IP Library Granted Patent US 9,887,995
Granted Patent B2
US 9,887,995 · App. 15/075,053 · Granted Feb 6, 2018

Locking applications and devices using secure out-of-band channels

Inventors: Bradley N. Rotter (San Mateo, CA); Pavan K. Muddana (Cerrtos, CA)
Assignee: CYBERDEADBOLT INC.
H04L63/0861H04W12/06H04L63/1425H04W12/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,887,995
App. No.
15/075,053
Filed
Mar 18, 2016
Granted
Feb 6, 2018
Kind
B2
Art Unit
2497
USPC
726/4
Abstract

Systems and methods are provided for locking/unlocking a user account for accessing a client application. The systems and methods pair a user account for accessing a client application to a separate user authentication account. The user authentication server managing the user authentication account provides heightened measures for authenticating the identity of the user, such as by voice samples and human authenticator. After the heightened authentication of the user, the user may lock or unlock paired accounts from the user authentication account, wherein preventing all attempts to access the client application using the paired account. The client application may also capture information regarding login attempts to the paired user account. The captured information may be sent to the authentication server for providing reports of login attempts and generating alerts to automatically lock the paired account in cases of suspicious behavior.

Claims (65)

1. A computer-implemented method for changing the lock status of a user account for a client application, the computer-implemented method comprising:

accessing a user authentication account via an authentication application configured on a user device, the user device communicatively coupled to the authentication server, and the user authentication account containing a pairing to the user account for the client application, wherein performing the pairing comprises:

generating identification information for the client application, the identification information saved at both the client application and the authentication server configured to manage the user authentication account;

selecting an option at the client application for enabling pairing of the user account for the client application to the user authentication account;

generating a pairing code in response to selecting the option, the pairing code comprising at least a client identifier, client name, and unique pairing identifier for the user account;

accessing the user authentication account via the authentication application configured on the user device;

selecting a pairing option through the authentication application, the pairing option authenticating the selector as a registered user of the user authentication account;

in response to authenticating the user, enabling the user to provide the pairing code to the authentication application, wherein the authentication application validates the client information contained in the pairing code against the identification information for the client application saved at the authentication server; and

in response to validating the user, sending the information contained in the pairing code to the authentication server to be stored in the user authentication account, wherein the pairing code information is linked to the saved identification information for the client application;

selecting the pairing and an option to change the status of the pairing via the authentication application;

in response to selection of the pairing, authenticating the selector as a registered user of the user authentication account;

in response to authenticating the user, sending a request to the authentication server with a pairing code for the pairing and the changed lock status;

transmitting, by the authentication server, an event to the client application identified in the pairing code, the event being received by the client application and the changed lock status saved at the client application for the pairing identified in the event; and

determining login access to the paired user account by the client application based on the saved lock status stored at the client application.

2. The computer-implemented method of claim 1 , wherein pairing to the user account, receiving the transmitted event, and saving the changed lock status is performed by an application programming interface (API) installed at the client application, the installed API communicatively coupled to the authentication server.

3. The computer-implemented method of claim 1 , wherein the client application is at least one of an online: service provider, wireless router, security system, wirelessly controlled appliance, and automatic car door.

4. The computer-implemented method of claim 1 , wherein communication between the user device and the client application and between the authentication server and the user device is over a distributed peer-to-peer decentralized network.

5. The computer-implemented method of claim 1 , wherein communication between the user device and the authentication server and between the client application and the authentication server is in a trusted execution environment.

6. The computer-implemented method of claim 1 , wherein the authenticating of the selector includes at least one of: comparing voice samples, comparing biometric information, comparing behavioral information, and contacting human authenticators.

7. The computer-implemented method of claim 1 , wherein the lock status is one of locked or unlocked.

8. The computer-implemented method of claim 1 , wherein the pairing code is a quick response (QR) code, and wherein the user scans the pairing code to provide the pairing code to the authentication application.

9. The computer-implemented method of claim 1 , further comprising monitoring the login activity of the user account for the client application comprising:

capturing each login attempt to the user account for the client application, the capturing sending collected information related to the captured login attempts to an authentication server;

capturing, at the authentication server, each lock attempt and unlock attempt to the login account for the client application through a paired user authentication account;

removing all personal identifiable information from information collected related to the captured login attempts, captured lock attempts, and captured unlock attempts;

generating reports indicating the health of the login account based on the collected information;

automatically changing the lock status for the user account to lock based on the collected information indicating a pattern of failed login attempts; and

generating an alert to a computing device of a user of the login account when a cyber-attack on the login account is detected from the collected information.

