IP Library Granted Patent US 10,193,880
Granted Patent B1
US 10,193,880 · App. 14/848,958 · Granted Jan 29, 2019

Systems and methods for registering user accounts with multi-factor authentication schemes used by online services

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,193,880
App. No.
14/848,958
Granted
Jan 29, 2019
Kind
B1
Abstract

The disclosed computer-implemented method for registering user accounts with multi-factor authentication schemes used by online services may include (1) determining that a user is associated with an account with an online service that allows the user to register the account with an MFA scheme that requests the user to complete multiple authentication steps before being allowed to access the account, (2) identifying, based on an analysis of the online service, at least a portion of the information that is requested by the online service to register the account with the MFA scheme, and (3) providing the requested information to the online service such that the account is registered with the MFA scheme. Various other methods, systems, and computer-readable media are also disclosed.

Claims (62)

1. A computer-implemented method for registering user accounts with multi-factor authentication schemes used by online services, at least a portion of the method being performed by a computing device comprising at least one processor, the method comprising:

determining, on a client device of a user, that the user is attempting to:

create an account managed by an online service; and

while creating the account, register the account with a multi-factor authentication scheme that requests the user to complete a plurality of authentication steps before being allowed to access the account;

determining, on the client device of the user, based on an analysis of the online service, that the online service requests at least an item of personal identification information associated with the user to register the account with the multi-factor authentication scheme;

identifying the item of personal identification information associated with the user by:

accessing a credential vault stored on the client device that contains authentication information the user has previously provided to additional online services while registering additional accounts; and

determining, based on the authentication information stored within the credential vault, that the user has previously provided the item of personal identification information to an additional online service while registering an additional account but has not provided the item of personal identification information to the online service; and

registering the account with the multi-factor authentication scheme by providing, from the client device of the user to the online service, at least the item of personal identification information associated with the user.

2. The method of claim 1 , further comprising determining that:

the user has an existing account with an additional online service; and

the user has not yet registered the existing account with an additional multi-factor authentication scheme provided by the additional online service.

3. The method of claim 2 , further comprising prompting the user to initiate an at least partially automatic process of providing an additional item of personal identification information to the additional online service to register the existing account with the additional multi-factor authentication scheme.

4. The method of claim 1 , wherein determining that the online service requests the item of personal identification information associated with the user comprises searching a user interface of the online service for user input fields that request information from the user.

5. The method of claim 1 , wherein determining that the online service requests the item of personal identification information associated with the user comprises:

identifying the online service; and

searching a database that stores information about multi-factor authentication schemes used by a plurality of online services for information that is known to be requested by the online service when users register accounts with the multi-factor authentication scheme used by the online service.

6. The method of claim 1 , wherein the item of personal identification information associated with the user comprises at least one of:

an address of the user;

a phone number of the user; and

an answer to a security question.

7. The method of claim 1 , wherein the credential vault is maintained by a browser extension running on the client device of the user.

8. The method of claim 1 , further comprising:

determining that the online service requests a cryptographic authentication code generated by a token to register the account with the multi-factor authentication scheme; and

utilizing a virtual representation of the token to provide the cryptographic authentication code to the online service.

9. The method of claim 1 , wherein providing, to the online service, the item of personal identification information associated with the user comprises monitoring interactions between the online service and at least one additional user to generate an automated script that provides the item of personal identification information to the online service.

10. A system for authenticating users to online services that use multi-factor authentication, the system comprising:

a determination module, stored in memory, that determines, on a client device of a user, that the user is attempting to:

create an account managed by an online service; and

while creating the account, register the account with a multi-factor authentication scheme that requests the user to complete a plurality of authentication steps before being allowed to access the account;

an identification module, stored in memory, that determines, on the client device of the user, based on an analysis of the online service, that the online service requests at least an item of personal identification information associated with the user to register the account with the multi-factor authentication scheme;

a providing module, stored in memory, that:

identifies the item of personal identification information associated with the user by:

accessing a credential vault stored on the client device that contains authentication information the user has previously provided to additional online services while registering additional accounts; and

determining, based on the authentication information stored within the credential vault, that the user has previously provided the item of personal identification information to an additional online service while registering an additional account; and

registers the account with the multi-factor authentication scheme by providing, from the client device of the user to the online service, at least the item of personal identification information associated with the user but has not provided the item of personal identification information to the online service; and

at least one physical processor configured to execute the determination module, the identification module, and the providing module.

