IP Library Granted Patent US 11,038,876
Granted Patent B2
US 11,038,876 · App. 16/241,504 · Granted Jun 15, 2021

Managing access to services based on fingerprint matching

Inventors: Aaron Cockerill (Los Gatos, CA); David Richardson (San Francisco, CA); Daniel Thanos (Burlington, CA); William Neil Robinson (Sunnyvale, CA); Brian James Buck (Livermore, CA); Kevin Patrick Mahaffey (San Francisco, CA)
Assignee: Lookout, Inc.
H04L63/0853H04L63/083H04L63/0823H04L63/0876H04L63/105H04L63/12H04L63/1433H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,038,876
App. No.
16/241,504
Granted
Jun 15, 2021
Kind
B2
Abstract

A method includes: receiving a request regarding access by a first computing device (e.g., a mobile device of a user) to a service; in response to the request, performing, by a second computing device (e.g., a device risk evaluation server, or a server of an identity provider), an evaluation that includes creating a fingerprint of the first computing device; and determining, by the second computing device, whether the fingerprint matches a fingerprint of one or more other computing devices. The second computing devices determines whether to authorize access to the service based on the evaluation.

Claims (55)

1. A method, comprising:

receiving, by a first computing device, a request from a second computing device, wherein the request is for access by the second computing device to a service, and wherein access to the service requires that a software component is installed on the second computing device;

in response to the request, determining whether the software component is installed on the second computing device;

in response to determining that the software component is not installed on the second computing device, creating a fingerprint of the second computing device, the fingerprint including network behavior information, the network behavior information including data from an evaluation that runs at least one behavioral test on at least one network to which the second computing device connects to determine whether the second computing device is sending at least one vulnerable communication to at least one unknown computing device, a network communication path between the first computing device and the second computing device, and further including communications by the second computing device with other computing devices; and

determining whether the fingerprint matches a fingerprint of a different computing device that has previously communicated with the first computing device.

2. The method of claim 1 , wherein the fingerprint further includes data extracted from at least one communication received by the first computing device from the second computing device.

3. The method of claim 1 , further comprising:

performing, by the first computing device, an evaluation of a configuration of the second computing device, wherein the evaluation comprises determining whether the fingerprint matches the fingerprint of the different computing device, and further comprises determining a risk level; and

performing, by the first computing device, an action based on the evaluation, wherein the action comprises sending a first communication to a computing device, the first communication indicating the risk level.

4. The method of claim 3 , wherein access to the service further requires authorization by a computing device of an identity provider, the method further comprising:

receiving data in a communication from the computing device of the identity provider;

wherein the evaluation is based at least in part on the received data from the identity provider.

5. The method of claim 3 , wherein access to the service further requires authorization by a computing device of an identity provider, and wherein the first communication is sent to the computing device of the identity provider.

6. The method of claim 3 , wherein:

the service is provided by a third computing device; and

an extent of access to the service provided to the second computing device is based on the risk level.

7. The method of claim 3 , wherein software on the second computing device is used to access the service, and the evaluation further comprises determining a source of the software.

8. The method of claim 3 , wherein the evaluation further comprises evaluating hardware-backed authentication in which the second computing device signs, using a hardware-stored key, a nonce provided by the first computing device.

9. The method of claim 3 , further comprising:

determining a location of the second computing device;

wherein the evaluation is based at least in part on the location.

10. The method of claim 3 , further comprising:

monitoring a plurality of computing devices; and

detecting a type of event associated with a number of the plurality of computing devices;

wherein the risk level is based at least in part on the number of the plurality of computing devices.

11. The method of claim 3 , wherein the evaluation determines that the configuration is not secure, and the action further comprises blocking access of the second computing device to the service.

12. The method of claim 1 , further comprising:

generating a token for the second computing device, the token comprising data encoding the risk level; and

providing the token to the second computing device.

13. The method of claim 1 , wherein the request for access to the service is generated by an application executing on the second computing device, the method further comprising:

performing, by the first computing device, an evaluation of a configuration of the second computing device, wherein the evaluation comprises determining an authenticity of the application.

14. The method of claim 1 , further comprising:

sending a second communication to the second computing device requesting installation of the software component; and

in response to determining that the software component is installed on the second computing device, sending a communication to cause a third computing device to grant the access by the second computing device to the service.

