IP Library › Granted Patent US 12,267,311
Granted Patent B2
US 12,267,311 · App. 18/155,812 · Granted Apr 1, 2025

Systems and methods for restricting security connection data resets

Inventor: Sidharth Garg (Atlanta, GA)
Assignee: TRUIST BANK
H04L63/08H04L41/0813H04L63/102
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,267,311
App. No.
18/155,812
Filed
Jan 18, 2023
Granted
Apr 1, 2025
Kind
B2
Art Unit
2495
USPC
726/3
Abstract

A system maintains values for secure connection settings for multiple registered users and restricts data resets. Upon receiving a reset request to reset the value of a particular secure connection setting for a specific user, trials are conducted each by: providing a reset tool to the requesting device for input of a requested new value for the secure connection setting; receiving the requested new value from the requesting device; and sending a validation request to a validation system, the validation request including, at least in part, the requested new value for the particular secure connection setting. If a reply from the validation system is deemed a repudiation of the requested new value, a trial count is tolled. If the trial count reaches a predetermined condition, trials are suspended, a denial message is sent to the requesting device, and the specific user is alerted of a attempt to alter their data.

Claims (36)

1. A system for restricting security connection data resets, the system comprising:

a computing system of a first entity including one or more processor configured to execute computer-readable instructions, at least one of a memory device and a non-transitory storage device maintaining values for respective secure connection settings for each user of multiple registered users each having one or more user device, and a communication interface for operatively connecting, via a communication network, the one or more processor to the one or more user device of each of the multiple registered users, and to a validation entity computing system of a validation service entity,

wherein, upon execution of the computer-readable instructions, the computing system performs steps comprising, for a specific user of the multiple registered users upon receiving a reset request, from a requesting device, to reset the value of a particular secure connection setting of the secure connection settings for the specific user:

conducting multiple trials in succession, by, for each of the multiple trials:

providing a reset tool to the requesting device for input of a requested new value for the particular secure connection setting;

receiving the requested new value from the requesting device;

sending a validation request to the validation entity computing system, the validation request including, at least in part, the requested new value for the particular secure connection setting;

receiving, from the validation entity computing system, a repudiation of the requested new value for the particular secure connection setting; and

tolling a trial count, and

upon the trial count reaching a predetermined condition:

suspending the conducting of the multiple trials;

sending a denial message to the requesting device; and

sending an alert of the request to reset the value of a particular secure connection setting to at least one user device of the one or more user device of the specific user according to at least one maintained value of the secure connection settings for the specific user.

2. The system according to claim 1 , wherein upon the trial count reaching a predetermined condition, the computing system further maintains the values for respective secure connection settings for the specific user against unassisted machine-conducted resets.

3. The system according to claim 2 , wherein upon the trial count reaching a predetermined condition, the computing system further maintains the values for respective secure connection settings for the specific user against unassisted machine-conducted resets for a delay interval.

4. The system according to claim 3 , wherein upon the trial count reaching a predetermined condition, the computing system further permits resets, conducted by a human agent of the first entity, within the delay interval, of the secure connection settings for the specific user.

5. The system according to claim 2 , wherein the repudiation of the requested new value for the particular secure connection setting comprises a score assessing likelihood of authenticity of the requested new value for the particular secure connection setting.

6. The system according to claim 1 , wherein maintaining values for respective secure connection settings comprises maintaining phone numbers and email addresses for user contact.

7. The system according to claim 1 , wherein the reset request from the requesting computing device is initiated by a malicious entity.

8. The system according to claim 1 , the validation request identifies the specific user.

9. A method for a computing system to restrict security connection data resets, the computing system being of a first entity and including one or more processor configured to execute computer-readable instructions, at least one of a memory device and a non-transitory storage device maintaining values for respective secure connection settings for each user of multiple registered users each having one or more user device, and a communication interface for operatively connecting, via a communication network, the one or more processor to the one or more user device of each of the multiple registered users, and to a validation entity computing system of a validation service entity, the method comprising, upon execution of the computer-readable instructions:

upon receiving a reset request, from a requesting device, to reset the value of a particular secure connection setting of the secure connection settings for a specific user of the multiple registered users:

conducting multiple trials in succession, by, for each of the multiple trials:

providing a reset tool to the requesting device for input of a requested new value for the particular secure connection setting;

receiving the requested new value from the requesting device;

sending a validation request to the validation entity computing system, the validation request including, at least in part, the requested new value for the particular secure connection setting;

receiving, from the validation entity computing system, a repudiation of the requested new value for the particular secure connection setting; and

tolling a trial count, and

upon the trial count reaching a predetermined condition:

suspending the conducting of the multiple trials;

sending a denial message to the requesting device; and

sending an alert of the request to reset the value of a particular secure connection setting to at least one user device of the one or more user device of the specific user according to at least one maintained value of the secure connection settings for the specific user.