10. A computer system for changing the lock status of a user account for a client application, the computer system comprising:

a user device configured with an authentication application, the user device configured, via the authentication application, to:

access a user authentication account on an authentication server, and the user authentication account containing a pairing to the user account for the client application, wherein performing the pairing comprises:

configuring the authentication server to manage the user authentication account;

configuring the client application to:

generate identification information for the client application, the identification information saved at both the client application and the authentication server;

enable selecting of an option at the client application for enabling pairing of the user account for the client application to the user authentication account; and

generate a pairing code in response to selecting the option, the pairing code comprising at least a client identifier, client name, and unique pairing identifier for the user account; and

configuring the user device configured to:

access the user authentication account via the authentication application;

enable selecting of a pairing option via the authentication application, the pairing option authenticating the selector as a registered user of the user authentication account;

in response to authenticating the user, enable the user to provide the pairing code to the authentication application, wherein the authentication application validates the client information contained in the pairing code against the identification information for the client application saved at the authentication server; and

in response to validating the user, send the information contained in the pairing code to the authentication server to be stored in the user authentication account, wherein the pairing code information is linked to the saved identification information for the client application;

enable a user to select the pairing and an option to change the status of the pairing via the authentication application;

in response to selection of the pairing, authenticating the selector as a registered user of the user authentication account; and

in response to authenticating the user, sending a request to the authentication server with a pairing code for the pairing and the changed lock status;

the authentication server configured to:

receive the pairing code and changed lock status; and

transmit an event to the client application identified in the pairing code identifying the changed lock status

the client application configured to:

receive the event and the change lock status saved at the client application for the pairing identified in the event; and

determine login access to the paired user account based on the saved lock status stored at the client application.

11. The computer system of claim 10 , wherein pairing to the user account, receiving the transmitted event, and saving the changed lock status is performed by an application programming interface (API) installed at the client application, the installed API communicatively coupled to the authentication server.

12. The computer system of claim 10 , wherein the client application is at least one of an online: service provider, wireless router, security system, wirelessly controlled appliance, and automatic car door.

13. The computer system of claim 10 , wherein communication between the user device and the client application and between the authentication server and the user device is over a distributed peer-to-peer decentralized network.

14. The computer system of claim 10 , wherein communication between the user device and the authentication server and between the client application and the authentication server is in a trusted execution environment.

15. The computer system of claim 10 , wherein the authenticating of the selector includes at least one of: comparing voice samples, comparing biometric information, comparing behavioral information, and contacting human authenticators.

16. The computer system of claim 10 , wherein the lock status is one of locked or unlocked.

17. The computer system of claim 10 , wherein the pairing code is a quick response (QR) code, and wherein the user scans the pairing code to provide the pairing code to the authentication application.

18. The computer system of claim 10 further configured to monitor the login activity of the user account for the client application by:

the client application configured to capture each login attempt to a login account for the client application, the capturing sending collected information related to the captured login attempts to the authentication server;

the authentication server configured to:

capture each lock attempt and unlock attempt to the login account for the client application through a paired user authentication account;

remove all personal identifiable information from information collected related to the captured login attempts, captured lock attempts, and captured unlock attempts;

generate reports indicating the health of the login account based on the collected information;

automatically changing the lock status for the user account to lock based on the collected information indicating a pattern of failed login attempts; and

generating an alert to the computing device of a user of the login account, when a cyber-attack on the login account is detected from the collected information.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 22, 2018
From: CYBERDEADBOLT INC.
To: RIVETZ CORPORATION
Reel/Frame 044691/0112 →
CHANGE OF NAME Recorded Oct 5, 2017
From: NCLUUD CORPORATION
To: CYBERDEADBOLT INC.
Reel/Frame 044133/0455 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 5, 2016
From: ROTTER, BRADLEY N.; MUDDANA, PAVAN K.
To: NCLUUD CORPORATION
Reel/Frame 040234/0128 →
Continuity (2)
Provisional Application 62136342 · Mar 20, 2015
Related Publication 20160277439A1 · Sep 22, 2016