IP Library Granted Patent US 6,938,167
Granted Patent B2
US 6,938,167 · App. 10/323,230 · Granted Aug 30, 2005

Using trusted communication channel to combat user name/password theft

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 6,938,167
App. No.
10/323,230
Granted
Aug 30, 2005
Kind
B2
Abstract

A technique for defining a system with enhanced trust is disclosed, in which an immediate contact is made with the user on the enhanced trust system when a compromise is first detected, e.g. when there is a second log in attempt from another location. Using these communications channels, the service can often contact the compromised user and ask for confirmation of the results, i.e. to change password or login, from a reduced trust machine. As a result, even if an attacker steals a password, the true user on the enhanced trust machine is able to preclude a login or preclude a password change. In each case, if the user of the enhanced trust machine does not respond within some short period of time, then a less trusted machine can be allowed to proceed. The invention comprehends two definitions of an enhanced trust machine. In a first embodiment of the invention, an enhanced trust machine is a machine where the user is currently logged in at the time that the second, less trusted machine attempts a login. A second embodiment of the invention comprehends an enhanced trust machine where the user has logged in repeatedly over a course of numerous weeks, as compared with a lesser trusted machine that the user has never logged into before and which is now asking for a change of the password. In this case, the system may or may not find the less trusted machine to be just that based on actions that are experientially inconsistent with what is expected.

Claims (31)

1. A method for using a trusted communication channel to combat user name/password theft, comprising the steps of:

detecting an access attempt from an untrusted system;

making an immediate contact with a user of a trusted system when said access attempt from said untrusted system is first detected;

asking said user to confirm whether or not access via said untrusted system should be allowed;

permitting or denying said access via said untrusted system in response to said confirmation; and

developing experience with regard to work patterns of said user, and an expectation that a particular system is used by said user;

wherein a trusted system is a system where said user has been granted access repeatedly over a course of time.

2. The method of claim 1 , further comprising the steps of:

recording a history of number of times said user has logged in from a particular system; and

storing evidence of said history, optionally signed by a service to preclude forgery.

3. A method for determining if a system is a trusted system, comprising the steps of:

detecting an access attempt at an untrusted system;

using a messaging system to make immediate contact with a user of a trusted system;

asking said user for confirmation with regard to one or more actions to be taken in connection with said untrusted system; and precluding said one or more actions if said user refuses to provide affirmative conformation;

wherein said user of said trusted system confirms that said actions at said untrusted system may be permitted by any of entering a password and typing a special password.

4. An apparatus for using enhanced trust to combat user name/password theft, comprising:

a mechanism for detecting an access attempt from an untrusted system;

a messaging system for making an immediate contact with a user of a trusted system when said access attempt from said untrusted system is first detected;

a mechanism for asking said user to confirm whether or not access via said untrusted system should be allowed;

a mechanism for permitting or denying said access via said untrusted system in response to said confirmation; and

a mechanism for developing experience with regard to work patterns of said user, and an expectation that a particular system is used by said user;

wherein a trusted system is a system where said user has been granted access repeatedly over a course of time.

5. The apparatus of claim 4 , further comprising:

a mechanism for recording a history of number of times said user has logged in from a particular system; and

a storage means for storing evidence of said history, optionally signed by a service to preclude forgery.

6. An apparatus for determining if a system is a trusted system, comprising:

a mechanism for detecting an access attempt at an untrusted system;

a messaging system for making immediate contact with a user of a trusted system;

a mechanism for asking said user for confirmation with regard to one or more actions to be taken in connection with said untrusted system; and

a mechanism for precluding said one or more actions if said user refuses to provide affirmative conformation;

wherein said user of said trusted system confirms that said actions at said untrusted system may be permitted by any of entering a password and typing a special password.

Assignments (8)
CHANGE OF NAME Recorded Dec 20, 2021
From: FACEBOOK, INC.
To: META PLATFORMS, INC.
Reel/Frame 058961/0436 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 3, 2012
From: AOL INC.
To: FACEBOOK, INC.
Reel/Frame 028487/0304 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Nov 16, 2010
From: BANK OF AMERICA, N A
To: AOL INC; AOL ADVERTISING INC; GOING INC; LIGHTNINGCAST LLC; MAPQUEST, INC; NETSCAPE COMMUNICATIONS CORPORATION; QUIGO TECHNOLOGIES LLC; SPHERE SOURCE, INC; TACODA LLC; TRUVEO, INC; YEDDA, INC
Reel/Frame 025323/0416 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 30, 2009
From: AOL LLC
To: AOL INC.
Reel/Frame 023750/0210 →
SECURITY AGREEMENT Recorded Dec 14, 2009
From: AOL INC.; AOL ADVERTISING INC.; BEBO, INC.; ICQ LLC; GOING, INC.; LIGHTNINGCAST LLC; MAPQUEST, INC.; NETSCAPE COMMUNICATIONS CORPORATION; QUIGO TECHNOLOGIES LLC; SPHERE SOURCE, INC.; TACODA LLC; TRUVEO, INC.; YEDDA, INC.
To: BANK OF AMERICAN, N.A. AS COLLATERAL AGENT
Reel/Frame 023649/0061 →
CORRECTIVE ASSIGNMENT TO CORRECT THE NATURE OF CONVEYANCE PREVIOUSLY RECORDED ON REEL 019711 FRAME 0316. ASSIGNOR(S) HEREBY CONFIRMS THE NATURE OF CONVEYANCE IS CHANGE OF NAME. Recorded Mar 25, 2009
From: AMERICA ONLINE, INC.
To: AOL LLC, A DELAWARE LIMITED LIABILITY COMPANY
Reel/Frame 022451/0186 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 17, 2007
From: AMERICA ONLINE, INC.
To: AOL LLC, A DELAWARE LIMITED LIABILITY COMPANY
Reel/Frame 019711/0316 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 28, 2003
From: ROSKIND, JAMES
To: AMERICA ONLINE, INC.
Reel/Frame 013822/0318 →