Invalidity dossier

US 5588056

Method and system for generating pronounceable security passwords

Current assignee: Verizon Patent and Licensing Inc

Added 9/26/2026, 4:00:50 PM

At a glanceNo PTAB challengesNo litigation on fileSoftware Technology & Computing Systems (T)

Active provider: DeepSeek · deepseek-v4-flash

Auto-generating section 1 of 2: Extensions…

Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.

Patent summary

Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.

✓ Generated

I'll search for authoritative information on this specific patent number, including any litigation or docket activity.

Let me verify the claim structure and check for any litigation specific to this patent number.

Let me verify the total claim set of US5588056 and confirm there is no litigation docket activity.

US Patent 5,588,056 — Summary

Source note: I worked from the authoritative full text and Google Patents bibliographic record for US5588056A (https://patents.google.com/patent/US5588056/en), plus corroborating full-text mirrors (FreePatentsOnline/5588056.html, patents.justia.com/patent/5588056, everypatent.com/comp/pat5588056.html). I did not find any litigation, PTAB, or CAFC 2026 docket activity for this patent (see "Litigation check" below).

Bibliographic data (verified)

Field Value
Patent number US 5,588,056 A
Title Method and system for generating pronounceable security passwords
Inventor Ravi Ganesan
Original assignee Bell Atlantic Network Services, Inc.
Current assignee (per Google Patents) Verizon Patent and Licensing Inc. (via Verizon Services Corp., change of name from Bell Atlantic)
Application number 08/328,226
Filing date October 25, 1994
Issue date December 24, 1996
Priority date October 25, 1994
Status Expired – Lifetime (anticipated expiration October 25, 2014)
Classifications G06F 21/31 (user authentication); G07F 7/10 (coded identity card/PIN)

Related family member (do not conflate): US 5,850,448, "Programmed computer for generating pronounceable security passwords," also Ravi Ganesan, filed October 15, 1996 (app. 08/731,427), which claims priority to the '056 application. The '448 patent carries the apparatus/programmed-computer claims; several search results blended the two documents. I have kept them separate here.

Abstract (as issued)

A pronounceable security password is generated using a plurality of first word segment portions and second word segment portions, each of which has at least one character. A transition number, for each of the plurality of first word segment portions, is identified, preferably using a Markov model. Each transition number corresponds to the number of different second word segment portions which can be combined with the first word segment portion to form a pronounceable word segment, such as a word syllable. A first word segment portion is randomly selected. The selection of any one of the plurality of first word segment portions is of substantially equal probability. A second word segment portion, to which the transition number associated with the selected first word segment portion corresponds, is then randomly selected. The selection of any one of the corresponding second word segment portions is likewise of substantially equal probability. The selected first and second word segment portions are combined to form at least a part of the pronounceable security password.

Independent claims — plain language

Claim 1 — Method (random equiprobable segment selection with an acceptability check). A computer-implemented method for building a pronounceable password from two families of word pieces: "first word segment portions" (e.g., bigrams/trigrams) and "second word segment portions" (e.g., unigrams). Each first portion has (i) a set of second portions that combine with it to form a pronounceable word segment and (ii) a "transition number" equal to how many such second portions are in that set. The method:

  1. randomly selects a first word segment portion, where every first portion is equally likely to be chosen (no frequency weighting by English-language probability);
  2. randomly selects a second word segment portion from the set associated with the chosen first portion, again with equal probability across that set;
  3. combines them into a first pronounceable word segment;
  4. tests whether the resulting segment is acceptable — specifically, whether consecutive characters of the segment correspond to a first word segment portion whose transition number falls below a threshold; and
  5. only if acceptable, generates the password to include that pronounceable word segment (with dependent claims adding further segments, thresholds, and applications such as encryption/decryption).

The core inventive concept: uniform-probability selection of both segment levels, so the generated distribution is not skewed toward high-frequency English letter sequences.

Claim 22 — Method (category-based selection). A companion independent method in which each first word segment portion is pre-categorized into one of at least two categories based on its transition number. The method identifies one or more "selection categories" whose members have transition numbers at or above a first threshold transition number; randomly selects a first word segment portion from within those selection categories (equal probability among them); randomly selects an associated second word segment portion (equal probability within that set); combines them; and generates the password including that word segment only if consecutive characters of it do not correspond to a first word segment portion categorized in a non-selection category. This is the "bucket"-based variant that avoids the "smallest bucket" attack the specification criticizes in the Sandia, Gasser/NIST, and DEC generators.

Dependent claims (representative): each first portion is a bigram or trigram (cl. 14), each second portion is a unigram (cl. 15), characters are alphabet letters (cl. 16), transition numbers are derived using a Markov model (cl. 17), the password is eight or more characters (cl. 18) with at least six characters drawn from the second word segment portions (cl. 19), the password forms part of a private key of a cryptosystem such as RSA (cls. 20–21), and the password is applied to encrypt or decrypt a message (cl. 13). Additional dependent claims of the claim-22 family (cls. 23–30, seen in full-text mirrors) add substitute-segment selection when the acceptability test fails.

Claim count uncertainty: The claim set runs at least through claim 30 (claim 30 depends from claim 29). I could not authoritatively confirm from the sources retrieved whether US5588056 contains any additional independent claims beyond claims 1 and 22 (e.g., a "system" claim), or the exact terminal claim number. The patent's title and specification describe both method and system embodiments, but the programmed-computer/apparatus claims appear in the continuation US5850448. This is a genuine gap in the record I retrieved, not a finding that no such claim exists.

Context the specification supplies

  • The patent frames the problem with "Criterion 5": a password scheme is weak if the password space can be split into buckets where the probability of a user drawing from a bucket exceeds that bucket's share of the total space — "the system is only as secure as its smallest bucket."
  • It critiques three prior generators: the Sandia/Kerberos system (25 equally indexed templates producing a highly non-uniform bucket distribution and adding an 8th noisy character), the Gasser/NIST FIPS-92 system (34 units with English-occurrence probabilities), and the DEC Markov-model generator (which, the patent asserts, inherits small-bucket vulnerability because transitions follow English-language probabilities).
  • The invention's remedy: retain Markov-derived legality (which transitions are pronounceable) but decouple selection probability from English-language frequency, using uniform random selection plus transition-number-based acceptability thresholds.

Litigation check (USPTO / CAFC 2026)

No case, IPR, or Federal Circuit appeal involving US 5,588,056 was found. Searches expressly keyed to the number 5588056 returned zero docket or infringement results. Verizon-related 2026 matters that surfaced are different patents and must not be attributed to this patent:

Because the '056 patent expired (anticipated expiration October 25, 2014, per the Google Patents legal-status record), it is not a candidate for a live 2026 infringement suit.

