Password Policy Enforcement via Regular Expressions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication systems lack efficient mechanisms for managing and enforcing password policies across customer devices, leading to potential security vulnerabilities due to inconsistent and uncontrolled password creation.

Innovation Solution

An apparatus and method that utilize a customer device to receive a password policy defined by regular expressions, evaluate passwords against these policies, and either permit or prevent password setting based on compliance, facilitated through device management protocols like TR-069 or TR-369.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If password policies are enforced using traditional methods, then security control is limited, but system complexity and implementation difficulty increase

Engineering Contradiction:
Improvesecurity controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a password policy server as an intermediary component that mediates between the device management system and password validation. This server receives password policies from the service provider, converts them into regular expressions, and distributes them to customer devices. By placing this intermediary layer, the patent achieves centralized security control without requiring complex integration into each device's existing authentication mechanisms, thus improving security control while limiting the increase in system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional mechanical password policy enforcement mechanisms with a software-based regular expression evaluation system. Instead of using complex device configurations or hardware security modules, the system uses programmable regular expression patterns that can be dynamically updated and distributed. This substitution allows for flexible security policies to be implemented through software updates rather than hardware changes or complex configuration procedures.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If custom password policies are implemented for each service provider, then security requirements are met, but device compatibility and ease of deployment deteriorate

Engineering Contradiction:
Improvesecurity requirementsVSAvoiddevice compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal password policy enforcement mechanism that can serve multiple service providers and device types through a single system architecture. The password policy server uses standardized device management protocols (such as TR-069) and regular expressions that can be applied across different device platforms and service provider requirements. This universal approach allows the same system to enforce customized security policies for each service provider while maintaining broad device compatibility, eliminating the need for provider-specific implementations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If complex password rules are enforced, then password strength improves, but user convenience and ease of operation decrease

Engineering Contradiction:
Improvepassword strengthVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent enables the system to automatically evaluate passwords against the configured regular expression patterns without requiring user intervention or manual policy configuration on each device. The password policy server automatically converts service provider security requirements into regular expressions and enforces them transparently during password creation or modification operations. Users simply need to enter their desired password, and the system automatically checks compliance, providing strong password enforcement while maintaining ease of operation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250068708A1Management and enforcement of password policies based on regular expressions and device management capabilities
Publication Date: 2025.02.27 NOKIA SOLUTIONS & NETWORKS OY
  • US20250068708A1 patent drawing
  • US20250068708A1 patent drawing
  • US20250068708A1 patent drawing

AI summary

Various example embodiments for supporting security for communication networks are presented herein. Various example embodiments may be configured to allow service providers of communication networks (e.g., Internet Service Providers (ISPs), Communication Service Providers (CSPs), or the like, as well as various combinations thereof) to support configuration and enforcement of password rules for customer devices of the communication networks (e.g., customer devices such as customer gateways and customer premises equipments (CPEs) supported by such customer gateways), using configurable regular expressions through a device management data model (e.g., a Broadband Forum (BBF) data model such as a TR-98 data model, a TR-181 data model, or the like, as well as various combinations thereof), for controlling passwords created for the customer devices of the communication networks through a device management interface (e.g., a Web Graphical User Interface (WebGUI) or the like).