Social authentication for account recovery

US10013728B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10013728-B2
Application numberUS-201414326377-A
CountryUS
Kind codeB2
Filing dateJul 8, 2014
Priority dateMay 14, 2009
Publication dateJul 3, 2018
Grant dateJul 3, 2018

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A backup account recovery authentication of last resort using social authentication is described. The account holder requests trustees who have been previously identified to obtain an account recovery code. The account recovery system sends a communication to the trustee for information to verify the trustee as one of the previously identified trustees. The account recovery system then may transmit a link and code with instructions for the trustee to return the link. The account recovery system then transmits a situational query to the trustee to provide additional security. Finally, if all the communications have been completed for the required level of security, the account recovery code is transmitted to the trustee. The trustee sends the account recovery code to the account holder for access to an account.

First claim

Opening claim text (preview).

The invention claimed is: 1. One or more computer-readable storage devices storing computer-executable instructions that, when executed, configure a computer to perform acts comprising: receiving, from an account holder of an account with a remote service, identification of a plurality of entities as trustees for an account recovery process for recovering access to the account with the remote service; subsequent to the initiation of the account recovery process, transmitting, by one or more devices associated with the remote service, a respective account recovery code to each of the plurality of entities identified as trustees for the account, the respective account recovery codes being distinct from one another; receiving, by the one or more devices associated with the remote service, at least a predefined number of distinct account recovery codes from the account holder over a network; verifying, by the one or more devices associated with the remote service, the account holder at least in part in response to the receiving of at least the predefined number of distinct account recovery codes of the account recovery codes from the account holder; and providing account recovery information to the account holder based at least in part on the verifying the account holder. 2. The one or more computer-readable storage devices of claim 1 , further comprising, receiving a code to authenticate at least one of the trustees and checking the code against a database record created to track the at least one of the trustees. 3. The one or more computer-readable storage devices of claim 1 , wherein each of the account recovery codes is transmitted to a pre-identified contact destination, which includes at least one of the following: telephone; e-mail; or text message. 4. A method, comprising: under control of one or more processors of one or more devices associated with a service, receiving, from an account holder of an account with the service, a designation of a plurality of trustees as trustees for an account recovery process; receiving, by the one or more devices associated with the service, a request from at least one trustee of the plurality of trustees for an account recovery code, the account recovery code for use by the account holder in conjunction with one or more other account recovery codes sent to other trustees of the plurality of trustees during the account recovery process, sending, to the at least one trustee, by the one or more devices associated with the service, the account recovery code. 5. The method of claim 4 , wherein the account further comprises initial access information for accessing the account and the account recovery process does not recover the initial access information. 6. The method of claim 4 , further comprising, prior to sending the account recovery code, transmitting a query to the at least one trustee, the query related to a manner in which the account holder requested the at least one trustee to obtain the respective account recovery code, and sending a warning message to the at least one trustee to enhance security based at least in part on an answer provided in response to the query. 7. The method of claim 4 , further comprising, prior to sending the account recovery code, transmitting, to the at least one trustee, a query; and transmitting, to the at least one trustee, a warning message based at least in part on an answer provided in response to the query, the warning message providing the at least one trustee with information to assist at least in part in determining whether or not to proceed with the acquisition of the account recovery code. 8. The method of claim 4 , further comprising receiving, from the account holder a request to abort the acquisition of the remaining account recovery codes if the account holder discovers an unauthorized attempt to obtain a first account recovery code before all of the account recovery codes have been received. 9. The method of claim 6 , further comprising receiving, from the at least one trustee, an electronic signature indicating that the trustee decides to proceed with the acquisition of the account recovery code after receiving the warning message, the electronic signature providing authorization to proceed. 10. The method of claim 6 , further comprising receiving, from the at least one trustee, a request to abort the acquisition of the account recovery code indicating that the at least one trustee decides not to proceed with the acquisition of the account recovery code after receiving the warning message. 11. The method of claim 6 , further comprising: subsequent to sending the warning, determining a probability that the at least one trustee is operating on behalf of the account holder; and using a processor of the one or more devices associated with the service executing processor-executable instructions to determine whether to send the respective account recovery code to the trustee based at least in part on the determined probability. 12. A system, comprising: under control of one or more processors of one or more devices associated with a first entity configured with specific executable instructions, receiving, from an account holder of an account with the first entity, identification of a plurality of second entities as trustees for an account recovery process; receiving a request to initiate the account recovery process; subsequent to the initiation of the account recovery process, transmitting, by the one or more devices associated with the first entity, a respective account recovery code to at least two of the plurality of second entities identified as trustees for the account; receiving, from the account holder, at least a predefined number of distinct account recovery codes of the account recovery codes; and verifying, by the one or more devices associated with the first entity, the account holder at least in part in response to the receiving of at least the predefined number of distinct account recovery codes of the account recovery codes from the account holder. 13. The system of claim 12 , wherein verifying the account holder based at least in part on receipt of at least the predefined number of the distinct account recovery codes from the account holder comprises receiving at least three of the distinct account recovery codes from the account holder, each of the at least three account recovery codes having been transmitted to a respective one of at least three separate trustees for the account. 14. The system of claim 12 , wherein receiving, from the account holder of the account, identification of the plurality of second entities as trustees for the account recovery process comprises receiving identification of at least three second entities as trustees for the account recovery process. 15. The system of claim 12 , further comprising transmitting a notification with the account recovery codes that the trustees are to deliver the account recovery codes to the account holder by using one or more specified communication mediums, at least one of the one or more specified communication mediums including at least a telephone call. 16. The system of claim 12 , further comprising transmitting a notification with the account recovery codes that the trustees are not to deliver the account recovery codes to the account holder by using one or more specified communication mediums, the one or more specified communication mediums including at least electronic mail. 17. The system of claim 12 , further comprising, during the account recovery process, receiving a request from each of at

Assignees

Inventors

Classifications

  • Information retrieval; Database structures therefor; File system structures therefor · CPC title

  • Lost password, e.g. recovery of lost or forgotten passwords · CPC title

  • User authentication · CPC title

  • where a single sign-on provides access to a plurality of computers · CPC title

  • involving a third party or a trusted authority · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10013728B2 cover?
A backup account recovery authentication of last resort using social authentication is described. The account holder requests trustees who have been previously identified to obtain an account recovery code. The account recovery system sends a communication to the trustee for information to verify the trustee as one of the previously identified trustees. The account recovery system then may tran…
Who is the assignee on this patent?
Microsoft Technology Licensing Llc
What technology area does this patent fall under?
Primary CPC classification G06Q50/265. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Jul 03 2018 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).