Confidence and caveats

  • High confidence in title, inventor, assignees, application number, filing date, and issue date — these match the authoritative record and the full text provided.
  • High confidence in the substance of independent claims 1 and 22 — the language was recovered verbatim from multiple full-text mirrors.
  • Uncertain about the exact total claim count and whether any independent system/apparatus claim exists in the '056 patent. I would verify against the USPTO PatentCenter/Patent Public Search full claim listing and the official PDF (patentimages.googleusercontent.com, US5588056.pdf) before relying on it. Note that Apple's US5850448 document (a same-inventor, same-family continuation) was repeatedly returned by search engines in place of the '056 patent; any "programmed computer" or "article of manufacture" claim language you encounter belongs to the '448 patent, not the '056 patent claimed here.
  • No fabrication: I did not locate an authoritative record of any CAFC 2026 docket naming 5588056, and I am reporting that absence rather than inferring one.

Generated 9/27/2026, 7:52:27 PM

Cases on file (0)

Specific litigation cases in our database that name US patent 5588056. The free-form analysis below may also discuss cases beyond this list.

No cases on file mention this patent. Upload a CSV or add a case manually in Admin → Manage litigation cases.

Litigation summary

Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.

✓ Generated

I'll search litigation databases for US patent 5588056.

Let me try more targeted litigation sources.

Let me try dedicated litigation databases directly.

Litigation Search — U.S. Patent No. 5,588,056

Result: No litigation identified

Based on the searches I was able to run against publicly indexed litigation sources, I found no known litigation involving U.S. Patent No. 5,588,056 — no district court infringement action, no declaratory judgment action, no ITC Section 337 investigation, and no PTAB proceeding (IPR/PGR/CBM) surfaced.

Because you asked for a case-by-case list, I have to report that the list is empty rather than populated. I will not manufacture cases to fill the table.

What I searched and what came back

I ran multiple queries against general and litigation-oriented indexes (including PACER-derived aggregators and RPX Insight document pages). Every hit resolved to an unrelated use of the digit string, which I am deliberately listing so you can see the false-positive pattern:

Hit Why it is not our patent
US Registration No. 5588056 — "MICAMA" (E&E Upholstery, Inc.), Serial 87735970 This is a trademark registration number, not a patent
JP 5588056 A (1983-01-18) A Japanese publication number
DOI 10.1155/2017/5588056; Shock & Vibration 2021, art. 5588056 Academic article identifiers
Phoenix Contact part no. 5588056 Commercial catalog number
Brazilian state registry entry "5588056 A FERNANDES DE SOUSA - ME" Company registration number
Various 4G/LTE complaints (e.g., CCE v. Verizon / Alcatel-Lucent / Ericsson / Apple / HTC) Different patents entirely — LTE standard-essential patents

None of these are the subject patent.

Why the null result is plausible (and not just a search artifact)

Three independent reasons make "no litigation" a credible answer here, rather than merely a gap in my searching:

  1. Terminal disclaimer of the market. The patent issued 1996-12-24 with a 1994-10-25 priority date, and Google Patents records its legal status as "Expired – Lifetime," with anticipated expiration on 2014-10-25. A patent that has been expired for over a decade cannot support a live infringement action (damages exposure ends at expiration), which sharply reduces the incentive to assert it and would explain the absence of any docket.

  2. Prosecution-history assignment chain, not a litigated chain. The recorded assignments are corporate housekeeping only — Bell Atlantic Network Services, Inc. → Verizon Services Corp. (change of name) → Verizon Patent and Licensing Inc. That is consistent with an internally held portfolio patent that was never spun out to an assertion entity, which is the typical precursor to NPE litigation.

  3. Claim scope is narrow and pre-dates the modern assertion wave. The claims are directed to a specific method of generating pronounceable passwords using transition counts from a Markov model, checked against thresholds. As a generator-side method claim, it is a poor fit for the standard "accused product in the stream of commerce" NPE model.

Caveats you should weigh before relying on this

  • I hit a tool-usage limit mid-search. My final round of targeted queries (RPX Insight, CourtListener/Docket Alarm, and a combined "5,588,056" docket query) did not complete. The negative result is therefore based on the queries that did run, not on an exhaustive sweep.
  • Clean-number searching on this patent is unusually polluted. Because "5588056" collides with a trademark registration, a Japanese publication number, academic DOIs, and product SKUs, an automated keyword sweep for the bare string produces heavy noise. This raises the false-negative risk: a real docket entry that cites the patent only as "5,588,056" or "'056 patent" will not be caught by a bare-digit search.
  • Per your instruction, I treated the identifier literally and did not auto-correct it. I deliberately did not report results for neighboring numbers (e.g., US 5,588,055, US 5,588,057) or for the frequently confused Verizon VoIP patents ('574, '711, '880) or the Immersion '213/'333 haptics patents.

Recommended verification steps

If you need a defensible "no litigation" opinion rather than a search summary, I would run the following, which I could not complete:

  1. Lex Machina / Docket Navigator — search the patent number as an "asserted patent" field; these tools normalize patent numbers and avoid the digit-string collision problem.
  2. Unified Patents litigation portal (portal.unifiedpatents.com) — check both the litigation caselist and the PTAB/IPR tab for the '056 patent.
  3. USPTO Patent Center / Global Dossier — pull the complete transaction history and the full assignment abstract; a § 315(b)-relevant complaint served on the patent owner would appear in the paper file even if unreported in commercial databases.
  4. ITC EDIS — search Section 337 investigations for the patent number.
  5. FRAP/CAFC docket search — confirm no appeal docket lists it.
  6. Lead worth chasing (flagging, not asserting): the Google Patents record shows a second application, US 08/731,427, filed 1996-10-15, which published as US 5,850,448 — evidently a related continuation in the same family. If a family-wide check is in scope, that patent should be searched independently. I did not search it, and I make no representation about its litigation history.

Bottom line: No litigation involving U.S. Patent No. 5,588,056 is known to me from the sources searched. The absence is corroborated (though not proven) by the patent's expired-lifetime status since 2014-10-25 and its internal-corporate assignment history. I cannot rule out an unreported, previously dismissed, or bare-number-indexed filing, and I'd recommend confirming via Lex Machina/Docket Navigator and the USPTO transaction history before treating this as conclusive.

Generated 9/27/2026, 7:52:26 PM

Proceedings on file (0)

All PTAB activity →

AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.

No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.

PTAB challenges

AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.

✓ Generated

PTAB / AIA Trial Analysis — U.S. Patent No. 5,588,056

Patent: US 5,588,056 A — "Method and system for generating pronounceable security passwords"
Inventor: Ravi Ganesan · Original assignee: Bell Atlantic Network Services, Inc. · Current assignee: Verizon Patent and Licensing Inc.
Filed: 1994-10-25 · Granted: 1996-12-24 · Legal status: Expired – Lifetime; anticipated expiration 2014-10-25
Source of record for the above: https://patents.google.com/patent/US5588056/en


Proceedings overview

Total AIA trial proceedings on file: 0 (0 active, 0 with claims invalidated, 0 with claims sustained, 0 settled, 0 institution-denied). The asserted record is empty — the USPTO Open Data Portal returns no IPR/PGR/CBM for US 5,588,056, no web search surfaced any petition, institution decision, Final Written Decision, or Federal Circuit appeal involving this patent number, and the bottom-line defensive posture is therefore not "the patent has survived IPRs and is hardened" and not "the claims have been cancelled" — it is "the patent was never tested at the PTAB and, more importantly, expired on 2014-10-25, so there is nothing left to invalidate that would change your damages exposure."

