IP Library › Granted Patent US 11,811,775
Granted Patent B2
US 11,811,775 · App. 17/713,987 · Granted Nov 7, 2023

System and method for handling user requests for web services

Inventor: Steven Hadler (San Francisco, CA)
Assignee: CHARLES SCHWAB & CO., INC.
H04L63/101H04L63/083
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,811,775
App. No.
17/713,987
Granted
Nov 7, 2023
Kind
B2
Abstract

A system and method detects and handles replay attacks using counters maintained for each of several different periods for various values of IP addresses and browser description attributes encountered.

Claims (64)

1. A method of invalidating credentials, comprising:

receiving a user identifier from an entity;

receiving a password from the entity;

receiving a plurality of browser attribute values from the entity;

determining whether the user identifier and password received match a valid user identifier and password;

responsive to the user identifier and password received matching the valid user identifier and password corresponding to the valid user identifier, recording a first indication of occurrence of the matching, at least one time, for each of the plurality of browser attribute values, the recordings corresponding to at least one period corresponding to a date and time substantially equal to a date and time at which the user identifier and password were received;

responsive to the user identifier received not matching the valid user identifier or the user identifier and password received matching a valid user identifier but not matching a password corresponding to the valid user identifier, recording a second indication of occurrence of the not matching or the matching and not matching, at least one time, for each of the plurality of browser attribute values, the recordings all corresponding to the at least one period corresponding to the date and time substantially equal to the date and time at which the user identifier and password were received;

computing at least one score for each of the plurality of browser attribute values received, the at least one score computed using the recordings of the first indication of occurrences and the indications of second occurrences for each of the browser attribute values;

combining the scores computed to produce a combined score;

comparing the combined score to a threshold; and

responsive to results of the comparing, invalidating the credentials associated with the user identifier received.

2. The method of claim 1 , further comprising:

providing a web page having at least a format of one that would be shown to the entity if the credentials associated with the user identifier had not been invalidated.

3. The method of claim 1 , wherein:

the at least one time the first indication of occurrence is recorded comprises a plurality of times; and

the at least one time the second indication of occurrence is recorded comprises a plurality of times.

4. The method of claim 3 , wherein:

the at least one period comprises a plurality of periods, each having a different size; and

each of the plurality of times corresponds to a different period size.

5. The method of claim 1 wherein each of the at least one score is computed by integrating an area under a curve representing a function.

6. The method of claim 5 wherein the function is configured to use the recordings of both of the first indications of occurrences and the second indications of occurrences to produce the curve.

7. The method of claim 6 wherein the function comprises a beta distribution.

8. A system for invalidating credentials in response to a request, comprising:

a memory having computer readable instructions stored thereon; and

at least one processor configured to execute the computer readable instructions to cause the system to perform,

receiving from an entity a request, the request comprising a user identifier, a password, and a plurality of browser attribute values,

retrieving a substantially current date and time,

determining whether the user identifier and password received match a valid user identifier and password,

providing an indication having a first state or a second state responsive to results of the determining, the providing including additionally providing the plurality of browser attribute values, the user identifier and the substantially current date and time;

responsive to the indication having the first state, recording a first indication of occurrence of the indication having the first state, at least one time, for the one of the plurality of browser attribute value, the recordings all corresponding to a period corresponding to the substantially current date and time,

responsive to the indication having the second state, recording a second indication of occurrence of the received indication, having the second state, at least one time, for the one of the plurality of browser attribute value, the recordings all corresponding to the period corresponding to the substantially current date and time,

computing a plurality of scores using the detected first indications and second indications,

combining the plurality of scores computed to produce a combined score,

comparing the combined score to a threshold,

providing a comparison indicator having a first state and a second state responsive to results of the comparing, and

invalidating credentials associated with the user identifier, responsive to results of the comparison indicator having the first state.

9. The system of claim 8 , wherein the system is further caused to perform:

providing at an output a web page having at least a format of one that would be shown to the entity if the credentials associated with the user identifier had not been invalidated, regardless of the comparison indicator.

10. The system of claim 8 , wherein the at least one time for the one of the plurality of browser attribute values comprise a plurality of times for each of the plurality of browser attribute values.

11. The system of claim 10 , wherein for each of the plurality of browser attribute values, each of the times corresponds to a different period size.

12. The system of claim 8 wherein each score is computed by the score computer by integrating an area under a curve representing a function.

13. The system of claim 12 wherein the function uses the first indications, second indications, third indications and fourth indications to produce the curve.

14. The system of claim 13 wherein the function comprises a beta distribution.

15. A non-transitory computer useable medium having computer readable program code stored thereon, the computer readable program code configured to cause a computer system to:

receive a user identifier from an entity;

receive a password from the entity;

receive a plurality of browser attribute values from the entity;

determine whether the user identifier and password received match a valid user identifier and password;

responsive to the user identifier and password received matching the valid user identifier and password corresponding to the valid user identifier, record a first indication of occurrence of the matching, at least one time, for each of the plurality of browser attribute values, the recordings corresponding to at least one period corresponding to a date and time substantially equal to a date and time at which the user identifier and password were received;

responsive to the user identifier received not matching the valid user identifier or the user identifier and password received matching a valid user identifier but not matching a password corresponding to the valid user identifier, record a second indication of occurrence of the not matching or the matching and not matching, at least one time, for each of the plurality of browser attribute values, the recordings all corresponding to the at least one period corresponding to the date and time substantially equal to the date and time at which the user identifier and password were received;

compute at least one score for each of the plurality of browser attribute values received, the at least one score computed using the recordings of the first indication of occurrences and the indications of second occurrences for each of the browser attribute values;

combine the scores computed to produce a combined score;

compare the combined score to a threshold; and

responsive to results of the comparing, invalidate credentials associated with the user identifier received.

16. The non-transitory computer useable medium of claim 15 , wherein the computer readable program code is further configured to cause the computer system to provide a web page having at least a format of one that would be shown to the entity if the credentials associated with the user identifier had not been invalidated.

17. The non-transitory computer useable medium of claim 15 , wherein:

the at least one time the first indication of occurrence is recorded comprises a plurality of times; and

the at least one time the second indication of occurrence is recorded comprises a plurality of times.

18. The non transitory computer useable medium of claim 17 , wherein:

the at least one period comprises a plurality of periods, each having a different size; and

each of the plurality of times corresponds to a different period size.

19. The non-transitory computer useable medium of claim 15 wherein each of the at least one score is computed by integrating an area under a curve representing a function.

20. The non-transitory computer useable medium of claim 19 wherein the function uses the recordings of both of the first indications of occurrences and the second indications of occurrences to produce the curve.

21. The non-transitory computer useable medium of claim 20 wherein the function comprises a beta distribution.

Continuity (4)
Continuation 16865422 · May 4, 2020
Continuation 15860605 · Jan 2, 2018
Provisional Application 62441138 · Dec 30, 2016
Related Publication 20220303275A1 · Sep 22, 2022