IP Library Granted Patent US 12,562,919
Granted Patent B2
US 12,562,919 · App. 18/473,465 · Granted Feb 24, 2026

Methods and systems for device authentication

Inventor: Steven Todd Kirsch (Los Altos Hills, CA)
Assignee: NEUSTAR, INC.
H04L9/3247G06F21/31G06F21/335H04L9/14H04L9/30H04L9/3263H04L63/06H04L63/08H04L63/0823H04L63/0869H04L63/12G06F2221/2103H04L63/083
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,562,919
App. No.
18/473,465
Granted
Feb 24, 2026
Kind
B2
Abstract

A method for disabling a device associated with a virtual identity may include receiving, from the device, a request to use the virtual identity, where the request that may include a passcode guess and a device identifier. The method may also include determining that the passcode guess does not authorize use of the virtual identity and incrementing a number of incorrect passcode guesses received within a time interval. The method may additionally include determining that the number of incorrect passcode guesses received within the time interval is greater than or equal to a threshold. The method may further include storing an indication that subsequent requests associated with the device identifier should not authorize use of the virtual identity.

Claims (38)

1 . A method for disabling a device associated with a virtual identity, the method comprising:

receiving, from the device, a request to register the device, the request comprising a passcode guess;

determining whether the passcode guess authorizes registration of the device based on a number of incorrect passcode guesses received from a user of the device within the time interval being greater than or equal to a threshold;

upon determining the passcode guess does not authorize registration of the device due to the number of incorrect passcode guesses received being greater than or equal to the threshold, determining the device has been compromised and sending an indication to the device that the request was successful in order to obtain further information from the user of the device regarding a location of the device;

upon receipt of the further information, storing the further information; and

preventing future registration attempts by the device.

2 . The method of claim 1 , wherein the passcode guess is based on a PIN.

3 . The method of claim 1 , wherein the passcode guess comprises a hash of a salted password.

4 . The method of claim 1 , further comprising incrementing the number of incorrect passcode guesses by a predetermined value for each incorrect passcode guess based on a type of device.

5 . The method of claim 1 , wherein the threshold varies based on a type of device.

6 . The method of claim 1 , further comprising sending a further indication to further devices reporting that the device is prevented from future registration attempts.

7 . The method of claim 1 , further comprising tracking further attempts by the device to register the device.

8 . A non-transitory computer readable medium storing instructions for disabling a device associated with a virtual identity, wherein when the instructions are executed by one or more processors of a computing system, the instructions perform operations comprising:

receiving a request to register a device, the request comprising a passcode guess;

determining whether the passcode guess authorizes registration of the device based on a number of incorrect passcode guesses received from a user of the device within the time interval being greater than or equal to a threshold;

upon determining the passcode guess does not authorize registration of the device due to the number of incorrect passcode guesses received being greater than or equal to the threshold, determining the device has been compromised and sending an indication to the device that the request was successful in order to obtain further information from the user of the device regarding a location of the device;

upon receipt of the further information, storing the further information; and

preventing future registration attempts by the device.

9 . The non-transitory computer readable medium of claim 8 , wherein the passcode guess is based on a PIN.

10 . The non-transitory computer readable medium of claim 8 , wherein the passcode guess comprises a hash of a salted password.

11 . The non-transitory computer readable medium of claim 8 , wherein the operations further comprise incrementing the number of incorrect passcode guesses by a predetermined value for each incorrect passcode guess based on a type of device.

12 . The non-transitory computer readable medium of claim 8 , wherein the threshold varies based on a type of device.

13 . The non-transitory computer readable medium of claim 8 , wherein the operations further comprise sending a further indication to further devices reporting that the device is prevented from future registration attempts.

14 . The non-transitory computer readable medium of claim 8 , wherein the operations further comprise tracking further attempts by the device to register the device.

15 . A computing system for disabling a device associated with a virtual identity comprising:

one or more processors; and

one or more memories coupled to the one or more processors, having instructions stored thereon, which, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

receiving a request to register a device, the request comprising a passcode guess, determining whether the passcode guess authorizes registration of the device based on a number of incorrect passcode guesses received from a user of the device within the time interval being greater than or equal to a threshold,

upon determining the passcode guess does not authorize registration of the device due to the number of incorrect passcode guesses received being greater than or equal to the threshold, determining the device has been compromised and sending an indication to the device that the request was successful in order to obtain further information from the user of the device regarding a location of the device,

upon receipt of the further information, storing the further information, and

preventing future registration attempts by the device.

16 . The computing system of claim 15 , wherein the passcode guess is based on a PIN.

17 . The computing system of claim 15 , wherein the passcode guess comprises a hash of a salted password.