What I actually verified (and what I could not)

Check Result
USPTO ODP structured "PTAB proceedings on file" block Empty — no AIA trial proceedings
Web search for IPR/PGR/CBM on "5,588,056" / "US5588056" No AIA petition, institution decision, or FWD found
Web search for a Federal Circuit appeal of an FWD on this patent None found
Assertion history in district court / ITC No infringement suit on this patent surfaced in searches

No proceeding-level entries follow, because there are none to describe. I will not manufacture a proceeding number, a panel, or a claim-level outcome. The remainder of this memo explains what the emptiness means and why the "558" hits you will find in searches are almost all the wrong patent.

Do-not-cite list — false positives for "the '558 patent"

This is a real risk in this instance, because the literature is saturated with other '558 patents. If a defendant's invalidity memo cites "the PTAB's treatment of the '558 patent," verify the number first:

None of those is this patent. None of them supplies a PTAB record for US 5,588,056.


Strategic summary

1. Claims status: everything is UNTESTED, and everything is EXPIRED.
No claim of US 5,588,056 has been cancelled, confirmed, or even construed by the PTAB. The published claim set presents independent method claim 1 with dependent claims 13–21 (including claim 13's encryption/decryption step, claim 17's Markov-model derivation, claim 20's private-key application and claim 21's RSA limitation), and a second independent method claim, 22, directed to the categorized-transition-number variant. I did not verify the complete claim count against the printed patent in this pass, so treat any "claims X–Y" statement as unconfirmed until you pull the face page. The dispositive fact is not the claim set but the calendar: per the Google Patents legal-status record, the patent expired 2014-10-25 for failure to pay maintenance fees / end of term. An expired patent cannot be infringed going forward; only pre-expiration conduct is actionable, and under 35 U.S.C. § 286 the damages lookback from today (2026-09-27) reaches only to 2020-09-27 — a window entirely after the patent's death. On those facts, a demand letter citing US 5,588,056 offers a defendant essentially no recoverable-damages theory.

2. Estoppel landscape: inapplicable, and that cuts both ways.
Section 315(e)(2) estoppel attaches only to a petitioner (and its privies/real parties in interest) that obtained an institution decision. There is no IPR/PGR/CBM here, so no party carries § 315(e)(2) estoppel, and no ground has been "used up." Practically, this means a defendant is not blocked by prior PTAB work from running any § 102/§ 103 theory — but it also means there is no knock-out ground already blessed by the Board to borrow. If you nonetheless want an invalidity position for a settlement/leverage posture, the art is unconstrained: the patent's own specification admits the Sandia/Kerberos V generator, the Gasser/NIST generator (GASS77, FIPS92), and the DEC Markov-model generator as prior approaches, and the patent itself frames the invention as an improvement on those. Separately, the inventors' companion paper, Ganesan & Davies, "A New Attack on Random Pronounceable Password Generators," appears in the 17th National Computer Security Conference proceedings dated 1994-10-11 (https://csrc.nist.gov/files/pubs/conference/1994/10/11/proceedings-17th-national-computer-security-confer/final/docs/1994-17th-ncsc-proceedings-vol-1.pdf). Read that date carefully: it is 14 days before the 1994-10-25 filing date, so it is not a pre-AIA § 102(b) statutory bar (the one-year grace period is not met) and it is the inventor's own work — do not build a § 102(b) theory on it. It is useful only as technical/background evidence about the state of the art.

3. Pattern signals: none.
No petitioner filed one IPR, let alone a series; there is no follow-on-petition or General Plastic fact pattern; the patent owner (Bell Atlantic → Verizon Services Corp. → Verizon Patent and Licensing Inc.) never had occasion to defend or appeal at the PTAB, so there is no aggressive PTAB-appeal pattern to model and no defensive aggregator (Unified Patents, RPX, etc.) anywhere in the chain. That is itself the signal: a 1994 password-generation patent that lapsed in 2014 without ever drawing a single AIA challenge was either never commercially asserted, or was asserted only in an era/venue where the IPR route was unattractive. Either way, this is a dead-letter patent, not a hardened one. (For completeness: I did not independently verify the continuation, US 5,850,448 — "Programmed computer for generating pronounceable security passwords," app. 08/731,427, priority 1996-10-15 — for AIA activity in this pass; if a demand letter names the family, that number should be run separately.)


Recommended next steps

  1. If you are a defendant and the demand letter cites US 5,588,056: the lead response is not an IPR petition — it is the date. Pull the Patent Center maintenance-fee and expiration record (https://patentcenter.uspto.gov) and the Google Patents legal-status entry showing "Expired – Lifetime," anticipated expiration 2014-10-25, then compute the § 286 window (2020-09-27 → present). There is no damages period in which the patent was in force, so there is no recoverable royalty. Quote the expiration record, not an FWD — there is no FWD to quote.
  2. If you need an invalidity backup anyway (e.g., for a DJ counterclaim, a fee motion, or license-negotiation leverage), note that no estoppel constrains you. You may use any § 102/§ 103 art. But remember the pre-AIA regime: the on-sale/printed-publication grace period runs from the 1994-10-25 filing date, and the inventors' own Oct. 1994 NIST paper is inside that grace period. Target prior art that predates 1993-10-25 for a § 102(b) theory.
  3. Do not cite any PTAB decision as precedent on this patent. There isn't one. If someone hands you "the '558 PTAB record," it is almost certainly the Matsushita spread-spectrum '558, the Qualcomm '558, or the Penn '558 — all different patents (see the do-not-cite list above). Verify by patent number and title before filing anything.
  4. If a proceeding does surface later: the default sources to re-check are the PTAB E2E / PTAB Decisions portal (https://www.uspto.gov/patents/ptab/decisions), the PTAB API at developer.uspto.gov, and CourtListener (https://www.courtlistener.com) for any CAFC appeal. As of 2026-09-27, none of them shows an AIA trial on US 5,588,056, and I found no basis to represent otherwise.

Caveat on confidence: I am highly confident there are no AIA trials on this patent, based on the empty ODP record plus searches that returned only unrelated '558 patents. I am less certain about full district-court assertion history and about the exact total claim count of the printed patent, neither of which I could fully confirm in this pass; both should be verified before being relied on in a filing.

Generated 9/27/2026, 7:52:44 PM

Ownership chain (3)

Asserters network →

Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.

  1. 1994-10-25 · Assignment

    Ravi GanesanBell Atlantic Network Services, Inc.

  2. 2000-08-01 · recorded 2007-04-23 · reel 19193/0346 · Change of Name

    Bell Atlantic Network Services, Inc.Verizon Services Corporation

    change of name only

  3. ? · recorded 2014-05-08 · Assignment

    Verizon Services CorporationVerizon Patent and Licensing Inc.

    internal reorg

Assignment history

Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.

✓ Generated

I'll verify the assignment record details before writing. Let me search for the recorded reel/frame entries.

Let me try to pin down the recorded reel/frame numbers and check the related continuation.

Found a concrete reel/frame lead. Let me verify it covers this patent and find the Verizon Patent & Licensing link.

