IP Library Granted Patent US 10,061,914
Granted Patent B2
US 10,061,914 · App. 14/928,443 · Granted Aug 28, 2018

Account recovery protocol

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,061,914
App. No.
14/928,443
Granted
Aug 28, 2018
Kind
B2
Abstract

The present disclosure relates to receiving a request for recovery of an account associated with a user, sending a CAPTCHA challenge to a user device associated with the user, receiving an answer to the CAPTCHA challenge and a confirmation code wrapped by an encryption key derived from a provisional master password, sending a notification of the request for recovery to one or more trusted entities associated with the user, and receiving a confirmation of the request from one or more of the trusted entities. The confirmation includes a recovery token associated with the particular trusted entity and an encrypted confirmation code.

Claims (47)

1. At least one non-transitory computer storage medium on which are stored instructions for allowing a user to regain access to credentials stored by a password manager, comprising instructions that when executed cause an authentication server to:

receive a request for recovery of an account associated with a user;

send a challenge to a user device associated with the user;

receive an answer to the challenge and a confirmation code wrapped by an encryption key derived from a provisional master password;

send a notification of the request for recovery to one or more devices associated with trusted entities authorized by the user;

receive a confirmation of the request from one or more of the devices, the confirmation including a recovery token associated with the particular trusted entity and a keyed-hash message authentication code keyed with a confirmation code provided by the user device to the particular trusted entity;

determine that a consensus status has been reached responsive to receiving a predetermined number of the recovery tokens from the one or more devices; and

send the recovery token associated with each of the one or more devices to the user device,

wherein the recovery tokens allow the user device to decrypt an account recovery block and re-encrypt the account recovery block with a key derived from the provisional master password, promoting the provisional master password to a master password for the account, and

wherein the authentication server maintains no knowledge of the master password.

2. The at least one non-transitory computer storage medium of claim 1 , wherein the instructions further comprise instructions that when executed cause the authentication server to send an indication of the consensus status to the user device.

3. The at least one non-transitory computer storage medium of claim 1 , wherein the instructions further comprise instructions that when executed cause the authentication server to receive a designation of the one or more devices from the user.

4. An authentication server for allowing a user to regain access to credentials stored by a password manager, comprising:

one or more processors; and

a memory element coupled to the one or more processors, on which are stored instructions, comprising instructions that when executed cause the one or more processors to:

receive a request for recovery of an account associated with a user;

send a challenge to a user device associated with the user;

receive an answer to the challenge and a confirmation code wrapped by an encryption key derived from a provisional master password;

send a notification of the request for recovery to one or more devices associated with trusted entities authorized by the user;

receive a confirmation of the request from one or more of the devices, the confirmation including a recovery token associated with the particular trusted entity and keyed-hash message authentication code keyed with a confirmation code provided by the user device to the particular trusted entity;

determine that a consensus status has been reached responsive to receiving a predetermined number of the recovery tokens from the one or more devices; and

send the recovery token associated with each of the one or more devices to the user device,

wherein the recovery tokens allow the user device to decrypt an account recovery block and re-encrypt the account recovery block with a key derived from the provisional master password, promoting the provisional master password to a master password for the account, and

wherein the authentication server maintains no knowledge of the master password.

5. The authentication server of claim 4 , wherein the instructions further comprise instructions that when executed cause the one or more processors to send an indication of the consensus status to the user device.

6. The authentication server of claim 4 , wherein the instructions further comprise instructions that when executed cause the one or more processors to receive a designation of the one or more devices from the user.

7. A computer-implemented method for allowing a user to regain access to credentials stored by a password manager, comprising:

receiving, by an authentication server a request for recovery of an account associated with a user;

sending a challenge from the authentication server to a user device associated with the user;

receiving by the authentication server an answer to the challenge and a confirmation code wrapped by an encryption key derived from a provisional master password;

sending by the authentication server a notification of the request for recovery to one or more devices associated with trusted entities authorized by the user;

receiving by the authentication server a confirmation of the request from one or more of the devices, the confirmation including a recovery token associated with the particular trusted entity and a keyed-hash message authentication code keyed with a confirmation code provided by the user device to the particular trusted entity;

determining by the authentication server that a consensus status has been reached responsive to receiving a predetermined number of the recovery tokens from the one or more devices; and

sending by the authentication server the recovery token associated with each of the one or more devices to the user device,

wherein the recovery tokens allow the user device to decrypt an account recovery block and re-encrypt the account recovery block with a key derived from the provisional master password, promoting the provisional master password to a master password for the account, and

wherein the authentication server maintains no knowledge of the master password.

8. The computer-implemented method of claim 7 , further comprising sending by the authentication server an indication of the consensus status to the user device.

9. The computer-implemented method of claim 7 , further comprising receiving a designation of the one or more devices from the user.

10. At least one non-transitory computer storage medium on which are stored instructions for allowing a user to regain access to credentials stored by a password manager after loss of a master password, comprising instructions that when executed cause a user device to:

receive from an authentication server a confirmation code associated with a trusted entity of a plurality of user authorized trusted entities;

send the confirmation code to a device associated with the trusted entity with a request for the trusted entity to assist in recovery of access to the credentials;

receive a plurality of recovery tokens from the authentication server, each associated with one of the plurality of user authorized trusted entities;

receive from a user a provisional master password;

combine the plurality of recovery tokens, producing a key encryption key;

decrypt an account recovery block using the key encryption key;

generate a new key encryption key from the provisional master password; and

promote the provisional master password to the master password by reencrypting the account recovery block with the new key encryption key.

Assignments (19)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 057453, FRAME 0053 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0413 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 056990, FRAME 0960 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0430 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 1, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060561/0466 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 057315 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 11, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060878/0126 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
RELEASE OF SECURITY INTEREST Recorded Jul 26, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: MCAFEE, LLC; SKYHIGH NETWORKS, LLC
Reel/Frame 057620/0102 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →