US2008301462A1PendingUtilityA1

System for protecting a user's password

Assignee: IBMPriority: Jun 3, 2004Filed: Jul 22, 2008Published: Dec 4, 2008
Est. expiryJun 3, 2024(expired)· nominal 20-yr term from priority
G06F 21/31
51
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

The present invention relates to a system for protecting a password. A system for providing a protectable password including a storage device, an input mechanism for entering a protectable password in any position and a password validation engine coupled to the storage device and to the input mechanism for analyzing the string of characters and keystrokes to find the protectable password and for validating the apparent password if the protectable password and the random pattern are determined to be present in any position in the string of characters and keystrokes of the apparent password, is provided.

Claims

exact text as granted — not AI-modified
1 . A computer-readable medium containing program instructions for providing a protectable password comprising instructions for:
 entering an apparent password into a computing system, wherein the apparent password is a string of characters and keystrokes including the password and an arbitrary number of characters and keystrokes unrelated to the protectable password;   entering the protectable password in any position within the string of characters and keystrokes of the apparent password;   analyzing the entered apparent password by the computing system to determine a presence or absence of the protectable password; and   validating the apparent password if the protectable password is determined to be present in any position within the string of characters and keystrokes of the apparent password.   
   
   
       2 . The computer-readable medium of  claim 1  wherein instruction of entering an apparent password into a computing system further includes:
 entering the protectable password in a first position in the apparent password by the user.   
   
   
       3 . The computer-readable medium of  claim 1 , wherein instruction of entering an apparent password into a computing system includes:
 fragmenting the protectable password into a plurality of segments;   entering a first segment of the protectable password;   entering a string of characters and keystrokes unrelated to the protectable password;   entering a next segment of the protectable password; and   repeating steps of entering a string of characters and keystrokes unrelated to the protectable password and entering a next segment of the protectable password until a last segment of the protectable password has been entered.   
   
   
       4 . The computer-readable medium of  claim 1 , wherein instruction entering an apparent password into a computing system includes:
 entering a first token delimiter immediately before the protectable password; and   entering a second token delimiter immediately after the protectable password.   
   
   
       5 . The computer-readable medium of  claim 4 , wherein instruction entering the protectable password in any position includes:
 detecting the first token delimiter in the string;   detecting the second token delimiter in the string; and   comparing the characters in the string between the first and second token delimiters with the protectable password.   
   
   
       6 . The computer-readable medium of  claim 4 , wherein the first and second token delimiters are defined by a user. 
   
   
       7 . A computer-readable medium containing program instructions for providing a protectable password comprising instructions for:
 creating a random pattern in response to receiving a request from a user to access a protected resource in a computing system, wherein the random pattern is associated with the request;   displaying the random pattern associated with the request to a user;   allowing the user to enter an apparent password into the computing system that controls access to the protected resource, wherein the apparent password is a string of characters and keystrokes including the password, the random pattern and an arbitrary number of characters and keystrokes unrelated to the protectable password;   entering the protectable password in any position within the string of characters and keystrokes of the apparent password;   analyzing the entered apparent password by the computing system to determine a presence or absence of the protectable password and the random pattern associated with the request; and   validating the apparent password if the protectable password and the random pattern are determined to be present in any position in the string of characters and keystrokes of the apparent password.   
   
   
       8 . The computer-readable medium of  claim 7 , wherein instruction analyzing the entered apparent password further includes:
 entering the protectable password in a first position in the apparent password by the user.   
   
   
       9 . The computer-readable medium of  claim 7 , wherein instruction entering the protectable password includes:
 fragmenting the protectable password into a plurality of segments;   entering a first segment of the protectable password;   entering a string of characters and keystrokes unrelated to the protectable password;   entering a next segment of the protectable password; and   repeating steps of entering a string of characters and keystrokes unrelated to the protectable password and entering a next segment of the protectable password until a last segment of the protectable password has been entered.   
   
   
       10 . The computer-readable medium of  claim 7 , wherein instruction analyzing entering the protectable password includes:
 (c 1 ) entering a first token delimiter immediately before the password; and   (c 2 ) entering a second token delimiter immediately after the password,   wherein the first and second token delimiters are defined by the user.   
   
   
       11 . A system for providing a protectable password comprising:
 a storage device for storing data including the password;   an input mechanism for entering the protectable password in any position within the string of characters and keystrokes of the apparent password and analyzing the entered apparent password by the computing system to determine a presence or absence of the protectable password and the random pattern associated with the request; and   a password validation engine coupled to the storage device and to the input mechanism for analyzing the string of characters and keystrokes to find the protectable password and for validating the apparent password if the protectable password and the random pattern are determined to be present in any position in the string of characters and keystrokes of the apparent password.   
   
   
       12 . The system of  claim 11 , wherein the user enters the protectable password in a first position in the apparent password. 
   
   
       13 . The system of  claim 11 , wherein the user fragments the protectable password into a plurality of segments; enters a first segment of the protectable password; enters a string of characters and keystrokes unrelated to the protectable password; enters a next segment of the protectable password; and repeats steps of entering a string of characters and keystrokes unrelated to the protectable password and entering a next segment of the protectable password until a last segment of the protectable password has been entered. 
   
   
       14 . The system of  claim 11  further including means for allowing the user to define a first token delimiter and a second token delimiter, wherein when the user enters the apparent password, the user enters the first token delimiter immediately before the protectable password and enters the second token delimiter immediately after the protectable password. 
   
   
       15 . The system of  claim 14 , wherein the password validation engine detects the first and second token delimiters in the string and compares the characters in the string between the first and second token delimiters with the protectable password. 
   
   
       16 . The system of  claim 11  further comprising:
 a random pattern generator coupled to the password validation engine for creating a random pattern associated with a request by the user to access a protected resource in a computing system; and   a display for displaying the random pattern associated with the request to the user,   wherein the apparent password includes a user's password and the random pattern and the password validation engine analyzes the apparent password to find the user's password and the random pattern associated with the request.

Join the waitlist — get patent alerts

Track US2008301462A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.