IP Library Granted Patent US 10,277,623
Granted Patent B2
US 10,277,623 · App. 15/075,077 · Granted Apr 30, 2019

Method of detection of comptromised accounts

Inventor: Rui Wang (Redmond, WA)
Assignee: AppBugs, INC.
H04L63/1441H04L9/002H04L9/3226H04L9/3236H04L63/083G06F21/6254H04L63/06H04L2209/42
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,277,623
App. No.
15/075,077
Granted
Apr 30, 2019
Kind
B2
Abstract

Processes and systems described herein enable a computing device to detect compromised accounts. The computing device may obtain a user credential including a user ID, and further modify the user ID. The computing device may transmit the modified user ID to a service including a database related to compromised accounts, receive a record corresponding to the modified user ID that includes information of a compromised account, and further determine whether an account of the user ID is compromised based on the received record.

Claims (40)

1. A method for detection of a compromised user accounts by brute-force attacks, the method comprising:

receiving, by one or more processors of a computing device from a user device, a user credential that comprises a user identifier (ID) and a password that are associated with a user;

anonymizing, by the one or more processors, the user ID by obscuring one or more letters of the user ID without altering length of the user ID;

transmitting, by the one or more processors, the anonymized user ID to a server associated with the detection of the compromised user accounts by the brute-force attacks;

receiving, by the one or more processors from the server, a record corresponding the anonymized user ID, the record comprising:

an ID comprising unobscured letters of the user ID,

a hashed password corresponding to the ID,

one or more hash algorithms associated with the hashed password, and

determining, by the one or more processors, whether the ID of the record matches the user ID;

in response to a determination that the ID of the record matches the user ID, performing a hash operation on the password associated with the user using the one or more hash algorithms of the received record to generate a hashed password corresponding to the user ID;

determining, by the one or more processors, whether the generated hashed password corresponding to the user ID matches the password corresponding to the ID; and

in response to a determination that the generated hashed password matches the password associated with the ID, generating, by the one or more processors, a notification based on the user credential, the notification indicating that an account associated with the user credential is compromised.

2. A method for detection of compromised user accounts, the method comprising: obtaining, by one more processors of a computing device, a user credential comprising a user ID;

modifying, by one or more processors, the user ID to anonymize the user ID, by obscuring one or more letters of the user ID without altering length of the user ID;

transmitting, by the one or more processors, the modified user ID to a computing device associated with a security service provider;

receiving, by the one or more processors from the computing device associated with the security service provider, a record corresponding to the modified user ID that comprises information of a compromised account;

the record comprising: an ID comprising unobscured letters of the user ID, a hashed password corresponding to the ID, one or more hash algorithms associated with the hashed password;

and determining, by the one or more processors, whether an account of the user ID is compromised based on the received record,

in response to the determination that an account of the user ID is compromised based on the received record, performing a hash operation on the password associated with the user using the one or more hash algorithms of the received record to generate a hashed password corresponding to the user ID;

determining, by the one or more processors, whether the generated hashed password corresponding to the user ID matches the password corresponding to the ID; and

in response to a determination that the generated hashed password matches the password associated with the ID, generating, by the one or more processors, a notification based on the user credential, the notification indicating that an account associated with the user credential is compromised.

3. The method of claim 2 , wherein the determining whether the account of the user ID is compromised based on the received record comprises determining whether the account of the user ID is compromised based on the ID corresponding to the modified user ID, the hashed password associated with the ID, and one or more hash algorithms associated with the hashed password.

4. The method of claim 3 , wherein the modifying the user ID to anonymize the user ID comprises anonymizing the user ID by obscuring one or more letters of the user ID.

5. The method of claim 4 , wherein the anonymized user ID comprises unobscured letters of the user ID.

6. The method of claim 3 , wherein the credential further comprises a password of the user, and the user ID comprises an email address of the user.

7. The method of claim 6 , wherein the determining whether the account of the user ID is compromised based on the received record comprises:

determining that the ID matches the user ID;

performing a hash operation on the password of the user to generate a hashed user password corresponding to the user ID; and

determining whether the hashed user password corresponding to the user ID matches the hashed password associated with the ID.

8. The method of claim 7 , further comprising in response to a determination that the hashed user password of the user ID matches the hashed password associated with the ID:

generating a notification based on the user credential, the notification indicating that an account associated with the user credential is compromised, and

providing the notification to the user.

9. The method of claim 3 , wherein the one or more hash algorithms comprise at least one of bcrypt file encryption utility (BCrypt), MD5 message-digest algorithm (MD5), or Secure Hash Algorithm 1 (SHA1).

10. The method of claim 3 , wherein the one or more hash algorithms comprises a first hash algorithm associated with the security service provider and a second hash algorithms associated with a third party system, and the hashed password have been hashed using the first hash algorithm and the second hash algorithm.

11. The method of claim 3 , wherein the record further comprises random data associated with the one or more hash algorithms.

12. The method of claim 3 , further comprising:

receiving a login request comprising the user credential;

receiving a query for a compromised record that indicates whether a user account is compromised, the query comprising the user credential; or

determining a user account for a compromising evaluation in a predetermined time period, the user account corresponding to the user credential, and

transmitting random data associated with a hash to the computing device associated with the security service provider.

Assignments (3)
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE NAME PREVIOUSLY RECORDED ON REEL 72643 FRAME 392. ASSIGNOR(S) HEREBY CONFIRMS THE THE ASSIGNMENT.. Recorded Nov 14, 2025
From: APPBUGS, INC.
To: PASSWORDPING LTD. D/B/A ENZOIC
Reel/Frame 073571/0423 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 22, 2025
From: APPBUGS, INC.
To: PASSWORDPING LTD. D/B/A ENZOINC
Reel/Frame 072643/0392 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 18, 2016
From: WANG, RUI
To: APPBUGS, INC
Reel/Frame 038039/0364 →
Continuity (1)
Related Publication 20170272461A1 · Sep 21, 2017