18 . The computing system of claim 15 , wherein the operations further comprise incrementing the number of incorrect passcode guesses by a predetermined value for each incorrect passcode guess based on a type of device.

19 . The computing system of claim 15 , wherein the threshold varies based on a type of device.

20 . The computing system of claim 15 , wherein the operations further comprise:

sending a further indication to further devices reporting that the device is prevented from future registration attempts; or

tracking further attempts by the device to register the device.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 11, 2025
From: ONEID INC.
To: NEUSTAR, INC.
Reel/Frame 070808/0751 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 11, 2025
From: KIRSCH, STEVEN TODD
To: ONEID INC.
Reel/Frame 070808/0829 →
Continuity (9)
Continuation 17323450 · May 18, 2021
Continuation 16002990 · Jun 7, 2018
Continuation 15155264 · May 16, 2016
Continuation 13745354 · Jan 18, 2013
Provisional Application 61609515 · Mar 12, 2012
Provisional Application 61609848 · Mar 12, 2012
Provisional Application 61609854 · Mar 12, 2012
Provisional Application 61588084 · Jan 18, 2012
Related Publication 20240022431A1 · Jan 18, 2024
References Cited (142)
US 5495235A · Durinovic-Johri et al. · 1996 [cited by applicant]
US 5550968A · Miller et al. · 1996 [cited by applicant]
US 5559505A · McNair · 1996 [cited by applicant]
US 5715314A · Payne et al. · 1998 [cited by applicant]
US 6209091B1 · Sudia et al. · 2001 [cited by applicant]
US 6263446B1 · Kausik et al. · 2001 [cited by applicant]
US 6289323B1 · Gordon et al. · 2001 [cited by applicant]
US 6381331B1 · Kato · 2002 [cited by applicant]
US 6826690B1 · Hind et al. · 2004 [cited by applicant]
US 6850951B1 · Davison · 2005 [cited by applicant]
US 7266695B2 · Nakayama · 2007 [cited by applicant]
US 7320073B2 · Zissimopoulos et al. · 2008 [cited by applicant]
US 7428750B1 · Dunn et al. · 2008 [cited by applicant]
US 7522723B1 · Shaik · 2009 [cited by applicant]
US 8023647B2 · Shaik · 2011 [cited by applicant]
US 8302187B1 · Gupta · 2012 [cited by examiner]
US 8316237B1 · Felsher · 2012 [cited by examiner]
US 8490162B1 · Popoveniuc · 2013 [cited by examiner]
US 8769304B2 · Kirsch · 2014 [cited by applicant]
US 9177005B2 · Mehta et al. · 2015 [cited by applicant]
US 9197673B1 · Gaddy et al. · 2015 [cited by applicant]
US 9203819B2 · Fenton et al. · 2015 [cited by applicant]
US 9215223B2 · Kirsch · 2015 [cited by applicant]
US 9344413B2 · Kirsch · 2016 [cited by applicant]
US 20010024502A1 · Ohkuma et al. · 2001 [cited by applicant]
US 20020076055A1 · Filipi-Martin et al. · 2002 [cited by applicant]
US 20020108046A1 · Armingaud · 2002 [cited by examiner]
US 20020194163A1 · Hopeman et al. · 2002 [cited by applicant]
US 20030057272A1 · Bidan et al. · 2003 [cited by applicant]
US 20030147534A1 · Ablay et al. · 2003 [cited by applicant]
US 20030177400A1 · Raley et al. · 2003 [cited by applicant]
US 20030204511A1 · Brundage et al. · 2003 [cited by applicant]
US 20040062400A1 · Sovio et al. · 2004 [cited by applicant]
US 20040088587A1 · Ramaswamy et al. · 2004 [cited by applicant]
US 20040205342A1 · Roegner · 2004 [cited by applicant]
US 20050010447A1 · Miyasaka et al. · 2005 [cited by applicant]
US 20050044402A1 · Libin et al. · 2005 [cited by applicant]
US 20050097320A1 · Golan et al. · 2005 [cited by applicant]
US 20050220080A1 · Ronkainen et al. · 2005 [cited by applicant]
US 20060080534A1 · Yeap et al. · 2006 [cited by applicant]
US 20060083187A1 · Dekel · 2006 [cited by applicant]
US 20060129817A1 · Borneman et al. · 2006 [cited by applicant]
US 20060206709A1 · Labrou et al. · 2006 [cited by applicant]
US 20060224508A1 · Fietz et al. · 2006 [cited by applicant]
US 20060236095A1 · Smith et al. · 2006 [cited by applicant]
US 20070061263A1 · Carter et al. · 2007 [cited by applicant]