Ownership & Assignment Analysis — US 5588056 A

"Method and system for generating pronounceable security passwords"
Inventor: Ravi Ganesan · Filed 1994‑10‑25 · Issued 1996‑12‑24 · Appl. 08/328,226 · Original assignee Bell Atlantic Network Services, Inc.

Methodological note up front (important): the USPTO Assignment Center (https://assignmentcenter.uspto.gov/) and Assignments‑on‑the‑Web (https://assignment.uspto.gov/patent/index.html) are JavaScript applications that I could not query live in this session. Reel/frame data below comes from (a) the legal‑events table rendered in the Google Patents full‑text record for this patent, and (b) a secondary index of USPTO assignment reel 19193/0346. Where I could not retrieve a reel/frame, I say so rather than reconstructing one. Verify every entry at the Assignment Center by searching patent number 5588056.


Inventors

Inventor Employer at filing Basis
Ravi Ganesan (sole inventor) Bell Atlantic Network Services, Inc., Arlington, VA The 1994 initial assignment transfers Ganesan's rights to Bell Atlantic Network Services, Inc.; the patent face lists that entity as assignee.

Pattern notes:

  • Single‑inventor patent — no co‑inventor fragmentation, and therefore no "inventors scattered to different buyers" problem.
  • No evidence of inventor departure preceding a sale. The assignment of record is the ordinary employee‑invention → employer conveyance executed contemporaneously with filing, not a cash‑out.
  • Ganesan appears on other patents in the same corporate family, including the continuation US 5850448 A ("Programmed computer for generating pronounceable security passwords," filed 1996‑10‑15, issued 1998‑12‑15, same original assignee). Public biographical sources associate him with later authentication/security ventures, but I could not verify that in this session, so I do not treat it as a finding.

Original assignee

Bell Atlantic Network Services, Inc. (Arlington, VA) — named on the issued patent.

  • Line of business: network‑services subsidiary of Bell Atlantic Corporation, one of the seven Regional Bell Operating Companies. Its Arlington facility housed Bell Atlantic's network/technology research organization; this patent is a security‑R&D artifact (password policy, dictionary‑attack resistance, Markov‑model word generation) rather than a network‑operations patent.
  • Product embodying the claims: not determinable / no evidence. I found no commercial pronounceable‑password product attributable to Bell Atlantic, and no litigation record tying this patent to a shipped product. Treat "shipped a product" as unclear — the claims are directed to a password generation method/system, and the likely use was internal security tooling.
  • Current status: Bell Atlantic Network Services, Inc. no longer exists under that name. Per recorded assignment reel 19193/0346, its name changed to Verizon Services Corporation (executed 2000‑08‑01, recorded 2007‑04‑23), consistent with the Bell Atlantic–GTE merger that formed Verizon Communications in 2000. The operating business continues inside Verizon; the patent itself now sits with Verizon Patent and Licensing Inc.

Assignment timeline

Two post‑issuance transfers were found, both intra‑corporate. The reel/frame for the 1994 inventor assignment and for the Verizon Services → Verizon Patent & Licensing transfer were not retrievable in this session — do not treat the absence as evidence they do not exist.

  • 1994‑10‑25 (executed) / recorded on or about 1994‑10‑25 — Reel/Frame not retrieved

    • Conveyance: Assignment of assignor's interest
    • Assignor: Ravi Ganesan (individual)
    • Assignee: Bell Atlantic Network Services, Inc. (Arlington, VA)
    • Correspondent: not retrieved
    • Context: standard employee‑invention assignment executed with the original filing; not a sale.
  • 2000‑08‑01 (executed) / recorded 2007‑04‑23 — Reel 19193 / Frame 0346

    • Conveyance: Change of Name (recorded as USPTO Patent Assignment 19193/346)
    • Assignor: Bell Atlantic Network Services, Inc.
    • Assignee: Verizon Services Corporation, 1320 North Court House Rd, Arlington, VA 22201
    • Correspondent: not captured in the indexed record
    • Context: change of name only, following the Bell Atlantic/GTE merger. Note the ~6.7‑year gap between execution (2000) and recording (2007) — a bulk corporate clean‑up recording covering a large Bell Atlantic patent set, not a discrete deal. Flag: Google Patents renders this same event with a 2014‑04‑25 date, which conflicts with the 2007 recording date on the underlying reel; the 2014 date in Google's legal‑events table appears to be a data‑load artifact.
  • 2014‑05‑08 (Google Patents legal‑event date; execution date not retrieved) — Reel/Frame not retrieved

    • Conveyance: Assignment of assignor's interest
    • Assignor: Verizon Services Corporation
    • Assignee: Verizon Patent and Licensing Inc. (Basking Ridge, NJ)
    • Correspondent: not retrieved
    • Context: internal reorganization — movement of the portfolio into Verizon's corporate IP‑holding subsidiary. Google Patents lists Verizon Patent and Licensing Inc. as current assignee.
  • 2014‑10‑25 — Anticipated expiration (20 years from the 1994‑10‑25 filing). Not an assignment; included because it is the terminal legal event and explains why no further transfers exist.

No security agreements, licenses, releases, mergers, or corrective assignments were surfaced for this patent. Ownership has never left the Bell Atlantic → Verizon corporate family.


Timeline diagram

timeline
    title Ownership of US 5588056
    1994 : Filed by Bell Atlantic Network Services
         : Inventor assignment to employer
    1996 : Patent issued
    1996 : Continuation US5850448 filed
    2000 : Name changed to Verizon Services Corp
    2007 : Change of name recorded at USPTO
    2014 : Moved to Verizon Patent and Licensing
    2014 : Patent term expires

NPE / troll-pattern signals

# Signal Call Evidence
1 Shell-entity transfer Not present The only assignees of record are Bell Atlantic Network Services, Inc., Verizon Services Corp., and Verizon Patent and Licensing Inc. — all members of one public telecom corporate family. No unrelated LLC, no registered-agent service address, no single-member Delaware/Texas shell appears. Reel 19193/0346 (2007) is a change of name within that family, not a transfer out of it. Verizon Patent and Licensing Inc. is an operating-company IP holder, not a licensing-only NPE.
2 Known asserter in the chain Not present No entry in the chain matches Acacia, Marathon, Intellectual Ventures, IPNav, Wi‑LAN, Mosaid/Conversant, Vringo, Pendrell, Innovatio, MPHJ, Lumen View, Round Rock, Document Generation Corp, or any Spangenberg-linked entity. Note: Verizon entities have enforced patents against actual competitors (e.g., Verizon v. Vonage, Verizon v. Cox), which is the opposite of the NPE pattern — but no source connects this patent to any such suit.
3 Repeat correspondent across the chain Unclear — not assessed Correspondent of record was not retrievable for any of the three recorded events from the sources available here. This is the single most valuable field for your purpose, and it is the one I cannot fill. Recommend a manual Assignment Center pull to capture the correspondent on reels for the 1994, 2007, and 2014 recordings.
4 Cascading transfers Not present Only two post‑issuance transfers across a 20‑year life (2007 change of name; 2014 internal reorg) — no chained LLC hops, no transfers inside a 24‑month window, no shared-address assignees.
5 Pre-litigation transfer Not present No infringement suit naming US 5588056 was identified. The 2014 transfer to Verizon Patent and Licensing Inc. precedes expiration (2014‑10‑25) rather than any complaint.
6 Bankruptcy fire-sale Not present No Chapter 7/11 proceeding involving Bell Atlantic Network Services, Verizon Services Corp., or Verizon Patent and Licensing Inc. The entity change was a merger (Bell Atlantic + GTE → Verizon), not an insolvency sale.
7 Privateering Not present No recorded transfer of this patent to a third-party assertion vehicle, and no SEC filing or press coverage linking it to an operating-company-funded NPE. (Verizon has divested patent portfolios generally, but nothing ties this patent to such a transaction.)
8 Defensive aggregator (anti-NPE) Not present Chain terminates at Verizon Patent and Licensing Inc., not at RPX, AST, LOT Network, Unified Patents, or OIN. The patent was not neutralized by aggregation; it simply expired.

