×

Techniques for real-time adaptive password policies

  • US 8,332,918 B2
  • Filed: 12/06/2007
  • Issued: 12/11/2012
  • Est. Priority Date: 12/06/2007
  • Status: Expired due to Fees
First Claim
Patent Images

1. A machine-implemented method residing and implemented in a non-transitory machine-readable medium for executing on a machine, comprising:

  • integrating, by the machine, processing of the method as a supplemental service to an enterprise authentication service that is just invoked by the authentication service when newly presented passwords are being established by the authentication service;

    enforcing, by the machine, a first password policy against users of a network service;

    dynamically evaluating, by the machine, password patterns being used by the users; and

    adapting, by the machine, in real-time to a second password policy in response to evaluation of the password patterns and enforcing the second password policy in place of the first password policy against the users, the first password policy is dynamically altered to adapt to the second password policy and the second password policy evolves based on changing patterns for used passwords, the used passwords stored as regular expressions that define the password patterns without retaining the used passwords, and the first password policy counts a total number of decorations or modifications made to each base pattern identified in the regular expressions and when a predefined threshold of iterative modifications on that base pattern is detected, the second password policy is dynamically enforced without administrative intervention or analysis.

View all claims
  • 11 Assignments
Timeline View
Assignment View
    ×
    ×