IP Library Granted Patent US 11,068,583
Granted Patent B2
US 11,068,583 · App. 16/839,220 · Granted Jul 20, 2021

Management of login information affected by a data breach

Inventors: Joshua Edwards (McLean, VA); Michael Mossoba (McLean, VA); Ljubica Chatman (McLean, VA); Jason Ji (McLean, VA); Carlos Rodriguez (McLean, VA)
Assignee: Capital One Services, LLC
G06F21/45G06F21/6218
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,068,583
App. No.
16/839,220
Granted
Jul 20, 2021
Kind
B2
Abstract

A device determines that a data breach of an application has been reported and determines that an individual has an account with the application based on identifying an association between an application identifier and a username the individual uses to access the application. The device receives, from a user device associated with the individual, password information used to access the application. The device uses the password information and usernames for a group of applications with which the individual has accounts to perform a login procedure for the group of applications to determine that login information for one or more of the applications includes the password information used to access the application affected by the data breach. The device provides, to the user device or another device, a recommendation to change the password information used to access the application and the one or more applications.

Claims (68)

1. A method, comprising:

obtaining, by a device, electronic mail (e-mail) content associated with an e-mail account of an individual by using a secure access delegation service to search the e-mail account,

wherein the e-mail content includes a plurality of e-mail messages;

using, by the device, a semantic engine parser to analyze the e-mail content to identify, based on one or more keywords, a group of applications with which the individual has accounts,

wherein the group of applications includes a plurality of different applications;

determining, by the device, that a data breach of an application has been reported;

determining, by the device, that one or more applications, different from the application and included in the group of applications, share at least a portion of login information used to access the application; and

providing, by the device and to a user device or a user account, data associated with changing at least the portion of the login information that the one or more applications share with the application affected by the data breach.

2. The method of claim 1 , wherein using the semantic engine parser to analyze the e-mail content comprises:

accessing a template that includes characters, terms, or phrases that identify one of the one or more applications; and

using the template to identify the group of applications with which the individual has accounts.

3. The method of claim 2 , wherein using the template to identify the group of applications comprises:

determining that the individual has an account with the one of the one or more applications based on the e-mail content including at least one keyword, of the one or more keywords, that satisfies a threshold level of similarity with template keywords included in the template.

4. The method of claim 1 , wherein using the semantic engine parser to analyze the e-mail content comprises:

providing data associated with the semantic engine parser as input to a machine learning model; and

receiving, as output from the machine learning model, data indicating at least one application, of the group of applications with which the individual has accounts.

5. The method of claim 4 , wherein the machine learning model has been trained based on historical transaction data indicating which merchants a user has interacted with over time.

6. The method of claim 1 , further comprising:

verifying that the individual has an account with a particular application of the one or more applications by using data associated with the data breach to attempt a password reset for the particular application.

7. The method of claim 1 , further comprising:

interacting with a login page of a particular application of the one or more applications;

identifying, in an interface associated with the particular application, a password reset option associated with the particular application; and

initiating a password reset for the particular application by interacting with the password reset option.

8. A device, comprising:

one or more memories; and

one or more processors communicatively coupled to the one or more memories, configured to:

obtain electronic mail (e-mail) content associated with an e-mail account of an individual by using a secure access delegation service to search the e-mail account,

wherein the e-mail content includes a plurality of e-mail messages;

use a semantic engine parser to analyze the e-mail content to identify, based on one or more keywords, a group of applications with which the individual has accounts,

wherein the group of applications includes a plurality of different applications;

determine that a data breach of an application has been reported;

determine that one or more applications, different from the application and included in the group of applications, share at least a portion of login information used to access the application; and

provide, to a user device or a user account, data associated with changing at least the portion of the login information that the one or more applications share with the application affected by the data breach.

9. The device of claim 8 , wherein the one or more processors, when using the semantic engine parser to analyze the e-mail content, are configured to:

access a template that includes characters, terms, or phrases that identify one of the one or more applications; and

use the template to identify the group of applications with which the individual has accounts.

