US2015074777A1PendingUtilityA1
Dynamically mitigating a noncompliant password
Est. expiryApr 16, 2024(expired)· nominal 20-yr term from priority
G06F 2221/2141G06F 2221/2149G06F 2221/2105G06F 21/46H04L 63/0892G06F 2221/2101H04L 63/083
57
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
Techniques are disclosed for dynamically mitigating a noncompliant password. The method comprises obtaining a password; generating one or more quality scores for the password using a password policy for an authentication and authorization service; determining whether the password has sufficient score quality; in response to determining that the password does not have sufficient score quality, granting to the user a different level of access to the service than if the password meets the quality criteria; wherein the method is performed by one or more computing devices.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method of dynamically mitigating a noncompliant password comprising:
obtaining a password from a computer attempting to access a network resource; generating one or more quality scores for the password using a password policy of an access service that controls access to the network resource; determining whether a particular quality score from among the one or more quality scores has a sufficient score quality; in response to determining that the particular quality score does not have the sufficient score quality, blocking the computer from accessing the network resource; wherein the method is performed by one or more computing devices.
2 . The method of claim 1 , further comprising:
in response to determining that the particular quality score does not have the sufficient score quality, displaying a message on a computer display device; wherein the message includes any one of: a recommendation to change the password, or a recommendation on increasing a score quality for the password.
3 . The method of claim 2 , further comprising, in response to determining that the password has the sufficient score quality, granting to the computer a first level of access to the access service, wherein the first level of access to the access service is associated with a first role of the computer.
4 . The method of claim 1 , further comprising:
comparing the one or more quality scores to a force-password-change threshold value, and in response to determining that any of the one or more quality scores is below the force-password-change threshold, determining that the password does not have the sufficient score quality and forcing the computer to change the password; comparing the one or more quality scores with the force-password-change threshold value and an alert value threshold, and in response to determining that any of the one or more quality scores exceeds the force-password-change threshold but does not exceed the alert value threshold, determining that the password does not have the sufficient score quality and notifying the computer that a change of the password is recommended; comparing the one or more quality scores with the alert value threshold, and in response to determining that any of the one or more quality scores exceeds the alert value threshold, determining that the password has the sufficient score quality.
5 . The method of claim 1 , further comprising obtaining the password from a computer via a graphical user interface when the computer attempts to access the access service.
6 . The method of claim 1 , further comprising:
obtaining the password from a repository of passwords; generating the one or more scores each time a change to the password policy for the access service occurs; generating the one or more scores in part by retrieving, from a machine-readable medium, one or more latest quality scores determined for the password using the password policy; determining the one or more quality scores for the password at least in part based on: one or more symbols used in the password; a length of the one or more symbols used in the password; a number of unique characters in the one or more symbols used in the password; a case of the characters in the one or more symbols used in the password; a sequencing of characters in the one or more symbols used in the password; a statistical analysis of the one or more symbols used in the password; one or more roles assigned to the computer.
7 . The method of claim 1 , further comprising performing one or more responsive actions that include: logging information related to the password; sending a report about the password; generating an alert about the password; forcing a password change; blocking the computer from accessing the access service.
8 . An apparatus for dynamically mitigating a noncompliant password, the apparatus comprising:
an interface unit obtaining a password from a computer attempting to access a network resource; an access service unit coupled to the interface unit and configured to perform:
generating one or more quality scores for the password using a password policy of an access service that controls access to the network resource;
determining whether a particular quality score from among the one or more quality scores has a sufficient score quality;
in response to determining that the particular quality score does not have the sufficient score quality, blocking the computer from accessing the network resource.
9 . The apparatus of claim 8 , wherein the access service unit is further configured to:
in response to determining that the particular quality score does not have the sufficient score quality, displaying a message on a computer display device; wherein the message includes any one of: a recommendation to change the password, or a recommendation on increasing a score quality for the password.
10 . The apparatus of claim 9 , wherein the access service unit is further configured to:
in response to determining that the password has the sufficient score quality, granting to the computer a first level of access to the access service, wherein the first level of access to the access service is associated with a first role of the computer.
