IP Library Granted Patent US 9,300,674
Granted Patent B2
US 9,300,674 · App. 14/702,896 · Granted Mar 29, 2016

System and methods for authorizing operations on a service using trusted devices

Inventor: Nikolay V. Borovikov (Moscow, RU)
Assignee: Kaspersky Lab AO
H04L63/10H04L63/083H04L63/0861H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,300,674
App. No.
14/702,896
Granted
Mar 29, 2016
Kind
B2
Abstract

Disclosed are systems and methods for ensuring confidentiality of information of a user of a service. One example method includes receiving a request to perform an operation for a service; selecting, based on a database of trusted devices, a trusted device for authorizing the operation of the service; establishing a secure connection with the trusted device; sending to the trusted device via the secure connection a request to enter confidential information on the trusted device to authorize the operation of the service; receiving the confidential information from the trusted device; and determining whether to authorize the operation of the service based on the confidential information.

Claims (37)

1. A method for ensuring confidentiality of information used during authentication and authorization operations, the method comprising:

receiving a request from a first user to perform an operation for a service;

identifying a second user responsible for authorizing the operation of the service, the second user being different from the first user;

selecting, based on a database of trusted devices, a trusted device associated with the second user for authorizing the operation of the service;

establishing a secure connection with the trusted device;

sending to the trusted device via the secure connection a request to the second user to enter confidential information on the trusted device for authorizing to authorize the operation of the service;

receiving the confidential information from the trusted device; and

determining whether to authorize the operation of the service based on the confidential information.

2. The method of claim 1 , wherein the request is received from an unsecure device via an unsecure connection, and the operation for the service is performed on the unsecure device associated with the first user.

3. The method of claim 1 , wherein the trusted device is configured to use a hacking identification module to prevent authorized opening, theft, or hacking of software installed on the trusted device.

4. The method of claim 1 , wherein the confidential information comprises a password to an account record, biometric data, or a PIN code.

5. The method of claim 1 , wherein the trusted device comprises a notebook, a netbook, a smartphone, a mobile telephone, a communicator, or a thin client.

6. A system for ensuring confidentiality of information used during authentication and authorization operations, the system comprising:

a processor configured to:

receive a request from a first user to perform an operation for a service;

identify a second user responsible for authorizing the operation of the service, the second user being different from the first user;

select, based on a database of trusted devices, a trusted device associated with the second user for authorizing the operation of the service;

establish a secure connection with the trusted device;

send to the trusted device via the secure connection a request to the second user to enter confidential information on the trusted device for authorizing the operation of the service;

receive the confidential information from the trusted device; and

determine whether to authorize the operation of the service based on the confidential information.

7. The system of claim 6 , wherein the request is received from an unsecure device via an unsecure connection, and the operation for the service is performed on the unsecure device associated with the first user.

8. The system of claim 6 , wherein the trusted device is configured to use a hacking identification module to prevent authorized opening, theft, or hacking of software installed on the trusted device.

9. The system of claim 6 , wherein the confidential information comprises a password to an account record, biometric data, or a PIN code.

10. The system of claim 6 , wherein the trusted device comprises a notebook, a netbook, a smartphone, a mobile telephone, a communicator, or a thin client.

11. A non-transitory computer-readable storage medium having a computer program product stored thereon, the computer-readable storage medium comprising computer-executable instructions for ensuring confidentiality of information used during authentication and authorization operations, the instructions comprising:

receiving a request from a first user to perform an operation for a service;

identifying a second user responsible for authorizing the operation of the service, the second user being different from the first user;

selecting, based on a database of trusted devices, a trusted device associated with the second user for authorizing the operation of the service;

establishing a secure connection with the trusted device;

sending to the trusted device via the secure connection a request to the second user to enter confidential information on the trusted device for authorizing to of the operation of the service;

receiving the confidential information from the trusted device; and

determining whether to authorize the operation of the service based on the confidential information.

12. The computer-readable storage medium of claim 11 , wherein the request is received from an unsecure device via an unsecure connection, and the operation for the service is performed on the unsecure device associated with the first user.

13. The computer-readable storage medium of claim 11 , wherein the trusted device is configured to use a hacking identification module to prevent authorized opening, theft, or hacking of software installed on the selected trusted device.

14. The computer-readable storage medium of claim 11 , wherein the instructions further comprises identifying another trusted device in the database of trusted devices associated with the second user for authorizing the operation of the service.

15. The computer-readable storage medium of claim 11 , wherein the confidential information comprises a password to an account record, biometric data, or a PIN code, and the trusted device comprises a notebook, a netbook, a smartphone, a mobile telephone, a communicator, or a thin client.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 4, 2015
From: BOROVIKOV, NIKOLAY V.
To: KASPERSKY LAB ZAO
Reel/Frame 035554/0517 →
Priority Claims (1)
RU 2013134220 · Jul 23, 2013 · national
Continuity (2)
Continuation 14256357 · Apr 18, 2014
Related Publication 20150237054A1 · Aug 20, 2015