US 20070228148A1 · Rable · 2007 [cited by applicant]
US 20070250920A1 · Lindsay · 2007 [cited by examiner]
US 20070283416A1 · Renaud · 2007 [cited by examiner]
US 20080016232A1 · Yared et al. · 2008 [cited by applicant]
US 20080028453A1 · Nguyen et al. · 2008 [cited by applicant]
US 20080046987A1 · Spector · 2008 [cited by applicant]
US 20080089520A1 · Kessler · 2008 [cited by applicant]
US 20080141313A1 · Kato et al. · 2008 [cited by applicant]
US 20080189778A1 · Rowley · 2008 [cited by applicant]
US 20080222711A1 · Michaelis · 2008 [cited by applicant]
US 20080250248A1 · Lieber · 2008 [cited by applicant]
US 20080282091A1 · Ashok · 2008 [cited by examiner]
US 20090031406A1 · Hirose · 2009 [cited by examiner]
US 20090037994A1 · Buss · 2009 [cited by applicant]
US 20090077645A1 · Kottahachchi · 2009 [cited by applicant]
US 20090080408A1 · Natoli et al. · 2009 [cited by applicant]
US 20090089625A1 · Kannappan et al. · 2009 [cited by applicant]
US 20090157799A1 · Sukumaran et al. · 2009 [cited by applicant]
US 20090159692A1 · Chew · 2009 [cited by examiner]
US 20090249014A1 · Obereiner · 2009 [cited by examiner]
US 20090249497A1 · Fitzgerald · 2009 [cited by examiner]
US 20090260064A1 · McDowell et al. · 2009 [cited by applicant]
US 20090300364A1 · Schneider · 2009 [cited by examiner]
US 20100077457A1 · Xu et al. · 2010 [cited by applicant]
US 20100100945A1 · Ozzie et al. · 2010 [cited by applicant]
US 20100100950A1 · Roberts · 2010 [cited by applicant]
US 20100161969A1 · Grebovich et al. · 2010 [cited by applicant]
US 20100174439A1 · Petricoin, Jr. et al. · 2010 [cited by applicant]
US 20100182283A1 · Sip · 2010 [cited by applicant]
US 20100210240A1 · Mahaffey et al. · 2010 [cited by applicant]
US 20100275009A1 · Canrad et al. · 2010 [cited by applicant]
US 20100306107A1 · Nahari · 2010 [cited by applicant]
US 20100316217A1 · Gammel et al. · 2010 [cited by applicant]
US 20110067095A1 · Leicher et al. · 2011 [cited by applicant]
US 20110078439A1 · Mao et al. · 2011 [cited by applicant]
US 20110179475A1 · Foell et al. · 2011 [cited by applicant]
US 20110185401A1 · Bak · 2011 [cited by examiner]
US 20110225090A1 · Hammad · 2011 [cited by applicant]
US 20110246765A1 · Schibuk · 2011 [cited by applicant]
US 20120050455A1 · Santamaria et al. · 2012 [cited by applicant]
US 20120124379A1 · Teranishi · 2012 [cited by applicant]
US 20120155637A1 · Lambert et al. · 2012 [cited by applicant]
US 20120158725A1 · Molloy et al. · 2012 [cited by applicant]
US 20120233685A1 · Palanigounder et al. · 2012 [cited by applicant]
US 20120265631A1 · Cronic et al. · 2012 [cited by applicant]
US 20120323686A1 · Burger et al. · 2012 [cited by applicant]
US 20120324076A1 · Zerr · 2012 [cited by examiner]
US 20120324242A1 · Kirsch · 2012 [cited by applicant]
US 20120331296A1 · Levin et al. · 2012 [cited by applicant]
US 20130047227A1 · Schultz · 2013 [cited by examiner]
US 20130074120A1 · Adimatyam · 2013 [cited by examiner]
US 20130198078A1 · Kirsch · 2013 [cited by applicant]
US 20130198516A1 · Fenton et al. · 2013 [cited by applicant]
US 20130198598A1 · Kirsch · 2013 [cited by applicant]
US 20130198834A1 · Kirsch · 2013 [cited by applicant]
US 20130205136A1 · Kirsch · 2013 [cited by applicant]
US 20130246272A1 · Kirsch · 2013 [cited by applicant]
US 20130246280A1 · Kirsch · 2013 [cited by applicant]
US 20130276125A1 · Bailey · 2013 [cited by examiner]
US 20140214902A1 · Mehta et al. · 2014 [cited by applicant]
US 20140344904A1 · Venkataramani et al. · 2014 [cited by applicant]
US 20140351596A1 · Chan · 2014 [cited by applicant]
US 20150088754A1 · Kirsch · 2015 [cited by applicant]
US 20160241509A1 · Akcin · 2016 [cited by applicant]
US 20160261413A1 · Kirsch · 2016 [cited by applicant]
US 20170324564A1 · Knopf · 2017 [cited by applicant]
US 20180013569A1 · Knopf · 2018 [cited by applicant]
