IP Library › Granted Patent US 12,744,771
Granted Patent B2
US 12,744,771 · App. 18/143,334 · Granted Sep 22, 2026

Methods and system to prevent credential piracy

Inventor: Zachary Bornheimer (Tampa, FL)
H04L63/083H04L63/102
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,744,771
App. No.
18/143,334
Granted
Sep 22, 2026
Kind
B2
Abstract

Methods and system are implemented to mitigate the chance of credential piracy within a content providing system. The content providing system allows access to the content on its platform to multiple, licensed devices activated for an account. The content platform uses an authentication engine to manage the device information and detect unauthorized access to the content platform. Each device submits credentials typically in the form of a user name or email, a password, and a random string generated at the device. The random string is used to track activated devices and to determine when a possible piracy action is occurring.

Claims (35)

1 . A method for activating a device to access a content platform, the method comprising:

receiving a plurality of credentials at an authentication engine from a plurality of devices connected to the content platform over a network, wherein each device is associated with a credential, and wherein the plurality of credentials and plurality of devices are associated with a user account, and the credentials include authentication components including a user name and a password for the user account and a random string generated at the respective device of the plurality of devices;

checking a random string database table for the random string;

if the random string has been stored in the random string database table, determining a status of an active device of the plurality of devices based on an entry in the random string database table, wherein the entry includes the random string for the active device associated with the user account and the credentials, and wherein each entry differs for each device of the plurality of devices; and

activating the device of the plurality of devices to access the content platform based on the determination using the random string, wherein statuses for the plurality of devices are changed due to the activating,

wherein for the user account, a predetermined number of devices of the plurality of devices are permitted to access the content platform at the same time, each of the predetermined number of devices generates a random string when registering with the content platform, and wherein the random string generated by each of the predetermined number of devices is stored in the random string database table and

when a maximum activation number associated with the user account is reached for active devices of the plurality of devices accessing the content platform when an additional device is logged in and statuses of the predetermined number of devices are all activated, further comprising denying the additional device from accessing the content platform.

2 . The method of claim 1 , further comprising determining that the random string is not within the random string database table.

3 . The method of claim 2 , further comprising making the status for the random string active and storing the random string with the status in the random string database table.

4 . The method of claim 3 , further comprising changing a status for additional random strings within the random string database from active to unknown.

5 . The method of claim 4 , further comprising:

receiving a subsequent random string for another device at the authentication engine; and

determining whether the subsequent random string is in the random string database table.

6 . The method of claim 5 , further comprising taking action with regard to the another device of the plurality of devices connected to the content platform based on the determination of a status of the subsequent random string.

7 . The method of claim 1 , when the maximum activation number associated with the user account is reached for active devices accessing the content platform when the additional device is logged in and at least one device has a status of unknown, further comprising:

changing the status of the at least one device from unknown to inactive; and

activating the additional device for accessing the content platform.

8 . A content provider providing contents to be used or viewed by at least one user, the content provider comprising:

a content platform receiving a plurality of credentials from a plurality of devices connected to the content platform over a network, wherein each device of the plurality of devices is associated with a credential of the plurality of credentials, and wherein the plurality of credentials and the plurality of devices are associated with a user account, and the credentials include authentication components including a a user name and a password for the user account and a random string generated at the respective device of the plurality of devices;

a database storing the user name, the password, and a random string database table having the random string for the user account;

a content database storing the contents to be sent to the at least one user associated with the user account;

one or more processors; and

a memory coupled to the one or more processors, the memory including computer-readable instructions, which when executed, causes the one or more processor to:

authenticate the credentials received from the device to determine if the user name and password match with those saved in the database;

checking the random string database table for the random string;

if the random string has been stored in the random string database table, determining a status of the device of the plurality of devices based on an entry in the random string database table, wherein the entry includes the random string for the device and the credentials and wherein each entry differs for each device of the plurality of devices; and

activating the device of the plurality of devices to access the content platform based on the determination using the random string, wherein statuses for the plurality of devices are changed due to the activating,

wherein for the user account, a predetermined number of devices of the plurality of devices are permitted to access the content platform at the same time, each of the predetermined number of devices generates a random string when registering with the content platform, and wherein the random string generated by each of the predetermined number of devices is stored in the random string database table and when a maximum activation number associated with the user account is reached for active devices of the plurality of devices accessing the content platform when an additional device is logged in and statuses of the predetermined number of devices are all activated, further comprising denying the additional device from accessing the content platform.

