Password Evaluation Engine for Attacker-Model Strength Assessment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing password evaluation methods fail to accurately assess password strength due to lack of consideration for an attacker's knowledge, computational resources, and time, leading to ineffective password policies and increased vulnerability to cracking attacks.

Innovation Solution

A password evaluation engine that redefines password complexity and strength by calculating the adjusted search space based on an attacker's knowledge and resources, incorporating factors like computational power and time, to provide a more accurate assessment of password resilience.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional password evaluation methods are used, then the evaluation process is simple, but the accuracy of password strength assessment is insufficient

Engineering Contradiction:
Improvepassword strength assessment accuracyVSAvoidevaluation system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The evaluation system is divided into multiple independent modules: rule set identification module, search space calculation module, attacker knowledge assessment module, computational resource analysis module, and strength determination module. Each module handles a specific aspect of the evaluation, improving accuracy while maintaining manageable system complexity through functional decomposition.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimension of evaluation by considering attacker's knowledge level and computational resources, transforming the traditional single-dimension password strength assessment into a multi-dimensional evaluation framework that incorporates attacker capabilities, thereby significantly improving assessment accuracy.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If password policies are made more restrictive to improve security, then password strength increases, but user convenience decreases

Engineering Contradiction:
Improvesecurity effectivenessVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The evaluation system dynamically adjusts password policy recommendations based on the calculated strength and identified vulnerabilities. Instead of applying fixed restrictive rules, the system adapts requirements according to the specific password characteristics and attacker threat models, achieving security effectiveness while minimizing unnecessary user inconvenience.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system provides feedback to users through detailed evaluation results and specific policy recommendations. Users receive actionable guidance on how to improve their passwords based on the identified weaknesses, enabling them to make informed decisions that balance security requirements with usability.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If the search space is calculated without considering attacker knowledge, then the calculation is simpler, but the evaluation accuracy deteriorates

Engineering Contradiction:
Improvesearch space calculation accuracyVSAvoidcalculation complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system performs preliminary identification of the rule set and attacker knowledge level before conducting the search space calculation. By pre-assessing the attacker's understanding of password generation rules, the system can adjust the search space boundaries accordingly, improving calculation accuracy without requiring complex real-time adjustments during the evaluation process.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10546116B2Systems and methods evaluating password complexity and strength
Publication Date: 2020.01.28 MASSACHUSETTS INST OF TECH
  • US10546116B2 patent drawing
  • US10546116B2 patent drawing
  • US10546116B2 patent drawing

AI summary

A password evaluation engine used to evaluate a user's password that redefines the concepts of password complexity and password strength is discussed. Password complexity may be calculated by the evaluation engine so as to take into account the amount of knowledge possessed by a potential attacker, seeking to crack the password, of the rules corresponding to a rule set used for generating the password. A determination of password strength by the evaluation engine may consider a potential attacker's computational resources, the protection function used to protect/store a password and the amount of time available to the attacker to crack the password with respect to an identified search space based on the attacker's knowledge. Embodiments also enable a password strength estimator to be evaluated and policy recommendations to be generated for an entity's password policy requirements.