发明名称 Systems and methods for evaluating a password policy
摘要 Systems, methods and articles of manufacture for evaluating a password policy are disclosed. The password evaluation system receives password policy data regarding a password policy, including a password constraint. The system analyzes the password policy data to determine a usability index and a password strength index for the password policy, and also determines a usability index and password strength index for a plurality of modified password policies having password constraints different from the password policy. The system then provides a graphical representation of the usability index and the password strength for the password policy and the modified password policies, thereby allowing a password designer to optimize the tradeoffs between usability and security of a password policy.
申请公布号 US8769607(B1) 申请公布日期 2014.07.01
申请号 US201113014406 申请日期 2011.01.26
申请人 Intuit Inc. 发明人 Jerdonek Robert A.;Chung Christopher C.
分类号 G06F17/00 主分类号 G06F17/00
代理机构 Vista IP Law Group LLP 代理人 Vista IP Law Group LLP
主权项 1. A method for evaluating a password policy, comprising: receiving at an evaluation system, from a user, password policy data regarding a password policy, including a password constraint; analyzing, by the evaluation system, said password policy data to determine a usability index and a password strength index for said password policy; determining, by the evaluation system, a usability index and a password strength index for a plurality of modified password policies having password constraints different from said password policy; creating, by the evaluation system, a curve of the usability against the password strength index for said password policy and said modified password policies; determining, by the evaluation system, one or more inflection points in said curve where a change in the password strength index has an increased effect on the usability index; and providing to the user, a graphical representation of the usability index and the password strength for said password policy and said modified password policies, and providing to the user a recommended password policy constraint based on the one or more inflection points.
地址 Mountain View CA US