9 . The content provider of claim 8 , wherein for the user account, a predetermined number of active devices of the plurality of devices are permitted to access the content platform at the same time, when requesting a connection with the content provider for the first time, each of the devices generating a random string together with the user name and the password to be sent to the content platform, and the random string of each of the plurality of devices is saved in the random string database table.

10 . The content provider of claim 8 , wherein the one or more processor further determines the random string is not within the random string database table.

11 . The content provider of claim 10 , wherein the one or more processor further makes the status for the random string active and storing the random string with the status in the random string database table.

12 . The content provider of claim 11 , wherein the one or more processor further changes a status for additional random strings within the random string database from active to unknown.

13 . The content provider of claim 9 , wherein the maximum activation number of the plurality of devices associated with the user account is reached for active devices accessing the content platform when the additional device is logged in and at least one active device has a status of unknown, further comprising:

changing the status of the at least one active device from unknown to inactivated; and

activating the additional device for accessing the content platform.

Continuity (2)
Provisional Application 63339212 · May 6, 2022
Related Publication 20230362155A1 · Nov 9, 2023
References Cited (27)
US 10414344B1 · Northcott · 2019 [cited by examiner]
US 20030048906A1 · Vora · 2003 [cited by examiner]
US 20130247161A1 · Bajko · 2013 [cited by examiner]
US 20140289825A1 · Chan · 2014 [cited by examiner]
US 20150135286A1 · Egan · 2015 [cited by examiner]
US 20150365416A1 · Narayanan · 2015 [cited by examiner]
US 20160007142A1 · Anderson · 2016 [cited by examiner]
US 20160140618A1 · Duggal · 2016 [cited by examiner]
US 20170124303A1 · Baldwin et al. · 2017 [cited by applicant]
US 20170302656A1 · Ramatchandirane · 2017 [cited by applicant]
US 20180109966A1 · Alexander · 2018 [cited by examiner]
US 20180150647A1 · Naqvi · 2018 [cited by examiner]
US 20190075130A1 · Petry et al. · 2019 [cited by applicant]
US 20200036693A1 · Huynh · 2020 [cited by applicant]
US 20200167553A1 · Abghari · 2020 [cited by examiner]
US 20200184568A1 · Bornheimer · 2020 [cited by examiner]
US 20220382908A1 · Buddhavarapu · 2022 [cited by examiner]
US 20230254288A1 · Nair · 2023 [cited by examiner]
CN 101783803A · 2010 [cited by examiner]
CN 111835514A · 2020 [cited by examiner]
JP 3744358B2 · 2006 [cited by examiner]
JP 2010009356A · 2010 [cited by examiner]
WO WO2013091068A1 · 2013 [cited by examiner]
Deshotels, Luke, Costin Carabas, Jordan Beichler, Rzvan Deaconescu, and William Enck. “Kobold: Evaluating decentralized access control for remote nsxpc methods on iOS.” In 2020 IEEE Symposium on Security and Privacy (SP… [cited by examiner]
Chow. Chapter 7. Solutions to the Problem. The Death of the Internet. First Edition, John Wiley & Sons. pp. 245-329, 2012. (Year: 2012). [cited by examiner]
Blue, Juanita, Eoghan Furey, and Joan Condell. “A novel approach for secure identity authentication in legacy database systems.” In 2017 28th Irish Signals and Systems Conference (ISSC), pp. 1-6. IEEE, 2017. (Year: 2017… [cited by examiner]
International Search Report PCT/US2023/21143 dated Oct. 10, 2023 (pp. 1-3). [cited by applicant]