IP Library › Granted Patent US 8,010,996
Granted Patent B2
US 8,010,996 · App. 11/627,161 · Granted Aug 30, 2011

Authentication seal for online applications

Assignee: Yahoo! Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,010,996
App. No.
11/627,161
Granted
Aug 30, 2011
Kind
B2
Abstract

A network device and method are directed towards providing a client side sign-in seal for use detecting phishing attempts. In one embodiment, a user of a client device may provide anti-phishing data through a sign-in setup user interface for a website, application, or the like. In one embodiment, the anti-phishing data is an image provided by the user. The user may also provide text, symbols, an audio clip, or the like. The user may also modify aspects of the image, text, symbols, or the like, such as a color. When the user accesses the website, application, or the like, the client device may provide client device data used to locate and display the sign-in seal. If the user is being phished, the anti-phishing data may not be displayed or otherwise played.

Claims (46)

1. In a client computing device, having a graphical user interface including a display and a user interface selection device, a method of generating an anti-phishing mechanism, comprising:

retrieving an interface screen that is configured to display user selectable anti-phishing options for use in creating a client side sign-in seal, wherein the client side sign-in seal is independent of a user authentication, and wherein the interface for at least creating and managing the client side sign-in seal is independent of a user authentication;

receiving a selection through the user interface selection device of at least one of the user selectable anti-phishing options;

modifying the interface screen to enable the user to provide anti-phishing data based on the selected anti-phishing option wherein the user is enabled to modify at least one feature of the provided anti-phishing data, in part, by modifying the interface screen to display additional selectable anti-phishing options and wherein the at least one feature further comprises at least one of a color, a size, or a rotation of the provided anti-phishing data;

displaying a requested webpage within the display; and

if the webpage is authentic, based in part on the anti-phishing data, then displaying the client side sign-in seal independent of user authentication.

2. The method of claim 1 , further comprising:

accessing the webpage, wherein the webpage is configured to receive sensitive information; and

selecting a link to a sign-in seal setup user interface.

3. The method of claim 1 , wherein displaying selectable anti-phishing options further comprises displaying at least one of a text input option, an image input option, or an audio input option.

4. The method of claim 1 , further comprising providing a selector within the interface screen to enable the user to preview the client side sign-in seal, wherein the selector is inactive until the user provides anti-phishing data.

5. The method of claim 1 , further comprising:

receiving client device data in a persistent cookie, in response, in part, to providing the anti-phishing data and information about the webpage.

6. The method of claim 5 , wherein the client device data further comprises information that is based in part on a characteristic of the client device.

7. A network device for detecting a phishing attack, comprising:

a transceiver to send and receive data over a network; and

a processor that is operative to perform actions, including:

providing to a client device a user interface independent of user authentication and that is configured to progressively provide selectable options to a user based on received input;

receiving from the client device, anti-phishing data for an application, independent of user authentication at the network device;

modifying the user interface to provide at least one option to enable a user to selectively modify at least one feature of the received anti-phishing data wherein the user is enabled to modify at least one feature of the provided anti-phishing data, in part, by further modifying the user interface to display additional selectable anti-phishing options and wherein the at least one feature further comprises at least one of a color, a size, or a rotation of the provided anti-phishing data;

creating a client side sign-in seal based on the anti-phishing data and optionally the at least one selectively modified feature of the received anti-phishing data, the client side sign-in seal being independent of user authentication; and

if a screen display associated with the application is requested by the client device, using the anti-phishing data to selectively display the client side sign-in seal with the screen display to indicate that the application is authentic and wherein displaying the client side sign-in seal is independent of a user authentication.

8. The network device of claim 7 , wherein the anti-phishing data further comprises at least one of text, a symbol, a graphic, an image, an audio file, or a link to a graphic, an image, or an audio file.

9. The network device of claim 7 , wherein the at least one feature further comprises at least one of a font size, a resolution, a displayed angle, or a font type.

10. The network device of claim 7 , wherein progressively providing selectable options further comprises displaying at least one selectable option only after the user provides input to at least one prior displayed selectable option.

11. The network device of claim 7 , wherein progressively providing selectable options further comprises enabling a selectable option to save anti-phishing data after the anti-phishing data is received from the client device.

12. The network device of claim 7 , wherein the user interface further displays at least one user selectable frequently asked question, wherein if the user selects at least one frequently asked question an answer is displayed.

13. The network device of claim 7 , wherein the application is at least one of a web application, a webpage, or a messenger application.

14. A system for use in detecting a phishing attack over a network, comprising:

a first computing device that includes a processor and computer executable instructions that enable actions, including:

sending, over the network, a user interface that is independent of a user authentication and is configured to receive anti-phishing data useable in creating a client side sign-in seal; and

in response to receiving anti-phishing data, creating a client side sign-in seal independent of user authentication;

sending another user interface, wherein the other user interface enables a user to at least one of previewing the client side sign-in seal, or providing a modification to at least one feature of the anti-phishing data wherein the user is enabled to modify at least one feature of the anti-phishing data, in part, by modifying the user interface to display additional selectable anti-phishing options and wherein the at least one feature further comprises at least one of a color, a size, or a rotation of the provided anti-phishing data; and

a second computing device that includes a processor and computer executable instructions that enable actions, including:

displaying the user interface;

sending to the first computing device anti-phishing data to be associated with a website, wherein the anti-phishing data is associated with a client device;

requesting a webpage associated with the website, wherein the webpage is configured to receive sensitive information; and

detecting a phishing attempt based on whether the client side sign-in seal is displayed by the website and wherein selectively displaying the client side sign-in seal is independent of a user authentication and is further determined based at least in part on the anti-phishing data.