10. The device of claim 9 , wherein the one or more processors, when using the template to identify the group of applications, are configured to:

determine that the individual has an account with the one of the one or more applications based on the e-mail content including at least one keyword, of the one or more keywords, that satisfies a threshold level of similarity with template keywords included in the template.

11. The device of claim 8 , wherein the one or more processors, when using the semantic engine parser to analyze the e-mail content, are configured to:

provide data associated with the semantic engine parser as input to a machine learning model; and

receive, as output from the machine learning model, data indicating at least one application, of the group of applications with which the individual has accounts.

12. The device of claim 11 , wherein the machine learning model has been trained based on historical transaction data indicating which merchants a user has interacted with over time.

13. The device of claim 8 , wherein the one or more processors are further configured to:

verify that the individual has an account with a particular application of the one or more applications by using data associated with the data breach to attempt a password reset for the particular application.

14. The device of claim 8 , wherein the one or more processors are further configured to:

interact with a login page of a particular application of the one or more applications;

identify, in an interface associated with the particular application, a password reset option associated with the particular application; and

initiate a password reset for the particular application by interacting with the password reset option.

15. A non-transitory computer-readable medium storing instructions, the instructions comprising:

one or more instructions that, when executed by one or more processors, cause the one or more processors to:

obtain electronic mail (e-mail) content associated with an e-mail account of an individual by using a secure access delegation service to search the e-mail account,

wherein the e-mail content includes a plurality of e-mail messages;

use a semantic engine parser to analyze the e-mail content to identify, based on one or more keywords, a group of applications with which the individual has accounts,

wherein the group of applications includes a plurality of different applications;

determine that a data breach of an application has been reported;

determine that one or more applications, different from the application and included in the group of applications, share at least a portion of login information used to access the application; and

provide, to a user device or a user account, data associated with changing at least the portion of the login information that the one or more applications share with the application affected by the data breach.

16. The non-transitory computer-readable medium of claim 15 , wherein the one or more instructions, that cause the one or more processors to use the semantic engine parser to analyze the e-mail content, cause the one or more processors to:

access a template that includes characters, terms, or phrases that identify one of the one or more applications; and

use the template to identify the group of applications with which the individual has accounts.

17. The non-transitory computer-readable medium of claim 16 , wherein the one or more instructions, that cause the one or more processors to use the template to identify the group of applications, cause the one or more processors to:

determine that the individual has an account with the one of the one or more applications based on the e-mail content including at least one keyword, of the one or more keywords, that satisfies a threshold level of similarity with template keywords included in the template.

18. The non-transitory computer-readable medium of claim 15 , wherein the one or more instructions, that cause the one or more processors to use the semantic engine parser to analyze the e-mail content, cause the one or more processors to:

provide data associated with the semantic engine parser as input to a machine learning model; and

receive, as output from the machine learning model, data indicating at least one application, of the group of applications with which the individual has accounts.

19. The non-transitory computer-readable medium of claim 18 , wherein the machine learning model has been trained based on historical transaction data indicating which merchants a user has interacted with over time.

20. The non-transitory computer-readable medium of claim 15 , wherein the one or more instructions, when executed by the one or more processors, further cause the one or more processors to:

verify that the individual has an account with a particular application of the one or more applications by using data associated with the data breach to attempt a password reset for the particular application.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE LISTING OF INVENTORS TO ADD CARLOS RODRIGUEZ PREVIOUSLY RECORDED ON REEL 052306 FRAME 0179. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 19, 2021
From: EDWARDS, JOSHUA; MOSSOBA, MICHAEL; CHATMAN, LJUBICA; JI, JASON; RODRIGUEZ, CARLOS
To: CAPITAL ONE SERVICES, LLC
Reel/Frame 055966/0785 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 3, 2020
From: EDWARDS, JOSHUA; MOSSOBA, MICHAEL; CHATMAN, LJUBICA; JI, JASON
To: CAPITAL ONE SERVICES, LLC
Reel/Frame 052306/0179 →
Continuity (2)
Continuation 16281547 · Feb 21, 2019
Related Publication 20200272728A1 · Aug 27, 2020
Cited By (1)
US 12,204,661