IP Library Granted Patent US 8,763,078
Granted Patent B1
US 8,763,078 · App. 13/827,201 · Granted Jun 24, 2014

System and method for monitoring authentication attempts

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,763,078
App. No.
13/827,201
Granted
Jun 24, 2014
Kind
B1
Abstract

When an authentication attempt is made to gain access to a secure environment is made, a notification is transmitted to the user associated with the user identification used in the authentication attempt. If the user who receives the notification did not make the authentication attempt, then the user alerts the appropriate parties of a breach in security.

Claims (54)

1. A computer-implemented method for notifying users when attempts to login into a secure environment are made, the method comprising:

determining that an authentication attempt has been made with credentials belonging to a user;

determining that a notification indicating that the authentication attempt has been made is to be transmitted to the user;

transmitting the notification to the user in response to the authentication attempt and every other time that the user makes an authentication attempt;

wherein determining that the notification is to be transmitted comprises evaluating a set of notification rules to determine;

wherein the notification rules specify one or more of: users to which notifications are not to be sent; a threshold distance for use in evaluating a distance a distance between a location from which a previous authentication attempt made with the credentials belonging to the user and a location from which the authentication attempt was made; a time period in a day during which notifications are not to be transmitted.

2. The method of claim 1 , wherein a first notification rule in the set of notification rules specifies a list of users to which notifications are not to be transmitted, and evaluating the first notification rule comprises determining whether the user is included in the list of users.

3. The method of claim 1 , wherein a first notification rule in the set of notification rules specifies a threshold distance, and evaluating the first notification rule comprises determining whether a distance between a location from which a previous authentication attempt made with the credentials belonging to the user and a location from which the authentication attempt was made is below the threshold distance.

4. The method of claim 1 , wherein a first notification rule in the set of notification rules specifies a time period in a day during which notifications are not to be transmitted, and evaluating the first notification rule comprises determining whether a current time does not fall within the time period.

5. The method of claim 1 , wherein determining that the authentication attempt has been made comprises accessing a login record maintained by an authentication service, wherein the login record indicates at least the authentication attempt.

6. The method of claim 1 , transmitting the notification to the user comprises retrieving a notification handle associated with the user from a user information repository and transmitting the notification to the user via the notification handle.

7. The method of claim 6 , wherein the notification handle comprises a telephone number associated with the user and transmitting the notification to the user further comprises transmitting a short message to the telephone number via a short messaging system.

8. The method of claim 1 , further comprising determining that the user belongs to a first category that includes high-risk users, and transmitting the notification to an additional user.

9. A non-transitory computer readable storage medium storing instructions that, when executed by a processor, cause the processor to notify users when attempts to login into a secure environment are made, by performing the steps of:

determining that an authentication attempt has been made with credentials belonging to a user;

determining that a notification indicating that the authentication attempt has been made is to be transmitted to the user;

transmitting the notification to the user in response to the authentication attempt and every other time that the user makes an authentication attempt;

wherein determining that the notification is to be transmitted comprises evaluating a set of notification rules to determine;

wherein the notification rules specify one or more of: users to which notifications are not to be sent; a threshold distance for use in evaluating a distance a distance between a location from which a previous authentication attempt made with the credentials belonging to the user and a location from which the authentication attempt was made; a time period in a day during which notifications are not to be transmitted.

10. The computer readable medium of claim 9 , wherein a first notification rule in the set of notification rules specifies a list of users to which notifications are not to be transmitted, and evaluating the first notification rule comprises determining whether the user is included in the list of users.

11. The computer readable medium of claim 9 , wherein a first notification rule in the set of notification rules specifies a threshold distance, and evaluating the first notification rule comprises determining whether a distance between a location from which a previous authentication attempt made with the credentials belonging to the user and a location from which the authentication attempt was made is below the threshold distance.

12. The computer readable medium of claim 9 , wherein a first notification rule in the set of notification rules specifies a time period in a day during which notifications are not to be transmitted, and evaluating the first notification rule comprises determining whether a current time does not fall within the time period.

13. The computer readable medium of claim 9 , wherein determining that the authentication attempt has been made comprises accessing a login record maintained by an authentication service, wherein the login record indicates at least the authentication attempt.

14. The computer readable medium of claim 9 , transmitting the notification to the user comprises retrieving a notification handle associated with the user from a user information repository and transmitting the notification to the user via the notification handle.

15. The computer readable medium of claim 14 , wherein the notification handle comprises a telephone number associated with the user and transmitting the notification to the user further comprises transmitting a short message to the telephone number via a short messaging system.

16. The computer readable medium of claim 9 , further comprising determining that the user belongs to a first category that includes high-risk users, and transmitting the notification to an additional user.

