IP Library Patent Application 17029008
Patent Application
App. No. 17/029,008

AUTOMATING PASSWORD CHANGE MANAGEMENT

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
17/029,008
Filed
Sep 22, 2020
Art Unit
2491
USPC
726/28
Abstract

A password management service provides automated password management. In one embodiment, a method for automating password changes begins in response to a determination that automated password changes are authorized. In response, a data mining session is initiated. Within the data mining session, a set of third party applications or sites are identified. Then, and responsive to receipt of a password reset flow authorization, a password reset flow to one or more of the third party applications or sites is initiated by the service. Thereafter, and still within the data mining session, and for each of the one or more third party applications or sites, a determination is made whether a password reset confirmation link has been received by the service. In response to a determination that a password reset confirmation link has been received for a given third party application or site, the service uses the password reset confirmation link to perform an automated password reset and thereby obtain a new user password for the application or site.

Claims (45)

1 . A method to automate password changes in a password management service, comprising:

responsive to a determination that automated password changes are authorized, initiating a data mining session;

within the data mining session, identifying a set of third party applications or sites;

responsive to receipt of a password reset flow authorization, automatically initiating a password reset flow to one or more of the third party applications or sites;

within the data mining session, and for each of the one or more third party applications or sites, determining whether a password reset confirmation link has been received; and

responsive to a determination that a password reset confirmation link has been received for a given third party application or site, using the password reset confirmation link to perform an automated password reset and thereby obtain a new user password.

2 . The method as described in claim 1 wherein the set of third party applications or sites are identified from one of: a user e-mail in-box, a browser history, and a list of common or popular third party applications or sites.

3 . The method as described in claim 1 wherein a data mining session is initiated with at least one email provider associated with the user.

4 . The method as described in claim 1 wherein the password reset confirmation link is provided to a browser plug-in or add-on to facilitate the automated password reset from the browser plug-in or add-on.

5 . The method as described in claim 1 further including storing the new user passwords in a password management vault associated with the user.

6 . The method as described in claim 1 further including:

exposing at least one third party application or site to a user as a potential candidate for password reset; and

receiving the password reset flow authorization from the user.

7 . The method as described in claim 6 further including closing the data mining session upon completing of the automated password reset for each of the third party application or sites for which the user has provided a password reset flow authorization.

8 . The method as described in claim 6 wherein the third party application or site is exposed to the user as it is discovered during the data mining session.

9 . The method as described in claim 5 further including storing the password management vault as an encrypted blob at the password management service.

10 . The method as described in claim 1 wherein the user is a mobile device user.

11 . Apparatus, comprising:

a hardware processor;

computer memory holding computer program instructions to provide automated password management, the computer program instructions operative:

in response to a determination that automated password changes are authorized, to initiate a data mining session;

within the data mining session, to identify a set of third party applications or sites;

in response to receipt of a password reset flow authorization, to initiate a password reset flow to one or more of the third party applications or sites; within the data mining session, and for each of the one or more third party applications or sites, to determine whether a password reset confirmation link has been received; and

in response to a determination that a password reset confirmation link has been received for a given third party application or site, to obtain a new user password for the application or site using the password reset confirmation link to perform an automated password reset.

12 . The apparatus as described in claim 11 wherein the set of third party applications or sites are identified from one of: a user e-mail in-box, a browser history, and a list of common or popular third party applications or sites.

13 . The apparatus as described in claim 11 wherein a data mining session is initiated with at least one email provider associated with the user.

14 . The apparatus as described in claim 11 wherein the computer program instructions are further operative to provide the password reset confirmation link to a browser plug-in or add-on to facilitate the automated password reset from the browser plug-in or add-on.

15 . The apparatus as described in claim 11 wherein the computer program instructions are further operative to store the new user passwords in a password management vault associated with the user.

16 . The method as described in claim 11 wherein the computer program instructions are further operative to:

expose at least one third party application or site to a user as a potential candidate for password reset; and

receive the password reset flow authorization from the user.

17 . The apparatus as described in claim 16 wherein the computer program instructions are further operative to close the data mining session upon completing of the automated password reset for each of the third party application or sites for which the user has provided a password reset flow authorization.

18 . The apparatus as described in claim 16 wherein the third party application or site is exposed to the user as it is discovered during the data mining session.

19 . The apparatus as described in claim 15 wherein the computer program instructions are operative to store the password management vault as an encrypted blob.

20 . Software-as-a-service system for password change management, comprising:

a network-accessible cloud service having a data repository; and

a browser plug-in or add-in configured to be executed in an end user computing system distinct from the network-accessible cloud service;

the network-accessible cloud service operative in response to a determination that automated password changes are authorized:

to initiate a data mining session;

within the data mining session, to identify a set of third party applications or sites;

in response to receipt of a password receipt flow authorization, to initiate a password reset flow to one or more of the third party applications or sites;

within the data mining session, and for each of the one or more third party applications or sites, to determine whether a password reset confirmation link has been received; and

in response to a determination that a password reset confirmation link has been received for a given third party application or site, providing the password reset confirmation link to the browser plug-in or add-in.

21 . The system as described in claim 20 wherein the browser plug-in or add-in uses the password reset confirmation link to obtain a new user password for the application or site.

22 . The system as described in claim 20 wherein the data repository stores passwords of a user, the passwords being stored as an encrypted blob.

Assignments (8)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 058708/0615) Recorded Mar 15, 2024
From: BARCLAYS BANK PLC, AS COLLATERAL AGENT
To: LASTPASS US LP
Reel/Frame 066800/0140 →
SECURITY INTEREST Recorded Feb 16, 2024
From: GOTO COMMUNICATIONS, INC.; GOTO GROUP, INC.; LASTPASS US LP
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION, AS THE NOTES COLLATERAL AGENT
Reel/Frame 066614/0355 →
SECURITY INTEREST Recorded Feb 16, 2024
From: GOTO COMMUNICATIONS, INC.,; GOTO GROUP, INC., A; LASTPASS US LP,
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION, AS THE NOTES COLLATERAL AGENT
Reel/Frame 066614/0402 →
SECURITY INTEREST Recorded Feb 7, 2024
From: GOTO GROUP, INC.,; GOTO COMMUNICATIONS, INC.; LASTPASS US LP
To: BARCLAYS BANK PLC, AS COLLATERAL AGENT
Reel/Frame 066508/0443 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 1, 2022
From: LOGMEIN USA, INC.
To: LASTPASS US LP
Reel/Frame 058848/0235 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 1, 2022
From: LOGMEIN, INC.
To: LOGMEIN USA, INC.
Reel/Frame 058847/0907 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 27, 2022
From: SIEGRIST, JOSEPH
To: LOGMEIN, INC.
Reel/Frame 058787/0356 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jan 6, 2022
From: LASTPASS US LP
To: BARCLAYS BANK PLC
Reel/Frame 058708/0615 →