15. A system, comprising:

at least one processor of a first computing device; and

memory storing instructions configured to instruct the at least one processor to:

receive a request from a second computing device, wherein the request is for access by the second computing device to a service, and wherein access to the service requires that a software component is installed on the second computing device;

in response to the request, determine whether the software component is installed on the second computing device;

create a fingerprint of the second computing device, the fingerprint including network behavior information, the network behavior information including data from an evaluation that runs at least one behavioral test on at least one ach network to which the second computing device connects to determine whether the second computing device is sending at least one vulnerable communication to at least one unknown computing device, a network communication path between the first computing device and the second computing device, and communications by the second computing device with other computing devices; and

in response to determining that the software component is not installed on the second computing device, determine whether the fingerprint matches a fingerprint of a different computing device that has previously communicated with the first computing device.

16. The system of claim 15 , wherein:

software on the first computing device is used to access the service;

the instructions are further configured to instruct the at least one processor to perform an evaluation of the second computing device; and

the evaluation comprises determining a source of the software.

17. The system of claim 15 , wherein access to the service further requires authorization by a computing device of an identity provider, and the instructions are further configured to instruct the at least one processor to:

receive data in a communication from the computing device of the identity provider; and

perform an evaluation of the second computing device, the evaluation including determining whether the fingerprint matches the fingerprint of the different computing device;

wherein the evaluation of the second computing device is based at least in part on the received data from the identity provider.

18. The system of claim 15 , wherein the service is provided by a third computing device, and an extent of access to the service provided to the second computing device is based on the risk level.

19. A non-transitory computer-readable storage medium storing computer-readable instructions, which when executed, cause a first computing device at least to:

receive a request from a second computing device, wherein the request is for access by the second computing device to a service provided by a third computing device;

in response to the request, create a fingerprint of the second computing device, the fingerprint including network behavior information, the network behavior information including data from an evaluation that runs at least one behavioral test on at least one network to which the second computing device connects to determine whether the second computing device is sending at least one vulnerable communication to at least one unknown computing device, a network communication path between the first computing device and the second computing device, and communications by the second computing device with other computing devices; and

determine whether the fingerprint matches a fingerprint of a different computing device that has previously communicated with the first computing device.

20. The non-transitory computer-readable storage medium of claim 19 , wherein the instructions further cause the first computing device to, in response to determining that the fingerprint matches the fingerprint of the different computing device, block access of the second computing device to the service.

Assignments (8)
SECURITY INTEREST Recorded Oct 7, 2025
From: LOOKOUT, INC.
To: MIDCAP FINANCIAL TRUST
Reel/Frame 073028/0189 →
SECURITY INTEREST Recorded Oct 2, 2025
From: LOOKOUT, INC.
To: CRESCENT COVE OPPORTUNITY LENDING, LLC, AS AGENT
Reel/Frame 072989/0675 →
SECURITY INTEREST Recorded Aug 10, 2024
From: LOOKOUT, INC.
To: MIDCAP FINANCIAL TRUST
Reel/Frame 068538/0177 →
RELEASE OF PATENT SECURITY INTEREST AT REEL 59909 AND FRAME 0764 Recorded Jun 2, 2023
From: ALTER DOMUS (US) LLC, AS ADMINISTRATIVE AGENT
To: LOOKOUT, INC.
Reel/Frame 063844/0638 →
RELEASE OF SECURITY INTEREST Recorded May 9, 2022
From: SILICON VALLEY BANK (THE "BANK")
To: LOOKOUT, INC.
Reel/Frame 059909/0668 →
SECURITY INTEREST Recorded May 9, 2022
From: LOOKOUT, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 059909/0764 →
SECURITY INTEREST Recorded Feb 18, 2020
From: LOOKOUT, INC.
To: SILICON VALLEY BANK
Reel/Frame 051966/0282 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 6, 2019
From: COCKERILL, AARON; RICHARDSON, DAVID; THANOS, DANIEL; ROBINSON, WILLIAM NEIL; BUCK, BRIAN JAMES; MAHAFFEY, KEVIN PATRICK
To: LOOKOUT, INC.
Reel/Frame 050299/0096 →