IP Library › Granted Patent US 11,489,829
Granted Patent B1
US 11,489,829 · App. 16/721,853 · Granted Nov 1, 2022

Automatic account protection for compromised credentials

Inventors: Erica Ulrich (San Francisco, CA); Lizmari Brignoni (Gilbert, AZ); Jason Britt (Birmingham, AL); Tobe B. Bassior (Walnut Creek, CA); Mark David Castonguay (Corte Madera, CA)
Assignee: Wells Fargo Bank, N.A.
H04L63/083G06F9/542H04L9/0643H04L63/0815H04L63/0861
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,489,829
App. No.
16/721,853
Granted
Nov 1, 2022
Kind
B1
Abstract

A method may include receiving a data file including a plurality of tuples, each respective tuple including a username and password; matching a username from a tuple in the data file to a username of an account stored in an account database; determining that the password from the tuple matches a password for the account; in response to the determining indicating a match, setting a security flag for the account identifying the account as compromised; subsequent to the security flag being set, receiving a login request with validated credentials for the account from a computing device; and in response to the login request, transmitting a request to the computing device to modify the password for the account.

Claims (53)

1. A method comprising:

receiving a credential data file including a plurality of tuples, each respective tuple including a username and password, the plurality of tuples previously indicated as compromised;

filtering the credential data file to exclude tuples with usernames that do not match a username in an account database;

matching a username in multiple tuples of the plurality of tuples in the credential data file to a username of an account stored in the account database;

determining that the password from a tuple in the multiple tuples of the plurality of tuples matches a password for the account by:

serially initiating attempts to log in to the account with each respective password in the multiple tuples of the plurality of tuples; and

preventing the account from being locked out during the attempts;

in response to the determining indicating a match, setting a security flag for the account identifying the account as compromised;

subsequent to the security flag being set, receiving a login request with validated credentials for the account from a computing device; and

in response to the login request, transmitting a request to the computing device to modify the password for the account.

2. The method of claim 1 , wherein the respective password of each tuple is hashed.

3. The method of claim 2 , wherein determining that the password from the tuple matches a password for the account includes:

attempting to log in to the account using the password from the tuple by submitting the hashed password via a login API.

4. The method of claim 1 , further comprising:

disabling a subset of a set of login methods in response to the security flag being set.

5. The method of claim 4 , wherein the subset of login methods includes biometric login methods.

6. The method of claim 4 , wherein disabling the subset of login methods in response to the security flag being set comprises:

disabling login requests from applications using the username as an alternative login method.

7. The method of claim 1 , further comprising, in response to the determining indicating the match:

transmitting a request to a user associated with username to modify the password; and

requesting additional identification verification requests before the password may be modified.

8. The method of claim 1 , wherein the credential data file is identified in a control file, the control file identifying a plurality of sets of compromised credentials.

9. The method of claim 8 , further comprising standardizing each set of compromised credentials into a common format.

10. A non-transitory computer readable medium comprising instructions, which when executed by at least one processor, configure the at least one processor to perform operations comprising:

receiving a credential data file including a plurality of tuples, each respective tuple including a username and password, the plurality of tuples previously indicated as compromised;

filtering the credential data file to exclude tuples with usernames that do not match a username in an account database;

matching a username in multiple tuples of the plurality of tuples in the credential data file to a username of an account stored in the account database;

determining that the password from a tuple in the multiple tuples of the plurality of tuples matches a password for the account by:

serially initiating attempts to log in to the account with each respective password in the multiple tuples of the plurality of tuples; and

preventing the account from being locked out during the attempts;

in response to the determining indicating a match, setting a security flag for the account identifying the account as compromised;

subsequent to the security flag being set, receiving a login request with validated credentials for the account from a computing device; and

in response to the login request, transmitting a request to the computing device to modify the password for the account.

11. The computer readable medium of claim 10 , wherein the respective password of each tuple is hashed.

12. The computer readable medium of claim 11 , wherein determining that the password from the tuple matches a password for the account includes:

attempting to log in to the account using the password from the tuple by submitting the hashed password via a login API.

13. The computer readable medium of claim 10 , wherein the instructions, which when executed by the at least one processor, further configure the at least one processor to perform:

disabling a subset of a set of login methods in response to the security flag being set.

14. A system comprising:

at least one processor;

a storage device comprising instructions, which when executed by at least one processor, configure the at least one processor to perform operations comprising:

receiving a credential data file including a plurality of tuples, each respective tuple including a username and password, the plurality of tuples previously indicated as compromised;

filtering the credential data file to exclude tuples with usernames that do not match a username in an account database;

matching a username from in multiple tuples of the plurality of tuples in the credential data file to a username of an account stored in the account database;

determining that the password from a tuple in the multiple tuples of the plurality of tuples matches a password for the account by:

serially initiating attempts to log in to the account with each respective password in the multiple tuples of the plurality of tuples; and

preventing the account from being locked out during the attempts;

in response to the determining indicating a match, setting a security flag for the account identifying the account as compromised;

subsequent to the security flag being set, receiving a login request with validated credentials for the account from a computing device; and

in response to the login request, transmitting a request to the computing device to modify the password for the account.

15. The system of claim 14 , wherein the respective password of each tuple is hashed.

16. The system of claim 15 , wherein determining that the password from the tuple matches a password for the account includes:

attempting to log in to the account using the password from the tuple by submitting the hashed password via a login API.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 14, 2020
From: ULRICH, ERICA; BRIGNONI, LIZMARI; BRITT, JASON; BASSIOR, TOBE B; CASTONGUAY, MARK DAVID
To: WELLS FARGO BANK, N.A.
Reel/Frame 052385/0805 →
Continuity (1)
Provisional Application 62784246 · Dec 21, 2018
Cited By (2)
US 12,204,661 US 12,500,895