17. A computer system, comprising:

a memory; and

a processor configured to:

determine that an authentication attempt has been made with credentials belonging to a user,

determine that a notification indicating that the authentication attempt has been made is to be transmitted to the user,

transmit the notification to the user in response to the authentication attempt and every other time that the user makes an authentication attempt;

and to determine that the notification is to be transmitted by evaluating a set of notification rules to determine;

wherein the notification rules specify one or more of: users to which notifications are not to be sent; a threshold distance for use in evaluating a distance a distance between a location from which a previous authentication attempt made with the credentials belonging to the user and a location from which the authentication attempt was made; a time period in a day during which notifications are not to be transmitted.

18. The computer system of claim 17 , wherein the memory includes instructions that cause the processor to determine that an authentication attempt has been made with credentials belonging to a user, determine that a notification indicating that the authentication attempt has been made is to be transmitted to the user, and transmit the notification to the user.

19. A computer-implemented method comprising:

determining that an authentication attempt has been made with credentials belonging to a user, wherein the authentication attempt is associated with a login to a secure environment;

determining that a notification indicating that the authentication attempt has been made is to be transmitted to the user by evaluating a set of notification rules to determine;

wherein a first notification rule in the set specifies a list of users to which notifications are not to be transmitted, and evaluating the first notification rule comprises determining whether the user is in the list of users;

wherein a second notification rule in the set specifies a threshold distance, and evaluating the second notification rule comprises determining whether a distance, between a first location of a previous authentication attempt with the credentials belonging to the user and a second location from which the authentication attempt was made, is below the threshold distance;

wherein a third notification rule in the set specifies a time period in a day during which notifications are not to be transmitted, and evaluating the third notification rule comprises determining whether a current time does not fall within the time period;

transmitting the notification to the user when at least one of the notification rules is satisfied;

wherein the method is performed using one or more computing systems.

20. The method of claim 19 further comprising determining that the user belongs to a first category that includes high-risk users, and transmitting the notification to an additional user.

21. A computer system, comprising:

a memory; and

a processor configured to:

determine that an authentication attempt has been made with credentials belonging to a user, wherein the authentication attempt is associated with a login to a secure environment;

determine that a notification indicating that the authentication attempt has been made is to be transmitted to the user by evaluating a set of notification rules to determine;

wherein a first notification rule in the set specifies a list of users to which notifications are not to be transmitted, and evaluating the first notification rule comprises determining whether the user is in the list of users;

wherein a second notification rule in the set specifies a threshold distance, and evaluating the second notification rule comprises determining whether a distance, between a first location of a previous authentication attempt with the credentials belonging to the user and a second location from which the authentication attempt was made, is below the threshold distance;

wherein a third notification rule in the set specifies a time period in a day during which notifications are not to be transmitted, and evaluating the third notification rule comprises determining whether a current time does not fall within the time period;

transmit the notification to the user when at least one of the notification rules is satisfied.

22. The computer system of claim 21 further configured to determine that the user belongs to a first category that includes high-risk users, and transmitting the notification to an additional user.

Assignments (8)
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENTS Recorded Jul 3, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: WELLS FARGO BANK, N.A.
Reel/Frame 060572/0640 →
SECURITY INTEREST Recorded Jul 3, 2022
From: PALANTIR TECHNOLOGIES INC.
To: WELLS FARGO BANK, N.A.
Reel/Frame 060572/0506 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ERRONEOUSLY LISTED PATENT BY REMOVING APPLICATION NO. 16/832267 FROM THE RELEASE OF SECURITY INTEREST PREVIOUSLY RECORDED ON REEL 052856 FRAME 0382. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST. Recorded Aug 26, 2021
From: ROYAL BANK OF CANADA
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 057335/0753 →
SECURITY INTEREST Recorded Jun 4, 2020
From: PALANTIR TECHNOLOGIES INC.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 052856/0817 →
RELEASE OF SECURITY INTEREST Recorded Jun 4, 2020
From: ROYAL BANK OF CANADA
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 052856/0382 →
SECURITY INTEREST Recorded Jan 27, 2020
From: PALANTIR TECHNOLOGIES INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS ADMINISTRATIVE AGENT
Reel/Frame 051713/0149 →
SECURITY INTEREST Recorded Jan 27, 2020
From: PALANTIR TECHNOLOGIES INC.
To: ROYAL BANK OF CANADA, AS ADMINISTRATIVE AGENT
Reel/Frame 051709/0471 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 14, 2013
From: CASTELLUCCI, RYAN; GETTINGS, NATHAN; BELKNAP, GEOFF
To: PALANTIR TECHNOLOGIES, INC.
Reel/Frame 030000/0544 →