US 20180013570A1 · Knopf · 2018 [cited by applicant]
US 20180013786A1 · Knopf · 2018 [cited by applicant]
US 20180013824A1 · Knopf · 2018 [cited by applicant]
EP 0683582A1 · 1995 [cited by applicant]
KR 20130083619A · 2013 [cited by applicant]
Yun Ding et al., Undetectable On-line Password Guessing Attacks, Oct. 1995, ACM, pp. 77-86. (Year: 1995). [cited by examiner]
Gurdip Kaur et al., Intrusion Detection System Using Honeypots and Swarm Intelligence, Jul. 21, 2011, pp. 34-38. (Year: 2011). [cited by examiner]
Sujata Yeldi et al., Enhancing Network Intrusion Detection System With Honeypot, Mar. 15, 2004, IEEE, pp. 1-6. (Year: 2004). [cited by examiner]
Vipul Goyal et al., CompChall: Addressing Password Guessing Attacks, May 16, 2005, IEEE, pp. 1-6. (Year: 2005). [cited by examiner]
Abe, T. et al. “Implementing Identity Provider on Mobile Phone” 2007, ACM, pp. 46-52. [cited by applicant]
Balasubramaniam, S. et al. “Identiy Management and its Impact on Federation in a System-of-Systems Context” Mar. 23-26, 2009, IEEE, pp. 179-182. [cited by applicant]
Beasley, J. et al. “Virtual Bluetooth Devices as a Means of Extending Pairing and Bonding in a Bluetooth Network” 2002, IEEE, vol. 4, pp. 2087-2089. [cited by applicant]
Chakchai So-In et al., “Virtual ID: A Technique for Mobility, MultiHoming, and Location Privacy in Next Generation Wireless Networks,” Jan. 9-12, 2010, IEEE, pp. 1-5. [cited by applicant]
Chen, Liqun et al., “Multiple Trusted Authorities in Identifier Based Cryptography from Pairings on Elliptic Curves,” Mar. 19, 2003, HP, pp. 1-26. [cited by applicant]
Jansen, Wayne et al., “Guidelines on Cell Phone and PDA Security,” Oct. 2008, NIST, pp. 1-52. [cited by applicant]
Kholmatov, A. et al. “Identify authentication using improved online signature verification method,” ScienceDirect, Nov. 2005, vol. 26, Issue 15, DD. 2400-2408. [cited by applicant]
Masmoudi, K. et al. “Building identity-based security associations for provider-provisioned virtual private networks,” Dec. 2008, Springer, vol. 39, Issue 3, pp. 215-222. [cited by applicant]
Mayrhofer, Rene et al., “Shake Well Before Use: Intuitive and Secure Pairing of Mobile Devices,” Feb. 27, 2009, IEEE, vol. 8, Issue 6, pp. 792-806. [cited by applicant]
Nguyen, Lang et al., “Secure Authorization, Access Control and Data Integrity in Bluetooth,” 2002, IEEE, pp. 428-433. [cited by applicant]
Novotny, J. et al. “An Online Credential Repository for the Grid: MyProxy,” IEEE, 2001, pp. 104-111. [cited by applicant]
Squicciarini, A. et al. “Access Control Strategies for Virtualized Environments in Grid Computing Systems,” Mar. 21-23, 2007, IEEE, pp. 48-54. [cited by applicant]
International Search Report and Written Opinion mailed Sep. 18, 2012 for International Patent ADDlication No. PCT/US2012/042743, 19 pages. [cited by applicant]
International Search Report and Written Opinion mailed Mar. 29, 2013 for International Patent Application No. PCT/US2013/022207, 13 pages. [cited by applicant]
International Search Report and Written Opinion mailed Jul. 25, 2017 from the U.S. International Search Authority for PCT/US17/31438, 8 paoes. [cited by applicant]
International Search Report and Written Opinion mailed May 30, 2018 from the U.S. International Search Authority for PCT/US18/21877, 8 pages. [cited by applicant]
Yun Ding et al., Undetectable On-Line Password Guessing Attacks, Oct. 1995, ACM, pp. 77-86. (1995). [cited by applicant]
Marc Barisch, Modelling the Impact of Virtual Identities on Communication Infrastructures, Nov. 2009, ACM, pp. 45-52 (2009). [cited by applicant]
Mansour Alsaleh et al., Revisiting Defenses against Large-Scale Online Password Guessing Attacks, May 12, 2011, IEEE, vol. 9, Issue 1, pp. 128-141 (2011). [cited by applicant]
Vipul Goyal et al., CompChall: Addressing Password Guessing Attacks, May 16, 2005, IEEE, pp. 1-6 (2005). [cited by applicant]