10. The method according to claim 9 , wherein upon the trial count reaching a predetermined condition, the computing system further maintains the values for respective secure connection settings for the specific user against unassisted machine-conducted resets for a delay interval.

11. The method according to claim 10 , wherein upon the trial count reaching a predetermined condition, the computing system further permits resets, conducted by a human agent of the first entity, within the delay interval, of the secure connection settings for the specific user.

12. The method according to claim 9 , wherein the repudiation of the requested new value for the particular secure connection setting comprises a score assessing likelihood of authenticity of the requested new value for the particular secure connection setting.

13. The method according to claim 9 , wherein maintaining values for respective secure connection settings comprises maintaining data for user contact.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 18, 2023
From: GARG, SIDHARTH
To: TRUIST BANK
Reel/Frame 062404/0912 →
Continuity (1)
Related Publication 20240244041A1 · Jul 18, 2024
References Cited (48)
US 7793835B1 · Coggeshall · 2010 [cited by examiner]
US 8386377B1 · Xiong · 2013 [cited by examiner]
US 10445514B1 · Brandwine · 2019 [cited by examiner]
US 10521857B1 · Shao · 2019 [cited by examiner]
US 10783520B2 · Moss · 2020 [cited by examiner]
US 11017464B1 · Harris · 2021 [cited by examiner]
US 11610278B2 · Clark · 2023 [cited by examiner]
US 11704679B2 · Epstein · 2023 [cited by examiner]
US 11843617B2 · Lee · 2023 [cited by examiner]
US 12051072B1 · Moss · 2024 [cited by examiner]
US 12093375B2 · Endler · 2024 [cited by examiner]
US 12120126B2 · Aguayo · 2024 [cited by examiner]
US 12125039B2 · Kramme · 2024 [cited by examiner]
US 12137114B2 · Vlahovic · 2024 [cited by examiner]
US 12137117B2 · Spitler · 2024 [cited by examiner]
US 12153666B1 · Katz · 2024 [cited by examiner]
US 20040249961A1 · Katsube · 2004 [cited by applicant]
US 20050193075A1 · Haff · 2005 [cited by applicant]
US 20070260884A1 · Venkitaraman · 2007 [cited by applicant]
US 20080114885A1 · Kulkarni · 2008 [cited by examiner]
US 20090310528A1 · Tamura · 2009 [cited by applicant]
US 20110055404A1 · Joyce · 2011 [cited by applicant]
US 20120054498A1 · Rickman · 2012 [cited by applicant]
US 20150256525A1 · Takaoka · 2015 [cited by applicant]
US 20160147989A1 · Venkata Dongala · 2016 [cited by applicant]
US 20170109855A1 · Stockton · 2017 [cited by examiner]
US 20180220475A1 · Tsurumi · 2018 [cited by applicant]
US 20190222606A1 · Schweighauser · 2019 [cited by examiner]
US 20190244217A1 · Shaw · 2019 [cited by examiner]
US 20200066379A1 · Chapman · 2020 [cited by applicant]
US 20200118235A1 · Clark · 2020 [cited by examiner]
US 20200242219A1 · Kaczynski · 2020 [cited by applicant]
US 20200329025A1 · Kahn · 2020 [cited by applicant]
US 20210221125A1 · Panshin · 2021 [cited by applicant]
US 20210241288A1 · Doreswamy · 2021 [cited by examiner]
US 20220247765A1 · Lee · 2022 [cited by examiner]
US 20230086281A1 · Kaidi · 2023 [cited by examiner]
US 20230199002A1 · Kaidi · 2023 [cited by examiner]
US 20230336571A1 · Costa · 2023 [cited by examiner]
US 20240089262A1 · Legault · 2024 [cited by examiner]
US 20240195828A1 · Panasiuk · 2024 [cited by examiner]
US 20240202309A1 · Brown · 2024 [cited by examiner]
US 20240244041A1 · Garg · 2024 [cited by examiner]
US 20240244043A1 · Garg · 2024 [cited by examiner]
US 20240314125A1 · Shaffer · 2024 [cited by examiner]
US 20240403885A1 · Bashore · 2024 [cited by examiner]
JP 3923312B2 · 2007 [cited by applicant]
Lempereur, Kira, “Account Takeover Prevention: How to Prevent ATO & Mitigate Fraud”, Nov. 10, 2022, Datadome.co, https://datadome.co/guides/account-takeover/how-to-prevent-account-takeover-attacks/, accessed Dec. 5, 202… [cited by examiner]