11. The system of claim 10 , wherein the determination module further determines that:

the user has an existing account with an additional online service; and

the user has not yet registered the existing account with an additional multi-factor authentication scheme provided by the additional online service.

12. The system of claim 11 , further comprising a prompting module that prompts the user to initiate an at least partially automatic process of providing an additional item of personal identification information to the additional online service to register the existing account with the additional multi-factor authentication scheme.

13. The system of claim 10 , wherein the identification module determines that the online service requests the item of personal identification information associated with the user by searching a user interface of the online service for user input fields that request information from the user.

14. The system of claim 10 , wherein the identification module determines that the online service requests the item of personal identification information associated with the user by:

identifying the online service; and

searching a database that stores information about multi-factor authentication schemes used by a plurality of online services for information that is known to be requested by the online service when users register accounts with the multi-factor authentication scheme used by the online service.

15. The system of claim 10 , wherein the item of personal identification information comprises at least one of:

an address of the user;

a phone number of the user; and

an answer to a security question.

16. The system of claim 10 , wherein the providing module maintains the credential vault within a browser extension running on the client device of the user.

17. A non-transitory computer-readable medium comprising one or more computer-readable instructions that, when executed by at least one processor of a computing device, cause the computing device to:

determine, on a client device of a user, that the user is attempting to:

create an account managed by an online service; and

while creating the account, register the account with a multi-factor authentication scheme that requests the user to complete a plurality of authentication steps before being allowed to access the account;

determine, on the client device of the user, based on an analysis of the online service, that the online service requests at least an item of personal identification information associated with the user to register the account with the multi-factor authentication scheme;

identify the item of personal identification information associated with the user by:

accessing a credential vault stored on the client device that contains authentication information the user has previously provided to additional online services while registering additional accounts; and

determining, based on the authentication information stored within the credential vault, that the user has previously provided the item of personal identification information to an additional online service while registering an additional account but has not provided the item of personal identification information to the online service; and

register the account with the multi-factor authentication scheme by providing, from the client device of the user to the online service, at least the item of personal identification information associated with the user.

18. The method of claim 3 , wherein prompting the user to initiate the at least partially automatic process of providing the additional item of personal identification information to the additional online service to register the existing account with the additional multi-factor authentication scheme comprises:

determining that the additional online service has recently made the additional multi-factor authentication scheme available for the existing account; and

alerting the user that the additional multi-factor authentication scheme has become available.

Assignments (6)
CHANGE OF NAME Recorded Feb 6, 2023
From: NORTONLIFELOCK INC.
To: GEN DIGITAL INC.
Reel/Frame 062714/0605 →
NOTICE OF SUCCESSION OF AGENCY (REEL 050926 / FRAME 0560) Recorded Sep 13, 2022
From: JPMORGAN CHASE BANK, N.A.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 061422/0371 →
SECURITY AGREEMENT Recorded Sep 13, 2022
From: NORTONLIFELOCK INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062220/0001 →
CHANGE OF NAME Recorded Feb 14, 2020
From: SYMANTEC CORPORATION
To: NORTONLIFELOCK INC.
Reel/Frame 051935/0228 →
SECURITY AGREEMENT Recorded Nov 4, 2019
From: SYMANTEC CORPORATION; BLUE COAT LLC; LIFELOCK, INC,; SYMANTEC OPERATING CORPORATION
To: JPMORGAN, N.A.
Reel/Frame 050926/0560 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 9, 2015
From: JIANG, KEVIN; SOKOLOV, ILYA
To: SYMANTEC CORPORATION
Reel/Frame 036522/0577 →
Cited By (8)
US 12,301,575 US 12,381,868 US 12,437,040 US 12,554,819 US 12,556,917 US 12,695,743 US 12,700,886 US 12,712,587