IP Library Granted Patent US 9,832,192
Granted Patent B2
US 9,832,192 · App. 14/312,269 · Granted Nov 28, 2017

Computer implemented method to prevent attacks against authorization systems and computer programs products thereof

Inventors: Jose Maria Alonso Cebrian (Madrid, ES); David Barroso Berrueta (Madrid, ES); Jose Maria Palazon Romero (Madrid, ES); Antonio Guzman Sacristan (Madrid, ES)
Assignee: TELEFONICA DIGITAL ESPANA, S.L.U.
H04L63/0869H04L63/08H04L63/0838
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,832,192
App. No.
14/312,269
Granted
Nov 28, 2017
Kind
B2
Abstract

A computer implemented method and computer program products to prevent attacks against authorization systems The computer implemented method comprising controlling the access to different resources and actions defined for a user by a first server, reducing the exposure time at which such operations are available and establishing a dual channel verification through the use of a second server. The computer programs implement the method.

Claims (54)

1. A computer implemented method to prevent attacks against authorization systems, the method comprising:

receiving from at least a first server a request from a first user in a name of a second user to be logged into a service of the first server, the first user being different from the second user;

authorizing the request, by the first server, by verifying user identification information of the first user; and

notifying, by a second server, the second user in response to the request to be logged into the service of the first server being rejected,

wherein the authorizing the request, by the first server, comprises:

sending, by the first server to the second server in connection with a user computing device with a dedicated program, a request about a status associated with the second user;

initializing a credential exchange between the first server and the second server to provide mutual authentication;

verifying the associated status that has been previously set as valid or as invalid by the second user and stored in a memory of the second server;

sending, by the second server, the associated status to the first server; and

using, by the first server, the received associated status to:

authorize the request from the first user in the name of the second user in response to the associated status being set as valid, or

reject the request in response to the associated status being set as invalid, and

wherein, in response to the request to be logged into the service of the first server being authorized and the request from the first user being in the name of the second user to perform an operation in the first server using at least a part of resources of the first server:

performing an operation status verification associated with the second user comprising matching the operation with a scheme entry and sending a status request to the second server;

receiving, by the second server from the first server, the status request about an operation status associated with the second user concerning the scheme entry;

initializing a credential exchange between the first server and the second server;

evaluating, by the second server, a scheme entry status from a root to the entry;

sending, by the second server, an evaluation result to the first server; and

making a decision, by the first server, by at least using the received result to allow or block the request from the first user in the name of the second user to perform the operation.

2. The computer implemented method according to claim 1 , wherein the notifying comprises one of a sending of a Short Message Service (SMS), a sending of an email, a sending of a message by a smartphone messenger application, or a highlighting or pushing in the dedicated program of the user computing device.

3. The computer implemented method according to claim 1 , wherein the associated status is set as valid or as invalid for a predefined period of time.

4. The computer implemented method according to claim 1 , wherein a second factor authentication is used within an answer of the scheme entry status in response to the scheme entry status being set as valid.

5. The computer implemented method according to claim 4 , wherein the second factor authentication comprises:

sending, by the second server to the first server ( 300 ), a one-time password (OTP);

requesting, by the first server from the first user, an OTP that the first user will use as a temporal second factor;

recovering, by the first user, the requested temporal second factor OTP through the dedicated program and further sending the temporal second factor OTP to the first server; and

checking, by the first server, if the received OTP from the second server and the received temporal second factor OTP from the first user match in order to authorize or reject the request from the first user for the service in the name of the second user.

6. The computer implemented method according to claim 5 , wherein the first server is configured to allow the operation in response to the received OTP from the second server and the received temporal second factor OTP from the first user matching and block the operation in response to the received OTP from the second server and the received temporal second factor OTP from the first user not matching.

7. The computer implemented method according to claim 1 , wherein the evaluating is performed at each level in a hierarchy, from the root to the scheme entry.

8. The computer implemented method according to claim 1 , wherein the request to be logged into the service and/or the request to perform the operation are recorded in order to provide statistics.

9. A non-transitory computer readable medium storing a program causing a computer to execute a method for preventing attacks against authorization systems, the method comprising:

receiving from at least a first server a request from a first user in a name of a second user to be logged into a service of the first server, the first user being different than the second user;

authorizing the request, by the first server, by verifying user identification information of the first user; and

notifying, by a second server, the second user in response to the request to be logged into the service of the first server being rejected,

wherein the authorizing the request, by the first server, comprises:

sending, by the first server to the second server in connection with a user computing device with a dedicated program, a request about a status associated with the second user;

initializing a credential exchange between the first server and the second server to provide mutual authentication;

verifying the associated status that has been previously set as valid or as invalid by the second user and stored in a memory of the second server;

sending, by the second server, the associated status to the first server; and

using, by the first server, the received associated status to:

authorize the request from the first user in the name of the second user in response to the associated status being set as valid, or

reject the request in response to the associated status being set as invalid, and

wherein, in response to the request to be logged into the service of the first server being authorized and the request from the first user being in the name of the second user to perform an operation in the first server using at least a part of resources of the first server:

performing an operation status verification associated with the second user comprising matching the operation with a scheme entry and sending a status request to the second server;

receiving, by the second server from the first server, the status request about an operation status associated with the second user concerning the scheme entry;

initializing a credential exchange between the first server and the second server;

evaluating, by the second server, a scheme entry status from a root to the entry;

sending, by the second server, an evaluation result to the first server; and

making a decision, by the first server, by at least using the received result to allow or block the request from the first user in the name of the second user to perform the operation.

10. The non-transitory computer readable medium according to claim 9 , further comprising performing a second factor authentication wherein the second factor authentication comprises:

sending, by the second server to the first server, a one-time password (OTP);

requesting, by the first server from the first user, an OTP that the first user will use as a temporal second factor;

recovering, by the first user, the requested temporal second factor OTP through the dedicated program and further sending the temporal second factor OTP to the first server; and

checking, by the first server, if the received OTP from the second server and the received temporal second factor OTP from the first user match in order to authorize or reject the request from the first user for the service in the name of the second user.

Assignments (4)
CHANGE OF NAME Recorded Jun 21, 2024
From: TELEFONICA DIGITAL ESPAÑA SL
To: TELEFONICA INNOVACION DIGITAL SL
Reel/Frame 067807/0092 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 12, 2022
From: TELEFONICA CYBERSECURITY TECH S.L.
To: TELEFÓNICA DIGITAL ESPAÑA, S.L.U.
Reel/Frame 061393/0176 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 22, 2021
From: TELEFONICA DIGITAL ESPANA, S.L.U.
To: TELEFONICA CYBERSECURITY TECH S.L.
Reel/Frame 055674/0377 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 7, 2016
From: ALONSO CEBRIAN, JOSE MARIA; BARROSO BERRUETA, DAVID; PALAZON ROMERO, JOSE MARIA; GUZMAN SACRISTAN, ANTONIO
To: TELEFONICA DIGITAL ESPANA, S.L.U.
Reel/Frame 037433/0434 →
Continuity (1)
Related Publication 20140380431A1 · Dec 25, 2014