US2022343017A1PendingUtilityA1

Provision of risk information associated with compromised accounts

Assignee: APPBUGS INCPriority: Dec 21, 2016Filed: Jul 5, 2022Published: Oct 27, 2022
Est. expiryDec 21, 2036(~10.4 yrs left)· nominal 20-yr term from priority
Inventors:Rui Wang
G06F 21/6254G06Q 50/265H04L 63/1433H04L 9/3226H04L 63/083H04L 9/3234G06F 21/6245G06Q 2220/10H04L 9/3236G06F 21/577
67
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Processes and systems described herein enable a computing device to detect compromised accounts. The computing device may obtain a user credential including a user ID, and further modify the user ID. The computing device may transmit the modified user ID to a service including a database related to compromised accounts, receive a record corresponding to the modified user ID that includes information of a compromised account, and further determine whether an account of the user ID is compromised based on the received record. Some implementations relate to the on-site provision of risk information associated with compromised accounts.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method for provision of risk information associated with user accounts, the method comprising:
 modifying, by one or more processors of a computing system, a password associated with a user account using a predetermined method to obtain a modified password;   transmitting, by the one or more processors of the computing system, the modified password to a computing device of a service provider;   receiving, by one or more processors of the computing device, the modified password;   modifying, by the one or more processors of the computing device, multiple passwords using the predetermined method, the multiple passwords associated with multiple compromised accounts;   identifying, by one or more processors of the computing device from the multiple passwords, one password corresponding to the modified password;   transmitting, by one or more processors of the computing device to the computing system, information of the one password;   receiving, by the one or more processors of the computing system, the information the one password; and   determining, by the one or more processors of the computing system, that the user password is compromised if the one password and the password are identical.   
     
     
         2 . The method of  claim 1 , wherein the modifying the password using the predetermined method to obtain the modified password comprises:
 performing a hash operation on the password using a predetermined hash algorithm to obtain a hashed password; and   anonymizing the hashed password by obscuring a portion of the hashed password to obtain the modified password.   
     
     
         3 . The method of  claim 2 , wherein the password comprises a string comprising multiple characters, and the obscuring a portion of the hashed password to obtain the modified password comprise hiding one or more characters of the multiple characters. 
     
     
         4 . The method of  claim 2 , wherein the modifying the multiple passwords using the predetermined method comprises:
 performing the hash operation on the multiple passwords using the predetermined hash algorithm to obtain multiple hashed password.   
     
     
         5 . The method of  claim 4 , wherein the identifying one password corresponding to the modified password comprises:
 identifying one hashed password from the multiple hashed password, the hashed password obtained by performing the hash operation on the one password using the predetermined, the one hashed password matching a pattern of an unobscured portion of the hashed password.   
     
     
         6 . The method of  claim 2 , wherein the predetermined hash algorithm is MDS, SHA1, or SHA256. 
     
     
         7 . The method of  claim 1 , wherein the password is a password in plain text. 
     
     
         8 . The method of  claim 1 , wherein the modifying the password using a predetermined method to obtain the modified password comprises:
 encrypting the password using a predetermined encryption key to obtain an encrypted password; and   anonymizing the encrypted password by obscuring a portion of the encrypted password to obtain the modified password.   
     
     
         9 . The method of  claim 2 , wherein the modifying the multiple passwords using the predetermined method comprises:
 encrypting the multiple passwords using the predetermined encryption key to obtain multiple encrypted password.   
     
     
         10 . The method of  claim 8 , wherein an encryption associated with the predetermined encryption key is AES or 3DES. 
     
     
         11 . A computer-readable hardware storage memory comprising stored instructions that are executable and, responsive to executing the instructions, a computing device:
 modifying a password associated with a user account using a predetermined method to obtain a modified password;   transmitting the modified password to a computing device of a service provider;   receiving, from the computing device, information one password, the information indicating a match between the modified password and one modified password obtained by modifying the one password using the predetermined method; and   determining that the user password is compromised if the one password and the password are identical.   
     
     
         12 . The computer-readable hardware storage memory of  claim 1 ,
 wherein the modifying the password using the predetermined method to obtain the modified password comprises:   performing a hash operation on the password using a predetermined hash algorithm to obtain a hashed password; and   anonymizing the hashed password by obscuring a portion of the hashed password to obtain the modified password.   
     
     
         13 . The computer-readable hardware storage memory of  claim 12 , wherein the password comprises a string comprising multiple characters, and the obscuring a portion of the hashed password to obtain the modified password comprise hiding one or more characters of the multiple characters. 
     
     
         14 . The computer-readable hardware storage memory of  claim 12 , wherein the predetermined hash algorithm is MDS, SHA1, or SHA256. 
     
     
         15 . A computer-readable hardware storage memory comprising stored instructions that are executable and, responsive to executing the instructions, a computing device:
 receiving a modified password associated with a user account, the modified password generated by modifying a password using a predetermined method;   modifying multiple passwords using the predetermined method, the multiple passwords associated with multiple compromised accounts;   identifying one password corresponding to the modified password;   transmitting to the computing system information of the one password to cause the computing system to determine that the user password is compromised if the one password and the password are identical.   
     
     
         16 . The computer-readable hardware storage memory of  claim 15 , wherein the modifying the password using the predetermined method comprises:
 performing a hash operation on the password using a predetermined hash algorithm to obtain a hashed password; and   anonymizing the hashed password by obscuring a portion of the hashed password to obtain the modified password.   
     
     
         17 . The computer-readable hardware storage memory of  claim 15 , wherein the password comprises a string comprising multiple characters, and the obscuring a portion of the hashed password to obtain the modified password comprise hiding one or more characters of the multiple characters. 
     
     
         18 . The computer-readable hardware storage memory of  claim 15 , wherein the modifying the multiple passwords using the predetermined method comprises:
 performing the hash operation on the multiple passwords using the predetermined hash algorithm to obtain multiple hashed password.   
     
     
         19 . The computer-readable hardware storage memory of  claim 18 , wherein the identifying one password corresponding to the modified password comprises:
 identifying one hashed password from the multiple hashed password, the hashed password obtained by performing the hash operation on the one password using the predetermined, the one hashed password matching a pattern of an unobscured portion of the hashed password.   
     
     
         20 . The computer-readable hardware storage memory of  claim 15 , wherein the predetermined hash algorithm is MD5, SHA1, or SHA256.

Join the waitlist — get patent alerts

Track US2022343017A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.