IP Library Granted Patent US 12,058,121
Granted Patent B2
US 12,058,121 · App. 17/303,209 · Granted Aug 6, 2024

Secure system and method for preventing cross-site credential reuse

Inventor: Vivek Chinar Nair (San Jose, CA)
H04L63/083H04L9/3236
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,058,121
App. No.
17/303,209
Granted
Aug 6, 2024
Kind
B2
Abstract

A system for preventing cross-site credential reuse includes: a plurality of secure services hosted on at least one server, each of the plurality of secure services having its own set of credentials; a central database for storing data relating to credentials associated with the plurality of secure services; whereby at least one of the plurality of secure services communicates with the central database to determine whether a credential is used across more than one of the plurality of secure services.

Claims (41)

1. A centralized system for preventing cross-site credential reuse comprising:

a plurality of secure services hosted on a plurality of servers, each of the plurality of secure services having a set of credentials;

a central database, hosted on at least one of the plurality of servers, for storing data relating to credentials associated with the plurality of secure services;

whereby at least one of the plurality of secure services communicates with the central database such that the at least one of the plurality of secure services determines whether a credential is used across more than one of the plurality of secure services,

whereby the at least one of the plurality of secure services and the central database jointly execute a secure multi-party computation cryptographic protocol such that the central database cannot ascertain the identities of users of the at least one of the plurality of secure services,

wherein a private set intersection of credentials is computed such that the at least one of the plurality of secure services determines whether a credential is used across more than one of the plurality of secure services,

wherein at least one of the plurality of secure services stores cryptographic hashes of credentials,

wherein credentials that are similar but not identical are identified, and

wherein similarity of other credentials in the central database is used to calculate credential strength.

2. The centralized system for preventing cross-site credential reuse of claim 1 , wherein the central database stores both current and previous credentials.

3. The centralized system for preventing cross-site credential reuse of claim 1 , wherein bulk requests are used to perform more than one operation in a single query.

4. The centralized system for preventing cross-site credential reuse of claim 1 , wherein at least one of the plurality of secure services communicates with the central database to determine whether a credential is reused by a particular user across more than one of the plurality of secure services.

5. The centralized system for preventing cross-site credential reuse of claim 1 , wherein at least one of the plurality of secure services communicates with the central database to determine whether a credential is reused across different users across more than one of the plurality of secure services.

6. The centralized system for preventing cross-site credential reuse of claim 1 , wherein credential strength is computed as a metric of factors.

7. The centralized system for preventing cross-site credential reuse of claim 1 , wherein the central database stores credentials that are known to be compromised.

8. A decentralized system for preventing cross-site credential reuse comprising:

a plurality of secure services hosted on a plurality of servers, each of the plurality of secure services having its own set of credentials, the plurality of secure services together forming a decentralized system, wherein each of a plurality of entities in the decentralized system executes a substantively identical decentralized protocol such that no entity assumes a role of special privilege, authority, or trust in the decentralized system and no entity serves a unique or centralized function in the decentralized system;

whereby at least one of the plurality of secure services communicates directly with at least one other of the plurality of secure services such that the at least one of the plurality of secure services determines whether a credential is used across more than one of the plurality of secure services,

whereby the at least one of the plurality of secure services and the at least one other of the plurality of secure services jointly execute a secure multi-party computation cryptographic protocol such that the at least one other of the plurality of secure services cannot ascertain the identities of users of the at least one of the plurality of secure services,

whereby a private set intersection of credentials is computed such that the at least one of the plurality of secure services determines whether a credential is used across more than one of the plurality of secure services,

whereby at least one of the plurality of secure services stores cryptographic hashes of credentials,

wherein credentials that are similar but not identical are identified, and

wherein similarity of other credentials in the central database is used to calculate credential strength.

9. The decentralized system for preventing cross-site credential reuse of claim 8 , wherein at least one of the plurality of secure services stores previous credentials in addition to current credentials.

10. The decentralized system for preventing cross-site credential reuse of claim 8 , wherein bulk requests are used to perform more than one operation in a single query.

11. The decentralized system for preventing cross-site credential reuse of claim 8 , wherein at least one of the plurality of secure services communicates with at least one other of the plurality of secure services to determine whether a credential is reused by a particular user across more than one of the plurality of secure services.

12. The decentralized system for preventing cross-site credential reuse of claim 8 , wherein at least one of the plurality of secure services communicates with at least one other of the plurality of secure services to determine whether a credential is reused across different users across more than one of the plurality of secure services.

13. A federated system for preventing cross-site credential reuse comprising:

a plurality of secure services hosted on a first plurality of servers, each of the plurality of secure services having its own set of credentials;

a plurality of service providers hosted on a second plurality of servers at least one server, the plurality of service providers together forming a decentralized system, wherein each of a plurality of entities in the decentralized system executes a substantively identical decentralized protocol such that no entity assumes a role of special privilege, authority, or trust in the decentralized system and no entity serves a unique or centralized function in the decentralized system;

whereby at least one of the plurality of secure services communicates with at least one of the plurality of service providers such that the at least one of the plurality of secure services determines whether a credential is used across more than one of the plurality of secure services,

whereby at least one of the plurality of service providers communicates directly with at least one other of the plurality of service providers such that the at least one of the plurality of service providers determines whether a credential is used across more than one of the plurality of service providers,

whereby the at least one of the plurality of service providers and the at least one other of the plurality of service providers jointly execute a secure multi-party computation cryptographic protocol such that the at least one other of the plurality of service providers cannot ascertain the identities of users of the at least one of the plurality of service provider,

wherein a private set intersection of credentials is computed such that the at least one of the plurality of secure services determines whether a credential is used across more than one of the plurality of secure services,

wherein at least one of the plurality of secure services stores cryptographic hashes of credentials,

wherein credentials that are similar but not identical are identified, and

wherein similarity of other credentials in the central database is used to calculate credential strength.

14. The federated system for preventing cross-site credential reuse of claim 13 , wherein at least one of the plurality of service providers stores previous credentials in addition to current credentials.

15. The federated system for preventing cross-site credential reuse of claim 13 , wherein bulk requests are used to perform more than one operation in a single query.

16. The federated system for preventing cross-site credential reuse of claim 13 , wherein at least one of the plurality of secure services communicates with at least one of the plurality of service providers to determine whether a credential is reused by a particular user across more than one of the plurality of secure services.

17. The federated system for preventing cross-site credential reuse of claim 13 , wherein at least one of the plurality of secure services communicates with at least one of the plurality of service providers to determine whether a credential is reused across different users across more than one of the plurality of secure services.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 16, 2025
From: NAIR, VIVEK
To: MULTIFACTOR, INC.
Reel/Frame 072263/0438 →
Continuity (2)
Provisional Application 63029165 · May 22, 2020
Related Publication 20210367934A1 · Nov 25, 2021