IP Library Granted Patent US 10,356,125
Granted Patent B2
US 10,356,125 · App. 15/607,329 · Granted Jul 16, 2019

Devices, systems and computer-implemented methods for preventing password leakage in phishing attacks

Inventors: Sebastien Goutal (San Francisco, CA); Antoine Honore (Templemars, FR)
Assignee: VADE SECURE, INC.
H04L63/1483G06F21/6245G06F21/6263H04L9/3236H04L63/06H04L63/101G06F2221/2119
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,356,125
App. No.
15/607,329
Granted
Jul 16, 2019
Kind
B2
Abstract

A computer-implemented method of preventing leakage of user credentials to phishing websites may comprise capturing user credentials input to website; updating a stored list of trusted website credentials upon determining that the domain of the URL of the website is present in a stored list of trusted websites; generating a hash of the captured user credentials; determining whether the hashed user credentials matches one of the hashed user credentials in the list of trusted website credentials; and when a match is found, requesting input whether the website is trusted or whether the website is unknown and/or untrusted; sending the URL to a remote computer server when the input indicates that the website is unknown and/or untrusted and disallowing submission of the user credentials to the website; adding the domain of the URL to the stored list of trusted websites, adding the generated hash of the captured user credentials to a stored list of trusted website credentials and allowing submission of the user credentials to the website.

Claims (44)

1. A computer-implemented method of preventing leakage of user credentials to phishing websites, comprising:

capturing user credentials input to a webpage of a website;

generating a hash of the captured user credentials;

updating a stored list of trusted website credentials with the generated hashed user credentials upon determining that the domain of a Uniform Resource Locator (URL) of the website to which the user credentials were input is present in a stored list of trusted websites;

in response to determining that the domain of the URL of the website to which the user credentials were input is not present in the stored list of trusted websites, determining whether the generated hashed user credentials matches one of a plurality of hashed user credentials in the list of trusted website credentials; and subsequently

when the generated hashed user credentials matches a hashed user credential in the list of trusted website credentials, requesting input indicative of whether the URL of the website is trusted or whether the URL of the website is unknown and/or untrusted;

when the requested input indicates that URL of the website is unknown and/or untrusted, sending the URL of the website to a remote computer server over a computer network and disallowing submission of the user credentials to the website; and

in response to the requested input indicating that the URL of website is trusted, adding the domain of the URL of the website to the stored list of trusted websites, adding the generated hash of the captured user credentials to the stored list of trusted website credentials and allowing the user credentials to be submitted to the website.

2. The computer-implemented method of claim 1 , wherein generating the hash comprises applying a key-stretching algorithm to the captured user credentials.

3. The computer-implemented method of claim 2 , wherein applying the key-stretching algorithm to the captured user credentials further comprises inputting a cryptographic salt when generating the hash.

4. The computing device of claim 2 , wherein applying the key-stretching algorithm to the captured user credentials further comprises inputting a cryptographic salt when generating the hash.

5. The computer-implemented method of claim 1 wherein, for each website, the stored list of trusted website credentials is configured as a First-In, First-Out (FIFO) queue.

6. The computer-implemented method of claim 1 , wherein the stored list of trusted website credentials further comprises the domain of the website to which the captured credentials were input and a time stamp.

7. The computer-implemented method of claim 1 , wherein capturing the user credentials further comprises:

waiting for a Document Object Model (DOM) tree of the webpage of the website to reach an idle state;

waiting for a DOM event and a DOM mutation;

identifying all forms having fields associated with user credentials;

adding at least one of an input event listener to at least one of the identified fields and a click event listener to at least one button and link belonging to the identified forms; and

capturing user credentials input to one of the forms using at least one of the input event listener and the click event listener.

8. The computer-implemented method of claim 1 , further comprising receiving updates to the list of trusted websites from the remote computer server.

9. The computer-implemented method of claim 1 , wherein the user credentials are input to a browser displaying the webpage of the website and wherein preventing leakage of user credentials by phishing websites is performed by a plug-in to the browser.

10. The computing device of claim 1 wherein, for each website, the stored list of trusted website credentials is configured as a First-In, First-Out (FIFO) register.