15. The system of claim 14 , wherein sending the anti-phishing data further comprises: providing a location identifier for at least one of an image file, a text file, or an audio file.

16. The system of claim 14 , wherein sending the anti-phishing data further comprises: providing text data.

17. The system of claim 14 , wherein providing a modification to at least one feature further comprises providing at least one modification to the anti-phishing data based on a font type change.

18. The system of claim 14 , wherein the anti-phishing data is user independent.

19. The system of claim 14 , wherein sending another user interface further comprises inhibiting the previewing of the client side sign-in seal and the providing of a modification to at least one feature until the anti-phishing data is provided.

20. The system of claim 14 , wherein detecting whether the requested webpage is phished further comprises:

if the requested webpage is displayed absent the anti-phishing data, indicating a phishing attempt; and

if the requested webpage is displayed with the anti-phishing data, indicating that a phishing attempt is undetected.

Assignments (9)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE ASSIGNOR NAME PREVIOUSLY RECORDED AT REEL: 052853 FRAME: 0153. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Mar 29, 2021
From: R2 SOLUTIONS LLC
To: STARBOARD VALUE INTERMEDIATE FUND LP, AS COLLATERAL AGENT
Reel/Frame 056832/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE NAME PREVIOUSLY RECORDED ON REEL 053654 FRAME 0254. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST GRANTED PURSUANT TO THE PATENT SECURITY AGREEMENT PREVIOUSLY RECORDED. Recorded Dec 30, 2020
From: STARBOARD VALUE INTERMEDIATE FUND LP
To: R2 SOLUTIONS LLC
Reel/Frame 054981/0377 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jul 8, 2020
From: STARBOARD VALUE INTERMEDIATE FUND LP
To: ACACIA RESEARCH GROUP LLC; AMERICAN VEHICULAR SCIENCES LLC; BONUTTI SKELETAL INNOVATIONS LLC; CELLULAR COMMUNICATIONS EQUIPMENT LLC; INNOVATIVE DISPLAY TECHNOLOGIES LLC; LIFEPORT SCIENCES LLC; LIMESTONE MEMORY SYSTEMS LLC; MOBILE ENHANCEMENT SOLUTIONS LLC; MONARCH NETWORKING SOLUTIONS LLC; NEXUS DISPLAY TECHNOLOGIES LLC; PARTHENON UNIFIED MEMORY ARCHITECTURE LLC; R2 SOLUTIONS LLC; SAINT LAWRENCE COMMUNICATIONS LLC; STINGRAY IP SOLUTIONS LLC; SUPER INTERCONNECT TECHNOLOGIES LLC; TELECONFERENCE SYSTEMS LLC; UNIFICATION TECHNOLOGIES LLC
Reel/Frame 053654/0254 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 25, 2020
From: EXCALIBUR IP, LLC
To: R2 SOLUTIONS LLC
Reel/Frame 053459/0059 →
PATENT SECURITY AGREEMENT Recorded Jun 5, 2020
From: ACACIA RESEARCH GROUP LLC; AMERICAN VEHICULAR SCIENCES LLC; BONUTTI SKELETAL INNOVATIONS LLC; CELLULAR COMMUNICATIONS EQUIPMENT LLC; INNOVATIVE DISPLAY TECHNOLOGIES LLC; LIFEPORT SCIENCES LLC; LIMESTONE MEMORY SYSTEMS LLC; MERTON ACQUISITION HOLDCO LLC; MOBILE ENHANCEMENT SOLUTIONS LLC; MONARCH NETWORKING SOLUTIONS LLC; NEXUS DISPLAY TECHNOLOGIES LLC; PARTHENON UNIFIED MEMORY ARCHITECTURE LLC; R2 SOLUTIONS LLC; SAINT LAWRENCE COMMUNICATIONS LLC; STINGRAY IP SOLUTIONS LLC; SUPER INTERCONNECT TECHNOLOGIES LLC; TELECONFERENCE SYSTEMS LLC; UNIFICATION TECHNOLOGIES LLC
To: STARBOARD VALUE INTERMEDIATE FUND LP, AS COLLATERAL AGENT
Reel/Frame 052853/0153 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 3, 2016
From: YAHOO! INC.
To: EXCALIBUR IP, LLC
Reel/Frame 038950/0592 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 1, 2016
From: EXCALIBUR IP, LLC
To: YAHOO! INC.
Reel/Frame 038951/0295 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 18, 2016
From: YAHOO! INC.
To: EXCALIBUR IP, LLC
Reel/Frame 038383/0466 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 20, 2007
From: CLINE, LEE KIMBALL; GUPTA, AANCHAL; BLESSING, CHRISTOPHER MICHAEL; TESLER, LAWRENCE GORDON; GEISHECKER, JOHN ANDREW, III; AGARWAL, NAVEEN; BEJAR, ARTURO; HENDRICKS, DANIEL ALEXANDER
To: YAHOO! INC.
Reel/Frame 019188/0043 →
Continuity (2)
Continuation In Part 11458048 · Jul 17, 2006
Related Publication 20080046968A1 · Feb 21, 2008