Verdict

Insufficient data — stated precisely: insufficient data to support any NPE classification, because the chain is entirely intra-corporate.

Justification: the only recorded post-issuance movement is reel 19193/0346 (change of name, Bell Atlantic Network Services → Verizon Services Corp, executed 2000‑08‑01, recorded 2007‑04‑23) followed by the 2014 transfer into Verizon Patent and Licensing Inc. — both internal steps within one operating telecom's corporate family, with no third-party buyer, no assertion vehicle, and no litigation. All eight NPE signals are unsupported or unevaluable, driven mainly by my inability to retrieve correspondent-of-record data in this session; that gap, not the absence of records, is what prevents a clean "non-NPE" call. Recommended verification step: search patent 5588056 at https://assignmentcenter.uspto.gov/ and capture the reel/frame plus correspondent for all three recordings — a recurrent Verizon in-house or outside correspondent across reels 19193/0346 and the 2014 recording would be a normal corporate-hygiene pattern and would confirm the non-NPE call.

Generated 9/27/2026, 7:53:00 PM

Prior art

Earlier patents, publications, and products that may anticipate or render the claims unpatentable.

✓ Generated

I'll research US Patent 5588056 and its citations.

Let me search for the specific citations listed on the patent's front page.

Let me try to access the patent's citation list directly from patent databases.

Important caveat before the analysis

I ran the searches you asked for, and I was unable to retrieve US 5,588,056's front‑page "References Cited" (examiner‑cited) list — the Google Patents full text supplied omits that section, and my queries returned forward citations ("Cited By") of the patent rather than the backward citations printed on its face. I will not invent patent numbers to fill that gap. Below I give (a) the verified bibliographic record, (b) the prior art that is actually identified within the patent, and (c) an honest statement of what I could not confirm.


1. Verified record for US 5,588,056

Field Value
Patent number US 5,588,056 A (literal)
Title "Method and system for generating pronounceable security passwords"
Inventor Ravi Ganesan
Application no. US 08/328,226
Filed 1994-10-25
Granted / published 1996-12-24
Original assignee Bell Atlantic Network Services, Inc.
Current assignee Verizon Patent and Licensing Inc. (via Verizon Services Corp., 2014 reassignments)
Status Expired – Lifetime (anticipated expiration 2014-10-25)
Classification G06F 21/31 (user authentication); G07F 7/10
Related case US 5,850,448 A (app. 08/731,427, filed 1996-10-15) — "Programmed computer for generating pronounceable security passwords," same inventor/assignee; a continuation of the 5,588,056 disclosure.

2. Prior art identified within US 5,588,056

These are the references the applicant/specification expressly relies on as the state of the art. They are non‑patent literature (NPL) and a co‑pending application, not examiner-cited patents. Because they are printed in the specification, they carry prior-art weight under pre-AIA § 102(a)/(b) by their publication dates, but NPL is not a "patent citation" in the technical sense, so I flag each accordingly.

Ref. Full citation (as given in the patent) Date Brief description § 102 exposure for 5,588,056
Sandia System "Pronounceable password generator distributed by Sandia Labs with Kerberos V source (files 7clcpwd.c, 7cldpwd.c)" pre‑1994 (Kerberos V) 25 pronunciation "templates"/buckets (e.g., cvcvcvc); randomly indexes a template, then picks a 7-char password; appends a random 8th digit/letter. Not anticipatory. Discloses pronounceable generation but not "equal-probability selection of first word segment portions keyed to a transition number," nor the threshold/category rejection logic of claims 1 and 22. § 103 candidate only.
Gasser / NIST [GASS77] M. Gasser (MITRE) random word generator; adopted as NIST standard [FIPS92] (FIPS PUB 181 lineage) 1977 / 1992–93 34 units with English-frequency probabilities; unit/diagram rule tables build syllables; optional fully-random variant. Not anticipatory. Different mechanism (rule tables + weighted unit probabilities). Relevant to claims 22–29 (categorization/threshold concept) but does not teach the claimed "transition number" tie.
DEC System Digital Equipment Corp. pronounceable password generator (Markov-model based) pre‑1994 Trains a Markov transition-probability matrix on natural language; probabilistically steps to next state; adds characters until an "information content" threshold is met. Closest NPL conceptually, but still not anticipatory: it uses information-content thresholding, not the claimed per-first-word-segment "transition number = count of combinable second segments" with equal-probability selection. § 103 candidate.
Morris & Thompson "Password security: A case history," Comm. ACM 22(11), Nov. 1979 1979 Classic dictionary-attack/salting analysis (DES one-way function; salt factor 4096). Background only; not anticipatory of the password-generation claims.
Karn & Feldmeier "UNIX password security—Ten years later," Advances in Cryptology—CRYPTO '89, Springer-Verlag, 1990 1990 Key-space searchability analysis. Background only.
Bellovin & Merritt "Encrypted Key Exchange," IEEE Computer Society Symposium on Security and Privacy, May 1992, Oakland, CA 1992 Encrypted-key-exchange hardening of Kerberos. Background only (system-alteration alternative).
Kohl, Neuman, Steiner "The Kerberos Network Authentication Service," MIT Project Athena, Version 5, Draft 3 (KOHL90) 1990-10-08 Kerberos V5 protocol description; dictionary-attack vulnerabilities. Background only.
DES FIPS PUB 46-1 (National Bureau of Standards) 1977-01-15 Data Encryption Standard / one-way password function. Background only.
Co-pending application U.S. App. Ser. No. 08/121,852, filed 1993-09-17, "Method and System for Proactive Password Validation," Bell Atlantic (same assignee) 1993 Proactive password checking against bad/noisy passwords. Analogue/related technique; cites it as related art, not as anticipating the generator claims.

3. Forward citations (context for relevance, not § 102 art)

US 5,588,056 is cited by later work on password generation/strength, including (per Google Patents "Cited By"): US 7,739,439 and password-strength/password-creation patents (e.g., US 2008/0216170 family), and US 7,089,581 ("Security system design supporting method"). US 5,850,448 lists 33 citations to this family. These are irrelevant to validity of 5,588,056 (they post-date it).


