IP Library Granted Patent US 11,062,018
Granted Patent B2
US 11,062,018 · App. 15/569,819 · Granted Jul 13, 2021

Platform for generation of passwords and/or email addresses

Inventor: Michael Hugh Thomas Dymond (Pewsey Wiltshire, GB)
Assignee: PHANTOMKEY TECHNOLOGY LIMITED
G06F21/46G06F21/41H04L9/0643H04L9/0861H04L9/0863H04L9/3228H04L51/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,062,018
App. No.
15/569,819
Granted
Jul 13, 2021
Kind
B2
Abstract

A password and/or email address management platform configured to regenerate a previously generated password for a given web domain or digital system without permanently storing the previously generated password. The platform can operate without maintaining a permanent store or list of other user-related information, e.g. a list of web domains or systems for which passwords have been generated. In an embodiment, the platform performs the steps of concatenating a plurality of password input data elements into a requested phantom password input data string, applying a hashing algorithm to the requested phantom password input data string to generate a phantom password hash, applying a hash-to-string function to convert the phantom password hash to a phantom password, and purging the password generation system of the phantom password after it is notified to a user.

Claims (67)

1. A method of generating a phantom password for authenticating a user, the method comprising:

receiving across a network from a remote client device at a server configured as a phantom password generation system, a request for generation or regeneration of a phantom password for an interaction between the remote client device and a remote digital resource, the remote digital resource being separate from the remote client device and accessible across the network;

in the phantom password generation system:

concatenating a plurality of password input data elements into a requested phantom password input data string;

applying a hashing algorithm to the requested phantom password input data string to generate a phantom password hash;

applying a hash-to-string function to convert the phantom password hash to a phantom password;

notifying the remote client device of the phantom password; and

purging the password generation system of the phantom password by:

deleting information representative of the phantom password from any portion of a memory of the phantom password generation system on which it resides, and

overwriting the portion of the memory with other information.

2. The method according to claim 1 , wherein the phantom password generation system includes a system database arranged to store a stored user password hash and a randomizer for each user.

3. The method according to claim 2 , wherein the randomizer is a randomly ordered string of different characters.

4. The method according to claim 3 , wherein the plurality of password input data elements are concatenated in an order selected based on a predetermined portion of characters in the randomizer.

5. The method according to claim 2 , wherein the plurality of password input data elements comprises:

a username for the user stored in the system database;

an internal salt selected from a list based on a first predetermined character of the randomizer; and

an identifier representative of the digital resource.

6. The method according to claim 2 including, before receiving the request for generation or regeneration of a password for a digital resource, logging in the user to the password generation system, the logging in step including:

receiving a user password from the user;

concatenating a plurality of login input data elements including the user password into a login input data string;

applying a hashing algorithm to the login input data string to generate a login user password hash; and

matching the login user system password hash with a stored user password hash stored in the system database, and

wherein the plurality of login input data elements are concatenated in an order selected based on the randomizer.

7. The method according to claim 6 , including, after successfully matching the login user password hash with a stored user password hash stored in the system database:

concatenating a plurality of session input data elements including the user password into a session input data string;

applying a hashing algorithm to the session input data string to generate a session user password hash; and

storing the session user password hash in the current session with the password generation system,

wherein the session user password hash is different from the stored user password hash stored in the system database.

8. The method according to claim 7 , wherein the plurality of session input data elements comprises:

a username for the user stored in the system database;

the user password; and

an internal salt selected from a list based on a third predetermined character of the user's randomizer, and

wherein the plurality of session input data elements are concatenated in an order selected based on the randomizer.

9. A method of generating an email address for a user to use with a remote digital resource, the method comprising:

receiving across a network from a remote client device at a server configured as a phantom email address generation system from a remote client device, a request for generation or regeneration of a phantom email address for use in an interaction between the remote client device and the remote digital resource, the remote digital resource being separate from the remote client device and accessible across the network;

in the email address generation system:

concatenating a plurality of email address input data elements into a requested email address input data string;

applying a hashing algorithm to the requested email address input data string to generate a phantom email address hash;

applying a hash-to-string function to convert the phantom email address hash to a local part of a phantom email address;

appending a domain part to the local part to form a complete phantom email address;

notifying the remote client device of the complete phantom email address; and

purging the email address generation system of the local part of the phantom email address by:

deleting information representative of the phantom email address from any portion of a memory of the email address generation system on which it resides, and

overwriting the portion of the memory with other information.

10. The method according to claim 9 , wherein the email address generation system includes a system database arranged to store a username and a randomizer for each user.

11. The method according to claim 10 , wherein the randomizer is a randomly ordered string of different characters.

12. The method according to claim 10 , wherein the plurality of email address input data elements comprises:

the username stored for the user;

an identifier representative of the digital resource; and

an internal salt selected from a list based on a fourth predetermined character of the user's randomizer, and

wherein the plurality of email address input data elements are concatenated in an order selected based on the randomizer.

13. The method according to claim 9 , including generating a stored email address hash for storage in the system database, and comparing the generated stored email address hash with the system database to ensure that the complete email address is not already in use in the system.

14. The method according to claim 13 , wherein generating the stored email address hash comprises:

concatenating a plurality of email address reference input elements into an email address reference input data string; and

applying a hashing algorithm to the email address reference input data string,

wherein the plurality of email address reference input elements comprises:

the complete phantom email address, and

an internal salt selected from a list based on a characteristic of the complete phantom email address.

15. The method according to claim 14 , wherein the characteristic is a predetermined character in the complete phantom email address.

16. The method according to claim 10 including generating a domain/key hash for storage in the system database as a stored identifier for the digital resource, wherein generating the domain/key hash comprises:

concatenating a plurality of domain/key input elements into a domain/key input data string; and

applying a hashing algorithm to the domain/key input data string,

wherein the plurality of domain/key input elements comprises:

the complete phantom email address;

an identifier representative of the digital resource; and

an internal salt selected from a list based on a fifth predetermined character of the randomizer, and

wherein the plurality of domain/key input data elements are concatenated in an order selected based on the randomizer.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 1, 2021
From: DYMOND, MICHAEL HUGH THOMAS
To: PHANTOMKEY TECHNOLOGY LIMITED
Reel/Frame 056401/0074 →
Priority Claims (1)
GB 1507436.2 · Apr 30, 2015 · national
Continuity (1)
Related Publication 20180144122A1 · May 24, 2018