11 . The Apparatus of claim 8 , wherein the access service unit is further configured to:
comparing the one or more quality scores to a force-password-change threshold value, and in response to determining that any of the one or more quality scores is below the force-password-change threshold, determining that the password does not have the sufficient score quality and forcing the computer to change the password; comparing the one or more quality scores with the force-password-change threshold value and an alert value threshold, and in response to determining that any of the one or more quality scores exceeds the force-password-change threshold but does not exceed the alert value threshold, determining that the password does not have the sufficient score quality and notifying the computer that a change of the password is recommended; comparing the one or more quality scores with the alert value threshold, and in response to determining that any of the one or more quality scores exceeds the alert value threshold, determining that the password has the sufficient score quality.
12 . The apparatus of claim 8 , wherein the access service unit is further configured to:
obtaining the password from a computer via a graphical user interface when the computer attempts to access the access service.
13 . The apparatus of claim 8 , wherein the access service unit is further configured to:
obtaining the password from a repository of passwords; generating the one or more scores each time a change to the password policy for the access service occurs; generating the one or more scores in part by retrieving, from a machine-readable medium, one or more latest quality scores determined for the password using the password policy; determining the one or more quality scores for the password at least in part based on: one or more symbols used in the password; a length of the one or more symbols used in the password; a number of unique characters in the one or more symbols used in the password; a case of the characters in the one or more symbols used in the password; a sequencing of characters in the one or more symbols used in the password; a statistical analysis of the one or more symbols used in the password; one or more roles assigned to the computer.
14 . The apparatus of claim 8 , wherein the access service unit is further configured to:
performing one or more responsive actions that include: logging information related to the password; sending a report about the password; generating an alert about the password; forcing a password change; blocking the computer from accessing the access service.
15 . A non-transitory computer-readable storage medium storing one or more sequences of instructions which, when executed by one or more processors, cause the one or more processors to perform:
obtaining a password from a computer attempting to access a network resource; generating one or more quality scores for the password using a password policy of an access service that controls access to the network resource; determining whether a particular quality score from among the one or more quality scores has a sufficient score quality; in response to determining that the particular quality score does not have the sufficient score quality, blocking the computer from accessing the network resource.
16 . The non-transitory computer-readable storage medium of claim 15 , comprising additional instructions which, when executed by the one or more processors, cause the one or more processors to perform:
in response to determining that the particular quality score does not have the sufficient score quality, displaying a message on a computer display device; wherein the message includes any one of: a recommendation to change the password, or a recommendation on increasing a score quality for the password.
17 . The non-transitory computer-readable storage medium of claim 16 , comprising additional instructions which, when executed by the one or more processors, cause the one or more processors to perform:
in response to determining that the password has the sufficient score quality, granting to the computer a first level of access to the access service, wherein the first level of access to the access service is associated with a first role of the computer.
18 . The non-transitory computer-readable storage medium of claim 15 , comprising additional instructions which, when executed by the one or more processors, cause the one or more processors to perform:
comparing the one or more quality scores to a force-password-change threshold value, and in response to determining that any of the one or more quality scores is below the force-password-change threshold, determining that the password does not have the sufficient score quality and forcing the computer to change the password; comparing the one or more quality scores with the force-password-change threshold value and an alert value threshold, and in response to determining that any of the one or more quality scores exceeds the force-password-change threshold but does not exceed the alert value threshold, determining that the password does not have the sufficient score quality and notifying the computer that a change of the password is recommended; comparing the one or more quality scores with the alert value threshold, and in response to determining that any of the one or more quality scores exceeds the alert value threshold, determining that the password has the sufficient score quality.
19 . The non-transitory computer-readable storage medium of claim 15 , comprising additional instructions which, when executed by the one or more processors, cause the one or more processors to perform:
obtaining the password from a computer via a graphical user interface when the computer attempts to access the access service.
20 . The non-transitory computer-readable storage medium of claim 15 , comprising additional instructions which, when executed by the one or more processors, cause the one or more processors to perform:
obtaining the password from a repository of passwords; generating the one or more scores each time a change to the password policy for the access service occurs; generating the one or more scores in part by retrieving, from a machine-readable medium, one or more latest quality scores determined for the password using the password policy; determining the one or more quality scores for the password at least in part based on: one or more symbols used in the password; a length of the one or more symbols used in the password; a number of unique characters in the one or more symbols used in the password; a case of the characters in the one or more symbols used in the password; a sequencing of characters in the one or more symbols used in the password; a statistical analysis of the one or more symbols used in the password; one or more roles assigned to the computer.Join the waitlist — get patent alerts
Track US2015074777A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.