant password based on the PCP by providing one or more in-place feedbacks for a resultant validation.

2 . The processor implemented method of claim 1 , wherein one or more data structures correspond to: (a) PCP structures, (b) blacklist structure, (c) cues, (d) message digest, and (e) thresholds, wherein the PCP structures comprises: (i) length, (ii) characters classes, and (iii) historical reuse requirement, wherein the blacklist structure comprises: (i) a list of dictionaries, (ii) a character threshold, and (iii) pre-processing, transformations, wherein the cues comprises: (i) colors codes, (ii) audio, and (iii) haptic, wherein the message digest comprises: password, and pattern digest for reuse check, and wherein thresholds comprises: threshold for a diversity index, and a suspicious behavior detection.

3 . The processor implemented method of claim 1 , wherein the one or more parameters corresponds to: (a) a deviation from one or more configured PCPs, (b) a usage of blacklisted phrases and keywords, (c) a reuse of personal data, and (d) one or more behavioural patterns associated with the user.

4 . The processor implemented method of claim 1 , wherein the one or more in-place feedbacks corresponds to (a) one or more visual identifiers, (b) an audio feedback, and (c) a haptic cues feedback, wherein the one or more visual identifiers corresponds to one or more color code associated with the one or more keys of the PKBD, wherein the audio feedback corresponds to a notification tone, and wherein the haptic cues feedback corresponds to a vibration alert on a device of the user.

5 . The processor implemented method of claim 1 , wherein a finite state machine is maintained to track at least one state of the PKBD based on the at least one input received from the user.

6 . The processor implemented method of claim 1 , wherein a pre-trained graph neural network (GNN) based model is obtained by the one or more in-place feedbacks to determine one or more behavioural patterns associated with the user.

7 . The processor implemented method of claim 1 , wherein the diversity index is determined to identify a number of character classes available in a password dataset from the user, and wherein the diversity index corresponds to statistical representations of password diversity in one or more attributes.

8 . A system, comprising:

a memory storing instructions;

one or more communication interfaces; and

one or more hardware processors coupled to the memory via the one or more communication interfaces, wherein the one or more hardware processors are configured by the instructions to:

initialize one or more data structures based on one or more configuration file;

configure one or more keys of a policy-enabled-virtual keyboard (PKBD) based on a predefined password-composition policy (PCP);

receive at least one input from a user, wherein the at least one input corresponds to one or more keys pressed at the PKBD;

process the at least one input from the user based on one or more parameters associated with the predefined PCP to identify one or more accessible keys and one or more inaccessible keys on the PKBD with one or more in-place feedbacks, wherein the step of processing comprises:

(a) provide a first in-place feedback to highlight one or more accessible keys of the PKBD for the user, if a class associated with at least one character, or at least one mandated number of character by the PCP are received as the input from the user are covered, wherein at least one mandated number of character corresponds to at least one lower case character, or

(b) disable the one or more keys of the PKBD for access to the user with a second in-place feedback by validating if a class associated with at least one character received as the input from the user are not covered, and a deviation of the one or more parameters; and

create at least one compliant password based on the PCP by providing one or more in-place feedbacks for a resultant validation.

9 . The system of claim 8 , wherein one or more data structures correspond to: (a) PCP structures, (b) blacklist structure, (c) cues, (d) message digest, and (e) thresholds, wherein the PCP structures comprises: (i) length, (ii) characters classes, and (iii) historical reuse requirement, wherein the blacklist structure comprises: (i) a list of dictionaries, (ii) a character threshold, and (iii) pre-processing, transformations, wherein the cues comprises: (i) colors codes, (ii) audio, and (iii) haptic, wherein the message digest comprises: password, and pattern digest for reuse check, and wherein thresholds comprises: threshold for a diversity index, and a suspicious behavior detection.

10 . The system of claim 8 , wherein the one or more parameters corresponds to: (a) a deviation from one or more configured PCPs, (b) a usage of blacklisted phrases and keywords, (c) a reuse of personal data, and (d) one or more behavioural patterns associated with the user.

11 . The system of claim 8 , wherein the one or more in-place feedbacks corresponds to (a) one or more visual identifiers, (b) an audio feedback, and (c) a haptic cues feedback, wherein the one or more visual identifiers corresponds to one or more color code associated with the one or more keys of the PKBD, wherein the audio feedback corresponds to a notification tone, and wherein the haptic cues feedback corresponds to a vibration alert on a device of the user.

12 . The system of claim 8 , wherein a finite state machine is maintained to track at least one state of the PKBD based on the at least one input received from the user.

13 . The system of claim 8 , wherein a pre-trained graph neural network (GNN) based model is obtained by the one or more in-place feedbacks to determine one or more behavioural patterns associated with the user.

14 . The system of claim 8 , wherein the diversity index is determined to identify a number of character classes available in a password dataset from the user, and wherein the diversity index corresponds to statistical representations of password diversity in one or more attributes.