4. Bottom line on anticipation

On the record I could verify, no cited reference anticipates US 5,588,056 under § 102. Each identified reference discloses pronounceable password generation, but none discloses the distinguishing limitations of independent claims 1 / 22 / the system claims — namely:

  • a "transition number" for each first word segment portion defined as the count of different second word segment portions combinable with it to form a pronounceable segment (claim 1; note this ties to [GASS77]/[FIPS92] only by analogy), and
  • substantially equal-probability selection of first portions and of their associated second portions (claims 1, 22), plus the threshold/category rejection logic that defeats the "smallest bucket attack."

The Sandia, Gasser/NIST, and DEC systems are properly cited as § 103 obviousness references / background, not as anticipatory art.


5. What I could not confirm (stated explicitly per your rules)

  • The exact examiner-cited U.S. patent numbers and foreign references on the 5,588,056 front page — not retrieved; not fabricated. If you need the authoritative list, pull the printed patent PDF front page (patentimages US5588056.pdf) or the USPTO PatentCenter "References Cited" tab for app. 08/328,226.
  • Exact publication details for [GASS77] and [FIPS92] beyond what the patent states; the patent's own labels were not auto-corrected.

If you can paste the front-page "References Cited" block (or the USPTO PatentCenter citation list), I will produce the per-reference § 102 anticipation table you specified.

Generated 9/27/2026, 7:52:40 PM

Obviousness

Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.

✓ Generated

I'll ground this § 103 analysis in the actual cited prior art and analogous art. Let me pull the front-page references and the closest known-generator art.

Let me pin down the patent's own front-page prior-art-of-record and the pre-1994 pronounceable-password generator art.

Let me check for U.S. patent prior art on pronounceable-password generation and confirm the Ganesan/Davies paper's status.

Obviousness Analysis — U.S. Patent No. 5,588,056 under 35 U.S.C. § 103

Posture note (important). This is a hypothetical/defensive § 103 analysis. Per the earlier sections of this page, the '056 patent issued 1996‑12‑24, expired for failure to pay maintenance ("Expired – Lifetime," anticipated expiration 1994‑10‑25 + 20 yrs = 2014‑10‑25), and I found no litigation, IPR, PGR, CBM, ITC § 337, or CAFC docket naming it. There is therefore no live validity contest to which this analysis attaches; it is useful only for portfolio diligence, freedom‑to‑operate history, or academic review. (Small housekeeping flag: the task header says "Current Date: April 26, 2026" while the system date is 2026‑09‑27. Nothing in this analysis turns on which is correct.)


1. Framework and the correct § 103 vintage

The application was filed 1994‑10‑25 and never left the pre‑AIA regime; validity is governed by pre‑AIA 35 U.S.C. § 103(a) with pre‑AIA § 102 for reference qualification. The Graham v. John Deere factors apply, and KSR Int'l v. Teleflex (2007) governs the legal standard for pre‑AIA patents as well — no rigid teaching‑specification‑or‑suggestion requirement, and "a court must ask whether the improvement is more than the predictable use of prior art elements according to their established functions." KSR, 550 U.S. 398, 417 (2007). Secondary considerations are only reached if a prima facie case is made; I found no evidence of record in the sources searched of unexpected results, commercial success, licensing, or industry praise, and the patent's own specification offers no comparative test data beyond the security math in the Background.

Level of ordinary skill in the art (POSITA). A POSITA here would hold a bachelor's degree in CS/EE (or equivalent) plus ~2 years in computer/network security, or a master's plus ~1 year — i.e., someone conversant with UNIX /etc/passwd and crypt(3), Kerberos V, DES, dictionary‑attack literature, and elementary Markov/ngram modeling of text. This is a modest level of skill; the relevant art is authentication/password generation, and the analogous art includes text‑generation and language‑modeling literature (the patent itself treats the DEC language-model generator and the Gasser linguistics-derived generator as the closest art).

Key constructions used below:

  • "Transition number" — claim 1 defines it functionally: the count of distinct second word segment portions in the associated set. It is a cardinality, not a probability. This distinction is the crux of the whole case.
  • "Substantially equal probability" — uniform random selection; the specification defines it as "the selection is of substantially equal probability."
  • "Pronounceable word segment" — a syllable-like string; subjective, as the specification concedes.

2. The prior art set

# Reference Status What it teaches
A Gasser, M., A Random Word Generator for Pronounceable Passwords, NTIS AD A017676 (Nov. 1975) — cited in the '056 spec as [GASS77] (OSTI copy) § 102(b) printed publication Unit table + digram table; pronounceability encoded as legality rules between adjacent units; concatenates syllables into a word.
B FIPS PUB 181, Automated Password Generator (announced 1993‑10‑05; effective 1994‑03‑25) (NIST) § 102(b) printed publication; arguably also § 102(a) as of its effective date Codifies A. Per‑unit legal‑successor lists in the digram table; the "unit table … is identical to that furnished in [A]." Government‑mandated for federal pronounceable password generation.
C Gasser's own variant, described in A/B and conceded by the '056 specification: generate passwords "completely at random," pass them through the generator as a filter, so the probability a user draws from a bucket equals ** bucket /K**
D EP 0 488 492 A2/A3, Callas & Piper (assigned to Digital Equipment Corp., Maynard MA), filed 1991‑06‑12, priority US 07/620,106, 1990‑11‑30, published 1992‑06‑03 (EPO) § 102(a)/(b) — US‑priority foreign publication >1 yr before filing "Random character generator": builds a rules database from a dictionary, then constructs output character‑by‑character, each new character chosen from the rules database based on the previous characters — i.e., a transition model. This is almost certainly the "DEC system" the '056 spec criticizes at col. 3.
E IBM Technical Disclosure Bulletin, vol. 27, no. 8, Jan. 1985, pp. 4786‑4787, "Easily Remembered Passphrases"; and vol. 26, no. 6, Nov. 1983, pp. 2831‑2833, "Compressed Dictionary for Word Verification" (both cited in D's search report) § 102(b) Pronounceable/memorable multi‑word credential construction from a compact dictionary structure.
F Jobusch & Oldehoeft, "A Survey of Password Mechanisms: Weaknesses and Potential Improvements, Part 2," Computers & Security, no. 8, Dec. 1989, pp. 675‑689 § 102(b) Survey framing the field: password‑space size, generator weaknesses, and improvement strategies — supplies motivation/context.
G Morris & Thompson, "Password Security: A Case History," CACM 22(11), Nov. 1979 (cited in the '056 spec) § 102(b) Dictionary attack on generator/user‑chosen passwords; salting (the "4096" factor the patent discusses).
H Feldmeier & Karn, "UNIX Password Security — Ten Years Later," CRYPTO '89 (cited in the '056 spec) § 102(b) Attack cost model; quantifies how large an effective password space must be; expressly motivates enlarging the actual search space the attacker must cover.
I Sandia Kerberos‑V files 7clcpwd.c / 7cldpwd.c (cited in the '056 spec) § 102(a)/(b) public use/printed publication 25 templates ("buckets") indexed with uniform probability; random password drawn within the chosen template.
J Bishop, "Proactive Password Checking" (Aug. 1992); Spafford, "OPUS" (Jun. 1991) and "Observing Reusable Password Choices" (1992) § 102(b) The field's recognized problem: bad/guessable passwords; motivates stronger generators.
K Bellovin & Merritt, "Encrypted Key Exchange," IEEE S&P, May 1992; Kohl/Neuman/Steiner, "The Kerberos Network Authentication Service" (1990‑10‑08) — both cited in the '056 spec § 102(b) Applying a password to encrypt/decrypt messages and to password‑based key exchange (EKE) — directly on the dependent‑claim applications.
L Ganesan & Davies, "A New Attack on Random Pronounceable Password Generators," 17th National Computer Security Conference, Oct. 1994 (NIST/CSRC PDF) Likely NOT prior art — see §6 States Criteria 1–5 (verbatim to the '056 Background) and, in "option 5," proposes: "Instead of picking units according to their probability of occurrence in English, pick units with a uniform distribution (i.e. each of the 34 units has a 1/34 probability of being picked). Since the rules of pronunciation are determined by the digram tables, this will not affect the pronounceability of the resulting passwords."

