IP Library Granted Patent US 11,586,711
Granted Patent B2
US 11,586,711 · App. 16/411,720 · Granted Feb 21, 2023

Systems and methods for securing and controlling access to electronic data, electronic systems, and digital accounts

Inventor: Rich Smith (Ann Arbor, MI)
Assignee: CISCO TECHNOLOGY, INC.
G06F21/125H04L63/0263H04L63/0442H04L63/0876H04L63/1491
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,586,711
App. No.
16/411,720
Granted
Feb 21, 2023
Kind
B2
Abstract

A system and method of securing a computing device with a remote computer security service includes: identifying a computing device that is subscribed to a remote computer security service, wherein the computing device comprises an anti-authentication application instance provided by the remote computer security service based on the subscription; identifying an occurrence of an anti-authentication action involving the computing device based on anti-authentication policy set to a subscriber anti-authentication account with the remote computer security service for the computing device; responsively to the anti-authentication action, automatically performing by the remote security service or the anti-authentication application instance one or more anti-authentication protective services by protectively altering the computing device based on the anti-authentication policy, wherein the computing device is altered to a protected state from a normal state based on the performance of the one or more anti-authentication protective services.

Claims (64)

1. A method of securing a computing device with a remote computer security service, the method comprising:

identifying a computing device that is subscribed to a remote computer security service, wherein the computing device comprises an anti-authentication application instance provided by the remote computer security service based on a subscription;

identifying an occurrence of an anti-authentication action involving the computing device based on an anti-authentication policy set to a subscriber anti-authentication account with the remote computer security service for the computing device;

responsively to the anti-authentication action, automatically performing by the remote computer security service or the anti-authentication application instance one or more anti-authentication protective services by protectively altering the computing device based on the anti-authentication policy, wherein the computing device is altered to a protected state from a normal state based on the performance of the one or more anti-authentication protective services;

responsive to the anti-authentication action, providing an anti-authentication token to a third party authentication service, different from the remote computer security service, that alerts the third party authentication service to take security measures regarding data, systems or user accounts associated with a user associated with the subscriber anti-authentication account; and

after performing the one or more anti-authentication protective services, performing, on the computing device, a cleaning operation that deletes data traces indicating that an anti-authentication credential was input to the computing device and that the one or more anti-authentication services have been performed.

2. The method according to claim 1 , wherein

the anti-authentication action relates to a sequence of actions involving an interaction by a user with the computing device that, when performed, causes the remote computer security service or the anti-authentication application instance to protectively alter a state of data of the computing device.

3. The method according to claim 1 , wherein

if no network connectivity can be established between the computing device and the remote computer security service, the anti-authentication application operates independently of the remote computer security service to alter the computing device to the protected state.

4. The method according to claim 1 , wherein

in the protected state, the anti-authentication application instance cloaks a subset of designated protected data maintained on the computing device based on anti-authentication policy associated with a subscriber anti-authentication account with the anti-authentication service.

5. The method according to claim 4 , wherein:

cloaking the subset of designated protected data includes encrypting by the remote computer security service or the anti-authentication application instance the subset of designated protected data with a public cryptographic key of an asymmetric key pair of the remote computer security service; and

only a private cryptographic key of the asymmetric key pair of the remote computer security service can decrypt the subset of designated protected data and revert the computing device to the normal state.

6. The method according to claim 1 , wherein

in the protected state, the anti-authentication application instance or the remote computer security service deletes designated protected data from one or more memory devices of the computing device based on anti-authentication policy associated with the subscriber anti-authentication account with the remote computer security service.

7. The method according to claim 1 , the method further comprising:

registering the computing device to the anti-authentication account with the remote computer security service;

designating protected data associated with the subscriber device; and

enabling access to the protected data to one or more of the remote computer security service and the anti-authentication application instance.

8. The method according to claim 1 , wherein

registering a first anti-authentication action with the subscriber anti-authentication account; and

registering an authentication action with the subscriber anti-authentication account that reverts the subscriber device from the protected state to the normal state, wherein the registered authentication action is distinct from a standard authentication action implemented for accessing the computing device in the normal state.

9. The method according to claim 1 , wherein

the anti-authentication action includes an input of anti-authentication credentials at the computing device,

the anti-authentication credentials including a set of credentials that is registered with the remote computer security service that, when received at the computing device, causes the anti-authentication application instance to covertly alter a state of the computing device to protect one or more features or data of the computing device while contemporaneously providing access to the computing device.

10. The method according to claim 9 , wherein

the anti-authentication credentials relate to credentials for an illegitimate access to or an illegitimate control of the computing device that differ from authentication credentials for a legitimate access to or a legitimate control of the computing device.

11. The method according to claim 9 , wherein

a plurality of distinct anti-authentication credentials are registered to the subscriber's anti-authentication account with the anti-authentication service;

each of the plurality of distinct anti-authentication credentials, when received at the computing device, causes an execution of a distinct anti-authentication protection of the computing device.

