IP Library › Granted Patent US 9,984,247
Granted Patent B2
US 9,984,247 · App. 14/945,447 · Granted May 29, 2018

Password theft protection for controlling access to computer software

Inventors: Ariel Farkash (Shimshit, IL); Ayman Jarrous (Shafa-amer, IL); Micha Moffie (Zichron Yaakov, IL)
Assignee: International Business Machines Corporation
G06F21/6218H04L9/30H04L9/3263H04L63/083
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,984,247
App. No.
14/945,447
Granted
May 29, 2018
Kind
B2
Abstract

Accessing a password-secured computer software application by acquiring an input password, generating at a first computer an output password from the input password using password generation data, where the output password differs from the input password, and providing the output password to a second computer as part of a request to access a password-secured computer software application using the output password, where the password-secured computer software application is accessible using the output password, and where the password-secured computer software application is inaccessible using the input password.

Claims (38)

1. A method for accessing a password-secured computer software application, the method comprising:

acquiring an input password;

generating at a first computer an output password from the input password using password generation data, wherein the output password differs from the input password, and

providing the output password accompanied by a user identifier that is associated with the output password to a second computer as part of a request to access a password-secured computer software application using the output password when accompanied by the user identifier,

wherein the password-secured computer software application is accessible using the output password when accompanied by the user identifier,

wherein the password-secured computer software application is inaccessible using the input password when accompanied by the user identifier,

wherein the acquiring comprises acquiring wherein the input password is input into a web page of the password-secured computer software application,

wherein the generating comprises generating the output password by using the password generation data in combination with data associated with the web page of the password-secured computer software application, and

wherein the generating comprises generating wherein the data associated with the web page includes any of a portion of a network address associated with the web page, and a certificate signature public key associated with the web page.

2. The method of claim 1 wherein the generating comprises generating wherein the password generation data includes an encryption key.

3. The method of claim 1 wherein the generating comprises generating wherein the password generation data includes a seed for use with a predefined data transformation algorithm.

4. The method of claim 1 wherein the generating comprises generating the output password in accordance with a predefined password format.

5. A system for accessing a password-secured computer software application, the system comprising:

a password acquirer configured to acquire an input password; and

a password generator configured to

generate at a first computer an output password from the input password using password generation data, wherein the output password differs from the input password, and

provide the output password accompanied by a user identifier that is associated with the output password to a second computer as part of a request to access a password-secured computer software application using the output password when accompanied by the user identifier,

wherein the password-secured computer software application is accessible using the output password when accompanied by the user identifier,

wherein the password-secured computer software application is inaccessible using the input password when accompanied by the user identifier,

wherein the input password is input into a web page of the password-secured computer software application,

wherein the password generator is configured to generate the output password by using the password generation data in combination with data associated with the web page of the password-secured computer software application, and

wherein the data associated with the web page includes any of a portion of a network address associated with the web page, and a certificate signature public key associated with the web page.

6. The system of claim 5 wherein the password generation data includes an encryption key.

7. The system of claim 5 wherein the password generation data includes a seed for use with a predefined data transformation algorithm.

8. The system of claim 5 wherein the password generator is configured to generate the output password in accordance with a predefined password format.

9. A computer program product for accessing a password-secured computer software application, the computer program product comprising:

a non-transitory, computer-readable storage medium; and

computer-readable program code embodied in the storage medium, wherein the computer-readable program code is configured to

acquire an input password,

generate at a first computer an output password from the input password using password generation data, wherein the output password differs from the input password, and

provide the output password accompanied by a user identifier that is associated with the output password to a second computer as part of a request to access a password-secured computer software application using the output password when accompanied by the user identifier,

wherein the password-secured computer software application is accessible using the output password when accompanied by the user identifier,

wherein the password-secured computer software application is inaccessible using the input password when accompanied by the user identifier,

wherein the input password is input into a web page of the password-secured computer software application,

wherein the computer-readable program code is configured to generate the output password by using the password generation data in combination with data associated with the web page of the password-secured computer software application, and

wherein the data associated with the web page includes any of a portion of a network address associated with the web page, and a certificate signature public key associated with the web page.

10. The computer program product of claim 9 wherein the password generation data includes an encryption key.

11. The computer program product of claim 9 wherein the password generation data includes a seed for use with a predefined data transformation algorithm.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 19, 2015
From: FARKASH, ARIEL; JARROUS, AYMAN; MOFFIE, MICHA
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 037078/0756 →
Continuity (1)
Related Publication 20170147826A1 · May 25, 2017