11. The computing device of claim 1 , wherein the stored list of trusted website credentials further comprises the domain of the URL of the website to which the captured credentials were input and a time stamp.

12. The computing device of claim 1 , wherein the plurality of processes spawned by the at least one processor for capturing the user credentials further includes processing logic for:

waiting for a Document Object Model (DOM) tree of the webpage of the website to reach an idle state;

waiting for a DOM event and a DOM mutation;

identifying all forms having fields associated with user credentials;

adding at least one of an input event listener to at least one of the identified fields and a click event listener to at least one button and link belonging to the identified forms; and

capturing user credentials input to one of the forms using at least one of the input event listener and the click event listener.

13. The computing device of claim 1 , further comprising processing logic for receiving updates to the list of trusted websites from the remote computer server.

14. The computing device of claim 1 , wherein the plurality of processes spawned by the at least one processor are configured as a plug-in to the browser.

15. A computing device configured for preventing leakage of user credentials to phishing websites comprising:

at least one hardware processor;

at least one data storage device coupled to the at least one hardware processor;

a network interface coupled to the at least one hardware processor and to a computer network;

a plurality of processes spawned by said at least one hardware processor, the processes including processing logic for:

capturing user credentials input to a webpage of a website;

generating a hash of the captured user credentials;

updating a stored list of trusted website credentials with the generated hashed user credentials upon determining that the domain of a Uniform Resource Locator (URL) of the website to which the user credentials were input is present in a stored list of trusted websites;

in response to determining that the domain of the URL of the website to which the user credentials were input is not present in the stored list of trusted websites, determining whether the generated hashed user credentials matches one of a plurality of hashed user credentials in the list of trusted website credentials; and subsequently

when the generated hashed user credentials matches a hashed user credential in the list of trusted website credentials, requesting input indicative of whether the URL of the website is trusted or whether the URL of the website is unknown and/or untrusted;

when the requested input indicates that the URL of the website is unknown and/or untrusted, sending the URL of the website to a remote computer server over a computer network and disallowing submission of the user credentials to the website

in response to the requested input indicating is that the URL of website is trusted, adding the domain of the URL of the website to the stored list of trusted websites, adding the generated hash of the captured user credentials to the stored list of trusted website credentials and allowing the user credentials to be submitted to the website.

16. The computing device of claim 15 , wherein generating the hash comprises applying a key-stretching algorithm to the captured user credentials.

Assignments (7)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT REEL 059510, FRAME 0419 Recorded Feb 22, 2024
From: TIKEHAU ACE CAPITAL
To: VADE USA INCORPORATED
Reel/Frame 066647/0152 →
SECURITY INTEREST Recorded Apr 15, 2022
From: VADE USA INCORPORATED
To: TIKEHAU ACE CAPITAL
Reel/Frame 059610/0419 →
CHANGE OF NAME Recorded Mar 3, 2022
From: VADE SECURE, INCORPORATED
To: VADE USA, INCORPORATED
Reel/Frame 059164/0846 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY DATA PREVIOUSLY RECORDED AT REEL: 050278 FRAME: 0726. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 6, 2019
From: GOUTAL, SEBASTIEN; HONORE, ANTOINE
To: VADE SECURE, INC.
Reel/Frame 050300/0349 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY DATA PREVIOUSLY RECORDED AT REEL: 042750 FRAME: 0020. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded May 21, 2019
From: GOUTAL, SEBASTIEN; HONORE, ANTOINE
To: VADE DECURE, INC.
Reel/Frame 050278/0726 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY DATA PREVIOUSLY RECORDED ON REEL 042750 FRAME 0020. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded May 21, 2019
From: GOUTAL, SEBASTIEN; HONORE, ANTOINE
To: VADE SECURE, INC.
Reel/Frame 051440/0842 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 19, 2017
From: GOUTAL, SEBASTIEN; HONORE, ANTOINE
To: VADE SECURE TECHNOLOGY, INC.
Reel/Frame 042750/0020 →
Continuity (1)
Related Publication 20180343283A1 · Nov 29, 2018
Cited By (4)
US 12,556,566 US 12,591,641 US 12,609,969 US 12,719,885