12. The method according to claim 1 , further comprising:

at a registration of the subscriber anti-authentication account with the remote computer security service:

identifying a blacklist of computer device items comprising a selection of one or more configuration states, one or more functions, one or more types of data, one or more corpus of data, one or more features, or one or more applications of the computing device; and

in response to receiving anti-authentication credentials at the computing device, automatically and protectively altering the blacklist of computer device items.

13. The method according to claim 1 , further comprising:

at a registration of the subscriber anti-authentication account with the remote computer security service:

identifying a whitelist of computer device items comprising a selection of one or more configuration states, one or more functions, one or more types of data, one or more corpus of data, one or more features, or one or more applications of the computing device; and

in response to receiving anti-authentication credentials at the computing device, automatically and protectively altering the computer device with an exception to the whitelist of computer device items.

14. A method of securing an online subscriber account with a remote security service, the method comprising:

identifying an online subscriber account that is subscribed to a remote security service, wherein the online subscriber account comprises an anti-authentication application instance provided by the remote security service based on a subscription;

identifying an occurrence of an anti-authentication action involving the online subscriber account based on anti-authentication policy set to a subscriber anti-authentication account with the remote security service for the online subscriber account;

responsively to the anti-authentication action, automatically performing by the anti-authentication application instance one or more anti-authentication protective services by protectively altering the online subscriber account based on the anti-authentication policy, wherein the online subscriber account is altered to a protected state from a normal state based on the performance of the one or more anti-authentication protective services;

responsive to the anti-authentication action, providing an anti-authentication token to a third party authentication service, different from the remote security service, that alerts the third party authentication service to take security measures regarding data, systems or user accounts associated with a user associated with the online subscriber account; and

after performing the one or more anti-authentication protective services, performing, on the online subscriber account, a cleaning operation that deletes data traces indicating that an anti-authentication credential was input to the computing device and that the one or more anti-authentication services have been performed.

15. The method according to claim 14 , wherein

the anti-authentication action relates to a sequence of actions involving an interaction by a user with the online subscriber account that, when performed, causes the remote computer security service or the anti-authentication application instance to protectively alter a state of data of the online subscriber account.

16. The method according to claim 14 , wherein

the anti-authentication action includes an input of anti-authentication credentials at the online subscriber account,

the anti-authentication credentials including a set of credentials that is registered with the remote computer security service that, when received via an interface associated with the online subscriber account, causes the anti-authentication application instance to covertly alter a state of the online subscriber account to protect one or more features or data of the online subscriber account while contemporaneously providing access to the online subscriber account.

17. The method according to claim 14 , wherein

in the protected state, the anti-authentication application instance or the remote security service deletes designated protected data from one or more memory devices associated with the subscriber online account based on anti-authentication policy associated with the subscriber anti-authentication account with the remote security service.

18. A computer program product for securing a computing resource with a remote computer security service, the computer program product comprising:

a non-transitory computer-readable medium storing computer-executable instructions that, when executed by one or more computer processors, causes the one or more computer processors to perform:

identifying a computing device that is subscribed to a remote computer security service, wherein the computing device comprises an anti-authentication application instance provided by the remote computer security service based on a subscription;

identifying an occurrence of an anti-authentication action involving the computing device based on anti-authentication policy set to a subscriber anti-authentication account with the remote computer security service for the computing device;

responsively to the anti-authentication action, automatically performing one or more anti-authentication protective services by protectively altering the computing device based on the anti-authentication policy, wherein the computing device is altered to a protected state from a normal state based on the performance of the one or more anti-authentication protective services;

responsive to the anti-authentication action, providing an anti-authentication token to a third party authentication service, different from the remote computer security service, that alerts the third party authentication service to take security measures regarding data, systems or user accounts associated with a user associated with the subscriber anti-authentication account; and

after performing the one or more anti-authentication protective services, performing, on the computing device, a cleaning operation that deletes data traces indicating that an anti-authentication credential was input to the computing device and that the one or more anti-authentication services have been performed.

19. The computer program product according to claim 18 , wherein

the anti-authentication action relates to a sequence of actions involving an interaction by a user with the computing device that, when performed, causes the remote computer security service or the anti-authentication application instance to protectively alter a state of data of the computing device.

20. The computer program product according to claim 18 , wherein

the anti-authentication action relates to a sequence of actions involving an interaction by a user with an online subscriber account that, when performed, causes the remote computer security service or the anti-authentication application instance to protectively alter a state of data of the online subscriber account.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 11, 2021
From: DUO SECURITY LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 056208/0504 →
CHANGE OF NAME Recorded May 11, 2021
From: DUO SECURITY, INC.
To: DUO SECURITY LLC
Reel/Frame 056210/0008 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 28, 2019
From: SMITH, RICH
To: DUO SECURITY, INC.
Reel/Frame 049290/0677 →
Continuity (2)
Provisional Application 62671262 · May 14, 2018
Related Publication 20190347384A1 · Nov 14, 2019