System and methods for protecting users from malicious content

US10257209B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10257209-B2
Application numberUS-201615012309-A
CountryUS
Kind codeB2
Filing dateFeb 1, 2016
Priority dateJan 21, 2011
Publication dateApr 9, 2019
Grant dateApr 9, 2019

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method, system and device for allowing the secure collection of sensitive information is provided. The device includes a display, and a user interface capable of receiving at least one user-generated interrupt in response to a stimulus generated in response to content received by the device, wherein the action taken upon receiving the user-generated interrupt depends on a classification of the content, the classification identifying the content as trusted or not trusted. The method includes detecting a request for sensitive information in content, determining if an interrupt is generated, determining if the content is trusted, allowing the collection of the sensitive information if the interrupt is generated and the content is trusted, and performing an alternative action if the interrupt is generated and the content is not trusted. The method may include instructions stored on a computer readable medium.

First claim

Opening claim text (preview).

We claim: 1. A mobile device system, comprising: a display component; a non-transitory memory storing instructions; and one or more hardware processors coupled to the non-transitory memory and configured to read the instructions to cause the mobile device system to perform operations comprising: generating a login screen on the display component, wherein the login screen comprises viewable content; determining a user input received by the mobile device system, wherein the user input corresponds to an indication of trust associated with the viewable content of the login screen; generating one or more system interrupts associated with the login screen based at least on the indication of trust; and terminating, while the mobile device system remains turned on, a rendering of the viewable content of the login screen and performing one or more actions based at least on the one or more system interrupts, wherein the performing the one or more actions comprises: causing the mobile device system to execute trusted software instructions; or electronically scanning for malicious code within the mobile device system. 2. The mobile device system of claim 1 , wherein the login screen generated on the display component comprises a login screen for a username and a password. 3. The mobile device system of claim 1 , wherein the display component comprises a capacitive sensor, wherein the user input received comprises a touch input detected by the capacitive sensor, and wherein the touch input specifies the indication of trust associated with the viewable content of the login screen. 4. The mobile device system of claim 1 , wherein the indication of trust comprises an indication that the viewable content of the login screen is non-functional, wherein the one or more system interrupts comprises a software interrupt that prevents the login screen from receiving a username and a password. 5. The mobile device system of claim 4 , wherein the login screen generated on the display component resembles a trusted login screen provided by a trusted source, and wherein performing the one or more actions further comprises reporting a notification to the trusted source comprising information associated with the login screen generated on the display component. 6. The mobile device system of claim 4 , wherein performing the one or more actions further comprises: determining one or more untrusted sources associated with the login screen generated on the display component; and maintaining a database that identifies the one or more untrusted sources to prevent the mobile device system from accessing information from the one or more untrusted sources. 7. A non-transitory machine-readable medium having stored thereon machine-readable instructions executable to cause a machine to perform operations comprising: displaying a login screen on a display component of a mobile device, wherein the login screen comprises viewable content; determining a user input received by the mobile device, wherein the user input corresponds to an indication of trust associated with the viewable content of the login screen; generating one or more system interrupts with the login screen based at least on the indication of trust; and terminating, without turning off the mobile device, the displaying of the login screen and performing one or more actions based at least on the one or more system interrupts, wherein the performing the one or more actions comprises: causing the mobile device to execute trusted software instructions; or electronically scanning for malicious code within the mobile device. 8. The non-transitory machine-readable medium of claim 7 , wherein the login screen comprises one or more editable fields configured to receive a username and a password. 9. The non-transitory machine-readable medium of claim 7 , wherein the mobile device comprises an accelerometer, wherein the user input received comprises one or more mobile device movements detected by the accelerometer, and wherein the one or more mobile device movements specifies the indication of trust associated with the viewable content of the login screen. 10. The non-transitory machine-readable medium of claim 7 , wherein the indication of trust comprises an indication that the viewable content of the login screen is malfunctioning, wherein the one or more system interrupts comprises a hardware interrupt of the mobile device that prevents the display component from receiving user information. 11. The non-transitory machine-readable medium of claim 10 , wherein the login screen generated on the display component resembles a trusted login screen provided by a trusted source, and wherein performing the one or more actions further comprises reporting a notification to the trusted source comprising information associated with the login screen generated on the display component. 12. The non-transitory machine-readable medium of claim 10 , wherein performing the one or more actions further comprises: determining one or more untrusted sources associated with the login screen generated on the display component; and maintaining a database of the one or more untrusted sources to prevent the mobile device from accessing information from the one or more untrusted sources. 13. A machine-implemented method, comprising: generating a login screen on a touch screen of a mobile device, wherein the login screen comprises viewable content; determining a user input received by the mobile device, wherein the user input corresponds to an indication of trust associated with the viewable content of the login screen; generating one or more system interrupts with the login screen based at least on the indication of trust; and terminating, without shutting down the mobile device, a display of the viewable content of the login screen and performing one or more actions based at least on the one or more system interrupts, wherein the performing the one or more actions comprises: causing the mobile device to execute trusted software instructions; or electronically scanning for malicious code within the mobile device. 14. The machine-implemented method of claim 13 , wherein the touch screen comprises a plurality of touch sensors, wherein the user input received comprises a touch input detected by the plurality of touch sensors, and wherein the touch input specifies the indication of trust associated with the viewable content of the login screen. 15. The machine-implemented method of claim 13 , wherein the indication of trust comprises an indication that the viewable content of the login screen is non-functional, wherein the one or more system interrupts comprises a software interrupt of the mobile device that prevents the login screen from receiving a username and a password. 16. The machine-implemented method of claim 13 , wherein the indication of trust comprises an indication that one or more of the viewable content of the login screen are functional, and wherein the one or more system interrupts comprises an interrupt of the mobile device to determine the login screen is associated with one or more trusted sources. 17. The machine-implemented method of claim 16 , wherein performing the one or more actions further comprises determining an action that enables the login screen to receive a username and a password based at least on the one or more trusted sources determined. 18. The mobile device system of claim 1 , wherein the operations further comprise identifying the trusted software instructions using one or more digital certificates.

Assignees

Inventors

Classifications

  • input devices, e.g. keyboards, mice or controllers thereof · CPC title

  • H04L63/123Primary

    received data contents, e.g. message integrity · CPC title

  • using interrupt (G06F13/32 takes precedence) · CPC title

  • Authenticating web pages, e.g. with suspicious links · CPC title

  • using passwords (cryptographic mechanisms or cryptographic arrangements for entity authentication using a predetermined code H04L9/3226) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10257209B2 cover?
A method, system and device for allowing the secure collection of sensitive information is provided. The device includes a display, and a user interface capable of receiving at least one user-generated interrupt in response to a stimulus generated in response to content received by the device, wherein the action taken upon receiving the user-generated interrupt depends on a classification of th…
Who is the assignee on this patent?
Paypal Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/123. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Apr 09 2019 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).