3. Ground 1 — Claims 1, 13–19 obvious over B (FIPS 181/Gasser) + D (DEC/EP 0 488 492) + H

Claim‑chart for claim 1:

Claim 1 element Where taught / why obvious
"plurality of first word segment portions, each having at least one character" B: the "units" (A–Z minus Q, plus CH, GH, PH, RH, SH, WH, QU, CK) and, in the digram table, pairs of units — bigram‑equivalents. D: character/ngram states in the rules database.
"associated set of second word segment portions … combinable with the associated first … to form a pronounceable word segment" B's digram table "contains one entry for every pair of units, whether that pair is allowed or not" — i.e., for each leading unit/ngram, a set of legal followers that yields a pronounceable sequence.
"transition number corresponding to the number of said second word segment portions within the associated set" Inherent in B. Because the digram table enumerates the legal followers of each unit, its row length is the count. Merely counting the entries is a routine data‑processing step with no new function — the classic KSR "predictable variation." D's rules database likewise stores a per‑state successor list.
"selecting a first one of said plurality … of substantially equal probability" C — Gasser's random‑generate‑and‑filter variant makes unit selection (and therefore bucket draw probability) uniform; I (Sandia) indexes the 25 templates with uniform probability.
"selecting a first one of said plurality of second word segment portions … of substantially equal probability" B's operator chooses uniformly among the legal successors of the current unit; D likewise selects among permitted next characters.
"combining … to form a first pronounceable word segment" B: "forming pronounceable syllables and concatenating them."
"generating … only if consecutive characters … fail to correspond to … first word segment portions having a transition number less than a threshold" The filter step is C's explicit teaching (randomly generated candidates are run through the generator as a filter and rejected unless they satisfy the rules). Quantifying "how permissive" a state is (its transition count) and rejecting low‑count states is the predictable mechanization of C's filter using the count that B/D already imply.

Motivation to combine (KSR rationales):

  1. Same field, same problem, same solution shape. A, B and D are all pronounceable‑password generators; B is the federal standard derived from A; D is a commercial rules‑database generator in the same art. Combination is the design incentive rationale.
  2. Art‑recognized deficiency. H (Feldmeier & Karn, cited on the face of the '056 patent) quantifies that a pronounceable generator's effective search space, not its nominal space, governs security. Gasser himself (per the '056's own characterization) articulated Criterion 2 (most‑probable passwords should be rare) and Criterion 3 (all passwords roughly equally probable) — the very goal claim 1's equiprobable selections pursue.
  3. C already supplies the uniformization. The '056 specification admits Gasser's variant "generates the passwords completely at random" so that "the probability of selecting from a particular bucket … [is] the ratio of the size of the bucket to the total size." A POSITA seeking to satisfy Gasser's Criterion 3 would apply exactly this.
  4. Predictable engineering. Replacing a probability‑weighted selection with a uniform selection is a substitution of one known selection scheme for another with the expected result (removal of frequency skew) — a "predictable variation."

Assessment: Strong as to the equiprobable‑selection limitations; moderate as to the count‑based threshold limitation. Ground 1 is the cleanest available attack on claim 1, but it depends on the inference that a POSITA would derive a cardinality metric from the digram table rather than a binary legal/illegal flag — because B's table is binary. Expect the patent owner to press that gap (see §7).


4. Ground 2 — Claim 22 and claims 23–32 obvious over C (Gasser variant) + D/A and/or I

Claim 22 adds only: categorizing first word segment portions into ≥2 categories by transition number; identifying a selection category at or above a threshold; selecting uniformly within the category; and the same "non‑selection category" filter.

  • Categorization by count is the same counting step as Ground 1, plus a binning step. Binning numeric values into ranges (the patent's own three bins: >15, 5–15, <5) is the definition of routine engineering.
  • The '056 specification itself concedes the bucket framing is old: it describes the Sandia system's "25 templates i.e. buckets," each selected with equal probability, and Gasser's 34 "units," and quotes Gasser's Criterion 3. It then admits the invention's own "Criterion 5" is a statement of a general property, not a structure.
  • I (Sandia) teaches uniform bucket selection; E/F teach the multi‑part memorable credential; D teaches the transition‑table substrate.
  • Claim 23 (selection‑category transition numbers > non‑selection) is a pure result‑effective‑variable limitation: it claims the consequence of choosing the category as the patent's own spec defines it.

Assessment: Moderate.* Claim 22 adds little physical structure over claim 1; its main added limitation is a threshold‑based categorization that a POSITA would implement once the counting metric exists.


5. Ground 3 — Dependent claims

Claim Content § 103 basis
13 Apply password to encrypt/decrypt a message K (EKE; Kerberos) — password‑based encryption is the field's purpose.
14 First portion = bigram or trigram B (digram table), D (n‑gram states).
15 Second portion = unigram B (unit table: single alphabetic characters).
16 Characters are alphabet letters A/B — inherent.
17 Transition numbers derived using a Markov model D (rules database built from a dictionary, character‑by‑character selection conditioned on prior characters = Markov/ngram model); A/B (digram tables are a first‑order Markov legality matrix). Also Ganesan et al., Statistical Techniques for Language Recognition (1993‑09‑28), on the family's own (56) list, shows Markov modeling of English was well within the art.
18 Password ≥ 8 characters B (FIPS 181 targets 8–10 char passwords); I (8‑char Sandia output); H (length for key space).
19 ≥6 characters from the second portions Mere degree/configuration of the same combination.
20–21 Password forms part of a private key of a cryptosystem, RSA type RSA was 16 years old and ubiquitous; K teaches password→key derivation. Straightforward application, no new structure.

Assessment: Strong. Dependent claims 13–21 are near‑certainly obvious over Ground 1 + K.


