IP Library Granted Patent US 11,758,403
Granted Patent B1
US 11,758,403 · App. 17/497,038 · Granted Sep 12, 2023

Threat identification, prevention, and remedy

Inventors: Saipavan K. Cherala (Telangana, IN); Rameshchandra Bhaskar Ketharaju (Telangana, IN); Sumanth Kumar Charugundla (Telangana, IN); Damaraju P. Vittal (Telangana, IN)
Assignee: Wells Fargo Bank, N.A.
H04W12/12G06F21/316G06F21/32H04L63/08H04L63/0861H04W12/06H04W12/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,758,403
App. No.
17/497,038
Granted
Sep 12, 2023
Kind
B1
Abstract

Theft identification, prevention, and remedy are provided. A determination is made that a client device has been compromised. When the device makes the determination, a message is conveyed to the server and the server replies with a security challenge. When the server makes the determination, the security challenge is automatically sent to the device. An intelligence manager on the device attempts to answer the security question without interaction from the user. If there is an anomaly, a challenge is output to the user. Based on a false response to the challenge, a current data stream may be disrupted and removed from the device. Further, other devices in the network may be notified about the compromised device.

Claims (37)

1. A method for providing data protection, comprising:

requesting a security signature from a client device in response to a request from the client device to connect to a secure network, wherein the security signature includes parameters of the client device and a user of the client device, and each parameter includes a score and rank relevant to other parameters;

receiving a compromise message over a network from a first user device that has been provided a data stream;

identifying that the first user device needs to be verified based on the compromise message;

determining a security challenge for the first user device based on intelligence gathered relating to the first user device;

transmitting the security challenge to the first user device; and

if an expected response is not received from the first user device in response to the security challenge, protecting the data stream on the first user device.

2. The method of claim 1 , wherein protecting the data stream comprises at least one of erasing the data stream from the user device, masking the data stream on the user device, and rendering the data stream corrupt on the user device.

3. The method of claim 1 , further comprising transmitting an alert to other user devices on the network concerning the first user device.

4. The method of claim 1 , further comprising receiving a request to perform a financial transaction and a signal from the first user device.

5. The method of claim 4 , further comprising rejecting the financial transaction based on failure of the security challenge.

6. The method of claim 4 , further comprising permitting performance of the financial transaction.

7. The method of claim 1 , further comprising validating the request to connect to the secure network based on comparison of the parameters of the security signature to historic parameters and an acceptable deviation threshold.

8. The method of claim 1 , wherein the security signature includes parameters that capture one or more biometrics of the user.

9. The method of claim 8 , wherein security signature includes parameters that capture typing speed or pressure on a touch screen of the client device.

10. A system comprising:

a processor configured to:

request a security signature from a client device in response to a request from the client device to connect to a secure network, wherein the security signature includes parameters of the client device and a user of the client device, and each parameter includes a score and rank relevant to other parameters;

receive a compromise message over a network from a first user device that has been provided a data stream;

identify that the first user device needs to be verified based on the compromise message;

determine a security challenge for the first user device based on intelligence gathered relating to the first user device;

transmit the security challenge to the first user device; and

if an expected response is not received from the first user device in response to the security challenge, protect the data stream on the first user device.

11. The system claim 10 , wherein protecting the data stream comprises at least one of erasing the data stream from the user device, masking the data stream on the user device, and rendering the data stream corrupt on the user device.

12. The system claim 10 , wherein the processor is further configured to transmit an alert to other user devices on the network concerning the first user device.

13. The system claim 10 , wherein the processor is further configured to receive a request to perform a financial transaction and a signal from the first user device.

14. The system claim 13 , wherein the processor is further configured to reject the financial transaction based on failure of the security challenge.

15. The system claim 13 , wherein the processor is further configured to permit performance of the financial transaction.

16. The system claim 10 , wherein the processor is further configured to validate the request to connect to the secure network based on comparison of the parameters of the security signature to historic parameters and an acceptable deviation threshold.

17. The system claim 10 , wherein the security signature includes parameters that capture one or more biometrics of the user.

18. A non-transitory computer readable medium comprising program code, which, when executed by one or more processors, is configured to cause the one or more processors to:

request a security signature from a client device in response to a request from the client device to connect to a secure network, wherein the security signature includes parameters of the client device and a user of the client device, and each parameter includes a score and rank relevant to other parameters;

receive a compromise message over a network from a first user device that has been provided a data stream;

identify that the first user device needs to be verified based on the compromise message;

determine a security challenge for the first user device based on intelligence gathered relating to the first user device;

transmit the security challenge to the first user device; and

if an expected response is not received from the first user device in response to the security challenge, protect the data stream on the first user device.

Assignments (2)
ADDRESS CHANGE Recorded Jun 2, 2025
From: WELLS FARGO BANK, N.A.
To: WELLS FARGO BANK, N.A.
Reel/Frame 071769/0143 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 6, 2022
From: CHERALA, SAIPAVAN K.; KETHARAJU, RAMESHCHANDRA BHASKAR; CHARUGUNDLA, SUMANTH KUMAR; VITTAL, DAMARAJU P.
To: WELLS FARGO BANK, N.A.
Reel/Frame 058960/0679 →
Continuity (2)
Continuation 16673263 · Nov 4, 2019
Continuation 14945522 · Nov 19, 2015