IP Library Granted Patent US 12,625,945
Granted Patent B2
US 12,625,945 · App. 18/200,315 · Granted May 12, 2026

Password security warning system

Inventors: Reza Farivar (Champaign, IL); Anh Truong (Champaign, IL); Vincent Pham (Champaign, IL); Austin Grant Walters (Savoy, IL); Galen Rafferty (Mahomet, IL); Jeremy Edward Goodsitt (Champaign, IL)
Assignee: Capital One Services, LLC
G06F21/46G06N3/04G06N3/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,625,945
App. No.
18/200,315
Granted
May 12, 2026
Kind
B2
Abstract

Various embodiments are directed to a password security warning system. An artificial neural network or other types of models may be used to determine whether a password that is created, input, or proposed by a user via an interface includes one or more predictable or typical transformations or combinations of characters derived from user-specific information. Based on the determination, a warning may be provided to the user.

Claims (60)

1 . An apparatus comprising:

a memory storing instructions,

one or more processors operably coupled to the memory and configured to execute the instructions that, when executed by the one or more processors, cause the one or more processors to:

determine one or more patterns associated with a user, the one or more patterns comprising at least one of a user-specific pattern of passwords specific to a user, the user-specific pattern not general to a population of users or combinations of at least: first personal information and second personal information different from the first personal information typical or predictable in weak passwords;

process a plurality of lists of blacklisted passwords received from a plurality of service providers, each of the plurality of lists of blacklisted passwords being received from a corresponding service provider of the plurality of service providers, wherein at least one of the plurality of lists of blacklisted passwords is different than other lists of the plurality of lists of blacklisted passwords, wherein at least one of the plurality of service providers is a financial institution;

train a neural network based at least in part on: the user-specific pattern, a plurality of typical or predictable password transformations, the one or more patterns of the combinations of at least the first and second personal information and the plurality of lists of blacklisted passwords, the trained neural network configured to output a plurality of possible password strings unique to a user in response to user-specific information associated with the user provided to the neural network;

receive a password created by the user;

determine whether the password matches at least one possible password string of the plurality of possible password strings based on a threshold match;

provide a warning message that the password is unsafe or insecure in response to the password matching the at least one possible password string, wherein the one or more processors are further caused to:

allow the warning message to be bypassed and the password to be created in response to the threshold match being below a predetermined threshold.

2 . The apparatus of claim 1 , wherein the user-specific information is provided by the user and comprises one or more of the following: a legal first name, a legal middle name, a legal last name, a nickname, a date of birth, a social security number, a home address, a work address, a telephone number, spousal information, and/or a maiden name.

3 . The apparatus of claim 1 , wherein the instructions, when executed by the one or more processors, further cause the one or more processors to:

perform an Internet search on the user and provide one or more results of the Internet search to the neural network as the user-specific information,

wherein the one or more results of the Internet search comprise information associated with the user from at least one of a social media account, a professional networking profile, a professional profile webpage, a blog, an online dating profile, a public article, or an image.

4 . The apparatus of claim 1 , wherein the plurality of typical or predictable password transformations comprises at least one replacement of a letter with an associated special character.

5 . The apparatus of claim 1 , wherein the plurality of possible password strings output by the neural network comprises at least one or more typical or predictable transformations of the user-specific information and one or more typical or predictable combinations of the user-specific information.

6 . The apparatus of claim 1 , wherein the user-specific pattern is determined based on an identification of a specific pattern used in previous passwords of the user.

7 . The apparatus of claim 1 , wherein the warning message is output to an interface; and

wherein the one or more processors are further caused to:

receive at least one compromised password determined to have been cracked or compromised; and

add the at least one compromised password to at least one of the plurality of lists of blacklisted passwords for updating the training of the neural network to include cracked and compromised passwords.

8 . An apparatus comprising:

at least one memory storing instructions;

one or more processors, operably coupled to the at least one memory, operable to execute the instructions that, when executed by the one or more processors, cause the one or more processors to:

determine a user-specific pattern of passwords specific to a user, the user-specific pattern not general to a population of users;

process a plurality of lists of blacklisted passwords received from a plurality of service providers, each of the plurality of lists of blacklisted passwords being received from a corresponding service provider of the plurality of service providers, wherein at least one of the plurality of lists of blacklisted passwords is different than other lists of the plurality of lists of blacklisted passwords, wherein at least one of the plurality of service providers is a financial institution;

train a neural network based at least in part on the user-specific pattern and the plurality of lists of blacklisted passwords, the trained neural network configured to output a plurality of possible password strings unique to the user based, at least in part, on user-specific information associated with the user provided to the neural network;

receive a password created by the user;

determine whether the password matches at least one possible password string of the plurality of possible password strings based on a threshold match;

output a warning message to an interface indicating the password may be unsafe or insecure; and

allow the warning message to be bypassed and the password to be created in response to the threshold match being below a predetermined threshold.

