Verification of credential reset

US11228599B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11228599-B2
Application numberUS-201916684502-A
CountryUS
Kind codeB2
Filing dateNov 14, 2019
Priority dateDec 15, 2015
Publication dateJan 18, 2022
Grant dateJan 18, 2022

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Methods and systems are provided for restoring access for user accounts when suspicious activity is detected. The methods and systems identify any potential suspicious activity or potential misuse associated with a user account. The user account has account privileges associated with a network service. The methods and systems sends a notification to a network application to indicate that account privileges associated with the user account are limited. In response to the notification, a series of tasks to restore access to the user account may be performed.

First claim

Opening claim text (preview).

What is claimed is: 1. A non-transitory computer-readable storage medium having stored thereon executable instructions that, as a result of execution by one or more processors of a computer system, cause the computer system to at least: provision a service for a user associated with a user account with account privileges to post items for sale; receive a request from a second user to use the service; detect that the second user is suspected to use the service to perform fraudulent activity, wherein the fraudulent activity includes posting a false item for sale; limit access to the account privileges based at least in part on the detection; cause a notification associated with the request to be presented by a network application that is different from an application from which the request was issued, wherein the notification indicates that the account privileges associated with the user account is limited; receive information to verify authenticity of the user in response to the notification; cause a second notification to be presented by the network application, wherein the second notification indicates that the authenticity of the user has been verified; and restore access to the account privileges as a result of verifying the authenticity of the user. 2. The non-transitory computer-readable storage medium of claim 1 , wherein the network application is an e-mail service and the notification is an e-mail message. 3. The non-transitory computer-readable storage medium of claim 1 , wherein the fraudulent activity further includes posting false account information. 4. The non-transitory computer-readable storage medium of claim 1 , wherein limiting access to the account privileges includes denying access to financial transactions associated with the account privileges. 5. The non-transitory computer-readable storage medium of claim 1 , wherein restoring access to the account privileges as a result of verifying the authenticity of the user includes enabling an administrator to unlock the user account. 6. The non-transitory computer-readable storage medium of claim 1 , the notification further indicates a series of tasks for the user to complete to verify authenticity of the user prior to removing the limitation on the account privileges. 7. A computer-implemented method, comprising: under the control of one or more computer systems configured with executable instructions, detecting activities that are being performed on a service without permission from a user, wherein the user is associated with a user account with account privileges; restricting access to the account privileges based at least in part on the detection; causing a notification to be presented by a network application that is different from the service from which activities were performed, wherein the notification indicates that the account privileges associated with the user account is restricted; receiving information to verify authenticity of the user in response to the notification; causing a second notification to be presented by the network application, wherein the second notification indicates that the authenticity of the user has been verified; and restoring access to the account privileges as a result of verifying the authenticity of the user. 8. The method of claim 7 , wherein the detected activities further include using the service to post false items for sale or false account information of the user. 9. The method of claim 7 , wherein the detected activities are performed by a third-party user impersonating the user. 10. The method of claim 7 , wherein the network application is an e-mail service that is associated with an email account accessible by the user. 11. The method of claim 7 , wherein information received includes documents indicating authenticity of the user. 12. The method of claim 7 , wherein restoring access to the account privileges as a result of verifying the authenticity of the user includes enabling an administrator to unlock the user account. 13. The method of claim 7 , wherein restricting access to the account privileges includes denying a portion of the account privileges for use by the user. 14. A system, comprising: at least one processor; and a memory coupled to the at least one processor, wherein the memory stores program instructions, wherein the program instructions are executable by the at least one processor to: detect suspicious activity being performed, using a first network application, that is associated with a user account having account privileges; limit access to account privileges associated with the user account; send a notification to a second network application associated with the user account to indicate that access to account privileges associated with the user account are limited, wherein the second network application is a different application than the first network application; and limit access to the account privileges until receipt of information that verifies authenticity of the user account in response to the notification. 15. The system of claim 14 , wherein the program instructions are further executable to: review the information that verifies authenticity of the user account; and send a second notification to the second network application to request additional information to verify authenticity of the user account. 16. The system of claim 14 , wherein the program instructions are further executable to remove limitations associated with accessing the account privileges after receipt of information that verifies authenticity of the user account. 17. The system of claim 14 , wherein the first network application is an e-commerce website and the second network application is an e-mail service. 18. The system of claim 17 , wherein the second network application is a trusted access point previously indicated by the user account to be secure. 19. The system of claim 14 , wherein suspicious activity comprises using the first network application to post false items for sale or false account information associated with the user account. 20. The system of claim 14 , wherein limiting access to account privileges associated with the user account includes denying requests associated with financial transactions from the user account.

Assignees

Inventors

Classifications

  • Tracking the activity of the user (network monitoring arrangements H04L43/00; recording of computer activity G06F11/34) · CPC title

  • User authentication · CPC title

  • H04L63/102Primary

    Entity profiles · CPC title

  • using passwords (cryptographic mechanisms or cryptographic arrangements for entity authentication using a predetermined code H04L9/3226) · CPC title

  • Electricity · mapped topic

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11228599B2 cover?
Methods and systems are provided for restoring access for user accounts when suspicious activity is detected. The methods and systems identify any potential suspicious activity or potential misuse associated with a user account. The user account has account privileges associated with a network service. The methods and systems sends a notification to a network application to indicate that accoun…
Who is the assignee on this patent?
Amazon Tech Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/102. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jan 18 2022 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 7 related publications on this page (citations in our corpus or others sharing the same primary CPC).