IP Library Granted Patent US 10,560,450
Granted Patent B2
US 10,560,450 · App. 15/985,382 · Granted Feb 11, 2020

Algorithm hardening in background context and external from the browser to prevent malicious intervention with the browser

Inventors: Greg Whiteside (Montreal, CA); Olivier Beaulieu (Montreal, CA); Mathieu Rene (Montreal, CA)
Assignee: McAfee, LLC
H04L63/083G06F16/957H04L9/0822H04L9/0894H04L9/32H04L63/06H04L63/1466H04L67/02H04L67/146
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,560,450
App. No.
15/985,382
Granted
Feb 11, 2020
Kind
B2
Abstract

A disclosed example to batch replace credentials for multiple websites includes accessing mappings between first encrypted credentials and corresponding ones of the websites; decrypting the first encrypted credentials using a master key to generate a plurality of first decrypted credentials; providing ones of the first decrypted credentials and corresponding ones of second decrypted credentials to corresponding ones of the websites to batch replace the first decrypted credentials with the corresponding ones of the second decrypted credentials at the corresponding ones of the websites; generating second encrypted credentials by encrypting the second decrypted credentials using the master key; and storing the second encrypted credentials in a database.

Claims (37)

1. An apparatus to batch replace credentials for multiple websites, the apparatus comprising:

a hardware processor; and

a memory including instructions that, when executed by the hardware processor, cause the hardware processor to:

access mappings between first encrypted credentials and corresponding ones of the web sites;

decrypt the first encrypted credentials using a master key to generate a plurality of first decrypted credentials;

provide ones of the first decrypted credentials and corresponding ones of second decrypted credentials to corresponding ones of the websites to batch replace the first decrypted credentials with the corresponding ones of the second decrypted credentials at the corresponding ones of the websites, the second decrypted credentials for performing user authentications at the corresponding ones of the websites to establish authenticated sessions;

generate second encrypted credentials by encrypting the second decrypted credentials using the master key; and

store the second encrypted credentials in a database.

2. The apparatus as defined in claim 1 , wherein the instructions are to cause the hardware processor to access the mappings from website identification information that includes uniform resource locators of the websites.

3. The apparatus as defined in claim 1 , wherein the instructions are to cause the hardware processor to provide the first and second decrypted credentials by providing the first and second decrypted credentials via a non-rendered application.

4. The apparatus as defined in claim 1 , wherein the instructions are further to cause the hardware processor to generate the second decrypted credentials for the websites based on credential criteria for the corresponding ones of the websites, the credential criteria indicative of acceptable credential characteristics.

5. The apparatus as defined in claim 1 , wherein the instructions are to cause the hardware processor to generate the second decrypted credentials for the websites at a user's computer.

6. The apparatus as defined in claim 1 , wherein the instructions are further to cause the hardware processor to receive the master key via user input.

7. The apparatus as defined in claim 1 , wherein the instructions are further to cause the hardware processor to access the first encrypted credentials from the database.

8. A storage device or storage disk comprising instructions that, when executed by a hardware processor, cause the hardware processor to at least:

access mappings between first encrypted credentials and corresponding ones of websites;

decrypt the first encrypted credentials using a master key to generate a plurality of first decrypted credentials;

provide ones of the first decrypted credentials and corresponding ones of second decrypted credentials to corresponding ones of the websites to batch replace the first decrypted credentials with the corresponding ones of the second decrypted credentials at the corresponding ones of the websites, the second decrypted credentials for performing user authentications at the corresponding ones of the websites to establish authenticated sessions;

generate second encrypted credentials by encrypting the second decrypted credentials using the master key; and

store the second encrypted credentials in a database.

9. The storage device or storage disk as defined in claim 8 , wherein the instructions are to cause the hardware processor to access the mappings from website identification information that includes uniform resource locators of the websites.

10. The storage device or storage disk as defined in claim 8 , wherein the instructions are to cause the hardware processor to provide the first and second decrypted credentials by providing the first and second decrypted credentials via a non-rendered application.

11. The storage device or storage disk as defined in claim 8 , wherein the instructions are further to cause the hardware processor to generate the second decrypted credentials for the websites based on credential criteria for the corresponding ones of the websites, the credential criteria indicative of acceptable credential characteristics.

12. The storage device or storage disk as defined in claim 8 , wherein the instructions are to cause the hardware processor to generate the second decrypted credentials for the web sites at a user's computer.

13. The storage device or storage disk as defined in claim 8 , wherein the instructions are further to cause the hardware processor to receive the master key via user input.

14. The storage device or storage disk as defined in claim 8 , wherein the instructions are further to cause the hardware processor to access the first encrypted credentials from the database.

15. A method of batch replacing credentials for multiple websites, the method comprising:

accessing, by executing an instruction with a processor, mappings between first encrypted credentials and corresponding ones of the websites;

decrypting, by executing an instruction with the processor, the first encrypted credentials using a master key to generate a plurality of first decrypted credentials;

providing, by executing an instruction with the processor, ones of the first decrypted credentials and corresponding ones of second decrypted credentials to corresponding ones of the websites to batch replace the first decrypted credentials with the corresponding ones of the second decrypted credentials at the corresponding ones of the web sites, the second decrypted credentials for performing user authentications at the corresponding ones of the websites to establish authenticated sessions;

generating, by executing an instruction with the processor, second encrypted credentials by encrypting the second decrypted credentials using the master key; and

storing, by executing an instruction with the processor, the second encrypted credentials in a database.

16. The method as defined in claim 15 , wherein the accessing of the mappings includes accessing the mappings from website identification information that includes uniform resource locators of the web sites.

17. The method as defined in claim 15 , wherein the providing of the first and second decrypted credentials includes providing the first and second decrypted credentials via a non-rendered application.

18. The method as defined in claim 15 , further including generating the second decrypted credentials for the websites based on credential criteria for the corresponding ones of the websites, the credential criteria indicative of acceptable credential characteristics.

19. The method as defined in claim 15 , further including generating the second decrypted credentials for the web sites at a user's computer.

20. The method as defined in claim 15 , further including receiving the master key via user input.

Assignments (4)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
CHANGE OF NAME Recorded Dec 17, 2019
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 051322/0919 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 6, 2018
From: WHITESIDE, GREG; BEAULIEU, OLIVIER; RENE, MATHIEU
To: MCAFEE, INC.
Reel/Frame 045997/0105 →
Continuity (2)
Continuation 14865140 · Sep 25, 2015
Related Publication 20180270218A1 · Sep 20, 2018