9 . The apparatus of claim 8 ,

wherein the user-specific pattern is determined based on an identification of a specific pattern used in previous passwords of the user.

10 . The apparatus of claim 8 , the instructions, when executed by the one or more processors, further cause the one or more processors to:

receive at least one compromised password determined to have been cracked or compromised; and

add the at least one compromised password to at least one of the plurality of lists of blacklisted passwords for updating training of the neural network to include cracked and compromised passwords.

11 . The apparatus of claim 8 , wherein the user-specific information is provided by the user and comprises one or more of the following: a legal first name, a legal middle name, a legal last name, a nickname, a date of birth, a social security number, a home address, a work address, a telephone number, spousal information, and/or a maiden name.

12 . The apparatus of claim 8 , wherein the instructions, when executed by the one or more processors, further cause the one or more processors to:

perform an Internet search on the user and provide one or more results of the Internet search to the neural network as the user-specific information,

wherein the one or more results of the Internet search comprise information associated with the user from at least one of a social media account, a professional networking profile, a professional profile webpage, a blog, an online dating profile, a public article, or an image.

13 . The apparatus of claim 8 , wherein the plurality of possible password strings comprises at least one typical or predictable password transformation, the at least one typical or predictable password transformation comprising at least one replacement of a letter with an associated special character.

14 . The apparatus of claim 8 , wherein the plurality of possible password strings output by the neural network comprises at least one typical or predictable transformation of the user-specific information and at least one typical or predictable combination of the user-specific information.

15 . A computer-implemented method, comprising, via at least one computing device:

determining a user-specific pattern of passwords specific to a user, the user-specific pattern not general to a population of users;

processing a plurality of lists of blacklisted passwords received from a plurality of service providers, each of the plurality of lists of blacklisted passwords being received from a corresponding service provider of the plurality of service providers, wherein at least one of the plurality of lists of blacklisted passwords is different than other lists of the plurality of lists of blacklisted passwords, wherein at least one of the plurality of service providers is a financial institution;

training a neural network based at least in part on the user-specific pattern and the plurality of lists of blacklisted passwords, the trained neural network configured to output a plurality of possible password strings unique to the user based, at least in part, on user-specific information associated with the user provided to the neural network;

receiving a password created by the user; and

determining whether the password matches at least one possible password string of the plurality of possible password strings based on a threshold match;

wherein the method further comprises:

outputting a warning message to an interface indicating the password may be unsafe or insecure; and

allowing the warning message to be bypassed and the password to be created in response to the threshold match being below a predetermined threshold.

16 . The method of claim 15 , wherein the user-specific pattern is determined based on an identification of a specific pattern used in previous passwords of the user.

17 . The method of claim 15 , further comprising:

receiving at least one compromised password determined to have been cracked or compromised; and

adding the at least one compromised password to at least one of the plurality of lists of blacklisted passwords for updating training of the neural network to include cracked and compromised passwords.

18 . The method of claim 15 , further comprising:

performing an Internet search on the user and provide one or more results of the Internet search to the neural network as the user-specific information,

wherein the one or more results of the Internet search comprise information associated with the user from at least one of a social media account, a professional networking profile, a professional profile webpage, a blog, an online dating profile, a public article, or an image.

19 . The method of claim 15 , wherein the plurality of possible password strings comprises at least one typical or predictable password transformation, the at least one typical or predictable password transformation comprising at least one replacement of a letter with an associated special character.

20 . The method of claim 15 , wherein the plurality of possible password strings output by the neural network comprises at least one typical or predictable transformation of the user-specific information and at least one typical or predictable combination of the user-specific information.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 17, 2024
From: FARIVAR, REZA; TRUONG, ANH; PHAM, VINCENT; WALTERS, AUSTIN GRANT; RAFFERTY, GALEN; GOODSITT, JEREMY EDWARD
To: CAPITAL ONE SERVICES, LLC
Reel/Frame 066149/0646 →
Continuity (3)
Continuation 17153335 · Jan 20, 2021
Continuation 16549391 · Aug 23, 2019
Related Publication 20230367868A1 · Nov 16, 2023
References Cited (9)
US 20090133120A1 · Cannizzaro · 2009 [cited by examiner]
US 20090150677A1 · Vedula · 2009 [cited by examiner]
US 20120110668A1 · Schechter · 2012 [cited by examiner]
US 20170155675A1 · Howe · 2017 [cited by examiner]
US 20180309721A1 · Ashley · 2018 [cited by examiner]
US 20190121953A1 · Chari · 2019 [cited by examiner]
CN 108763920A · 2018 [cited by examiner]
Knabl, Georg. Thesis “Machine Learning-driven Password Lists”. DOI: 10.13140/RG.2.2.33677.38883. May 2018 (Year: 2018). [cited by examiner]
Machine Translation of CN-108763920-A (Year: 2018). [cited by examiner]