6. The decisive disqualification — and it cuts against the analysis, not for it

Reference L (Ganesan & Davies, NCSC Oct. 1994) is the closest thing to an anticipatory disclosure in existence: it states the patent's entire Background (Criteria 1–5 nearly verbatim) and proposes the very fix. But it is almost certainly not prior art:

  • It was published October 11–14, 1994, eleven to fourteen days before the October 25, 1994 filing date.
  • It is co‑authored by the inventor, Ravi Ganesan. Under pre‑AIA § 102(a), a reference must be the work "of another"; a publication co‑authored by the applicant is generally not "by others" as to the applicant's own contribution. Under § 102(b), an applicant's own publication within the one‑year grace period is excluded.
  • Its internal cross‑reference [4], Ganesan, "BApronounce: A New Random Pronounceable Password Generator," is expressly "one of our own design" — i.e., the '056 patent is the BApronounce system reduced to claims.

Consequence: the single most potent § 103/§ 102 reference is self‑disclosed. If, however, an adversary can prove that the claimed subject matter (the count‑based metric and threshold selection, as opposed to the general goal) was contributed by Davies rather than Ganesan, the § 102(a) "by others" analysis could flip for those claims — and then L becomes a devastating § 103 (indeed § 102(a)) reference. This is the highest‑value unexplored line, and it requires the inventorship/contribution record and the prosecution history, which I have not obtained.

(Separately, a pre‑AIA § 102(b) public‑use/on‑sale theory exists if BApronounce was deployed at Bell Atlantic more than one year before 1994‑10‑25 — but any such use is the applicant's own and is excluded only if non‑public/experimental. I have no evidence either way and do not assert it.)


7. Where the obviousness case genuinely falls short (candid counter‑analysis)

I would not call claim 1 clearly obvious on A/B/C/D alone, for these reasons:

  1. The metric is a count, not a legality flag. A and B teach a binary digram table (legal/illegal). B "contains one entry for every pair of units, whether that pair is allowed or not." The '056's "transition number" as a cardinality of the legal‑successor set — and the insight that this cardinality is the size of the bucket an attacker must search — is not plainly in A, B, or D. The patent's own Background says of the DEC system that it "suffers from the smallest bucket attacks," i.e., DEC did not appreciate the counting metric.
  2. The motivation may be the inventor's own. The "smallest‑bucket"/Criterion 5 framing appears to originate in the applicant's own 1994 paper. Motivation "in the art" is what counts for § 103; if the only place the counting insight appears is the inventor's own pre‑filing publication, a court could find the art did not supply the motivation. Gasser's Criterion 3 helps, but it is a goal, not a mechanism.
  3. The threshold‑on‑the‑trailing‑ngram filter is specific. Claim 1(e) requires rejection when consecutive characters correspond to a first portion below a threshold. C filters on pronounceability rules, not on a cardinality threshold. Bridging that requires an inference.
  4. No secondary considerations evidence either way. The patent's claims were narrow and its product (BApronounce) may or may not have been adopted — I have no evidence.

Net: the strongest defensible position is that claims 1 and 22 are obvious as a matter of KSR predictable variation, with the equiprobable‑selection element squarely anticipated by admission (C), and the count metric supplied by routine counting of B's digram table. I rate this moderately strong — perhaps 55–65% likely to prevail in an IPR‑style forum with a good expert declaration, and materially weaker without the count‑metric bridge spelled out. I would not represent it as a certainty.


8. Cross‑reference updates and corrections to the earlier sections of this page

  1. Claim set extends further than previously stated. The earlier "Patent summary" reported claims "at least through claim 30." Full‑text mirrors retrieved in this session show claims 31 and 32 ("A method for forming a pronounceable security password according to claim 30, further comprising the steps: … combining said third selected first word segment portion and said third selected second word segment portion to form a substitute second pronounceable word segment …"), plus "32. A method for forming a pronounceable security…". The claim set therefore runs at least through claim 32; whether 32 is terminal is still unconfirmed (no independent system claim is visible in the '056 — consistent with the earlier finding).
  2. The related patent is a CIP, not a bare continuation. US5850448's own text states: "This application is a continuation‑in‑part of application Ser. No. 08/328,226, filed Oct. 25, 1994, now U.S. Pat. No. 5,586,056." The earlier sections described it as a "related continuation." The CIP characterization matters for § 103/§ 112: CIP‑added claims (visible up to at least claim 36 in the '448, e.g., "A programmed computer … according to claim 36") carry the 1996‑10‑15 date, and the '448's new matter is not supported in the '056.
  3. The (56) references list I retrieved is the '448's, not independently confirmed as the '056's. It is reproduced from the US5850448 PDF front page and includes Spafford (OPUS; "Observing Reusable Password Choices"), the Federal Register notice of 1992‑09‑08, Smid & Branstad ("The Data Encryption Standard: Past and Future"), Nagle ("Tell if a Password is Obvious"), Bishop, Ganesan et al. ("Statistical Techniques for Language Recognition," 1993‑09‑28), and Feldmeier & Karn. I could not separately verify the '056's own front‑page list from a primary image. Treat the "Feldmeier & Karn" and "Morris & Thompson" citations as confirmed (they appear in the '056 specification body), and the rest as family‑level.
  4. The "DEC system" is now identified to a reference. The '056 spec never names it. EP 0 488 492 A2/A3 (Callas & Piper, DEC; US priority 07/620,106, 1990‑11‑30; published 1992‑06‑03) matches the spec's description of the DEC system (Markov/rules‑database training from a dictionary; character‑by‑character generation conditioned on prior characters; information‑content stopping criterion). I did not confirm the corresponding US patent number; I deliberately do not guess it, and it should be verified before being named in any filing.
  5. Litigation: nothing new; consistent with the earlier "no litigation identified" conclusion.

9. Bottom line

  • Claim 1: Obvious under § 103 over FIPS 181/Gasser (A+B) in view of DEC/EP 0 488 492 (D) and Feldmeier & Karn (H), with the equiprobable‑selection limitations supplied by Gasser's admitted random‑generate‑and‑filter variant (C) and Sandia's uniform template indexing (I). The count‑based "transition number" limitation is the weak link and must be argued as routine quantification of the digram table.
  • Claim 22 and 23–32: Obvious on the same record once counting is assumed; claim 23 is a result‑effective‑variable limitation.
  • Claims 13–21: Obvious over the same grounds plus Bellovin & Merritt / Kerberos (K) and the conventionality of RSA.
  • Biggest risk to the theory: the only reference that expressly teaches the claimed insight (Ganesan & Davies 1994) is the inventor's own work and therefore almost certainly disqualified as prior art. Everything turns on the contribution question (Ganesan vs. Davies) and therefore on documentation I have not seen: the '056 prosecution history (Office Actions and reasons for allowance) and USPTO PatentCenter/Assignment records.

Confidence: high on reference content and dates (§§1–5), high on the § 102(b)/§ 102(a) self‑disclosure disqualification of reference L, low‑to‑moderate on the ultimate § 103 conclusion as to claim 1's counting/threshold limitations. I have flagged rather than resolved the two open items — the '056's authoritative (56) list and its term of claims — rather than filling them by inference.

Generated 9/27/2026, 7:53:37 PM

Extensions

Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Derivative works

Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Keep exploring

Other patents in Software Technology & Computing Systems (T)

See all Software Technology & Computing Systems (T) patents →