15 . One or more non-transitory machine readable information storage mediums comprising one or more instructions which when executed by one or more hardware processors cause:

initializing, one or more data structures based on one or more configuration file;

configuring, one or more keys of a policy-enabled-virtual keyboard (PKBD) based on a predefined password-composition policy (PCP);

receiving, at least one input from a user, wherein the at least one input corresponds to one or more keys pressed at the PKBD;

processing, the at least one input from the user based on one or more parameters associated with the predefined PCP to identify one or more accessible keys and one or more inaccessible keys on the PKBD with one or more in-place feedbacks, wherein the step of processing comprises:

(a) providing, a first in-place feedback to highlight one or more accessible keys of the PKBD for the user, if a class associated with at least one character, or at least one mandated number of character by the PCP are received as the input from the user are covered, wherein at least one mandated number of character corresponds to at least one lower case character, or

(b) disabling, the one or more keys of the PKBD for access to the user with a second in-place feedback by validating if a class associated with at least one character received as the input from the user are not covered, and a deviation of the one or more parameters; and

creating, at least one compliant password based on the PCP by providing one or more in-place feedbacks for a resultant validation.

16 . The one or more non-transitory machine-readable information storage mediums of claim 15 , wherein one or more data structures correspond to: (a) PCP structures, (b) blacklist structure, (c) cues, (d) message digest, and (e) thresholds, wherein the PCP structures comprises: (i) length, (ii) characters classes, and (iii) historical reuse requirement, wherein the blacklist structure comprises: (i) a list of dictionaries, (ii) a character threshold, and (iii) pre-processing, transformations, wherein the cues comprises: (i) colors codes, (ii) audio, and (iii) haptic, wherein the message digest comprises: password, and pattern digest for reuse check, and wherein thresholds comprises: threshold for a diversity index, and a suspicious behavior detection.

17 . The one or more non-transitory machine-readable information storage mediums of claim 15 , wherein the one or more parameters corresponds to: (a) a deviation from one or more configured PCPs, (b) a usage of blacklisted phrases and keywords, (c) a reuse of personal data, and (d) one or more behavioural patterns associated with the user.

18 . The one or more non-transitory machine-readable information storage mediums of claim 15 , wherein the one or more in-place feedbacks corresponds to (a) one or more visual identifiers, (b) an audio feedback, and (c) a haptic cues feedback, wherein the one or more visual identifiers corresponds to one or more color code associated with the one or more keys of the PKBD, wherein the audio feedback corresponds to a notification tone, and wherein the haptic cues feedback corresponds to a vibration alert on a device of the user, and wherein a pre-trained graph neural network (GNN) based model is obtained by the one or more in-place feedbacks to determine one or more behavioural patterns associated with the user.

19 . The one or more non-transitory machine-readable information storage mediums of claim 15 , wherein a finite state machine is maintained to track at least one state of the PKBD based on the at least one input received from the user.

20 . The one or more non-transitory machine-readable information storage mediums of claim 15 , wherein the diversity index is determined to identify a number of character classes available in a password dataset from the user, and wherein the diversity index corresponds to statistical representations of password diversity in one or more attributes.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 24, 2024
From: SHUKLA, MANISH; BOJJA, SREECHARAN; BANAHATTI, VIJAYANAND MAHADEO; LODHA, SACHIN PREMSUKH
To: TATA CONSULTANCY SERVICES LIMITED
Reel/Frame 067819/0422 →
Priority Claims (1)
IN 202321046973 · Jul 12, 2023 · national
Continuity (1)
Related Publication 20250021639A1 · Jan 16, 2025
References Cited (20)
US 7042442B1 · Kanevsky · 2006 [cited by examiner]
US 8441454B2 · Longe · 2013 [cited by examiner]
US 9524393B2 · Aggarwal et al. · 2016 [cited by applicant]
US 10223517B2 · Kandekar · 2019 [cited by applicant]
US 10824196B1 · Thigpen · 2020 [cited by examiner]
US 11481109B2 · Westerman · 2022 [cited by examiner]
US 11558375B1 · Cao · 2023 [cited by examiner]
US 12118207B2 · Patra · 2024 [cited by examiner]
US 12131136B2 · Nasirishargh · 2024 [cited by examiner]
US 20090174667A1 · Kocienda · 2009 [cited by examiner]
US 20100164897A1 · Morin · 2010 [cited by examiner]
US 20190243959A1 · Radoslaw · 2019 [cited by examiner]
US 20200380115A1 · Knight · 2020 [cited by examiner]
US 20210081524A1 · Moon · 2021 [cited by examiner]
US 20240419294A1 · Krivoruchko · 2024 [cited by examiner]
Blase UR, “Supporting Password-Security Decisions with Data,” Thesis, 2016, Carnegie Mellon University, http://reports-archive.adm.cs.cmu.edu/anon/anon/usr/ftp/isr2016/CMU-ISR-16-110.pdf. [cited by applicant]
Richard Shay, “Creating Usable Policies for Stronger Passwords with MTurk,” Title of the item: Thesis, 2015, Carnegie Mellon University, http://ra.adm.cs.cmu.edu/anon/usr/ftp/usr0/anon/isr2015/CMU-ISR-15-100.pdf. [cited by applicant]
Richard Shay et al.,“ Designing Password Policies for Strength and Usability,” ACM Transactions on Information and System Security, 2016, vol. 18; Issue: 4, ACM, https://dl.acm.org/doi/abs/10.1145/2891411. [cited by applicant]
Anuj Gautam et al., “Improving Password Generation Through the Design of a Password Composition Policy,” Description Language, Proceedings of the Eighteenth Symposium on Usable Privacy and Security, Date: 2022, USENIX A… [cited by applicant]
Saranga KomandurI et al., “Telepathwords: Preventing Weak Passwords by Reading Users' Minds,” Proceedings of the 23rd USENIX Security Symposium, 2014, USENIX Association Link: https://www.usenix.org/system/files/confere… [cited by applicant]