System and methods for protecting users from malicious content

US9286449B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9286449-B2
Application numberUS-201113339275-A
CountryUS
Kind codeB2
Filing dateDec 28, 2011
Priority dateJan 21, 2011
Publication dateMar 15, 2016
Grant dateMar 15, 2016

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method, system and device for allowing the secure collection of sensitive information is provided. The device includes a display, and a user interface capable of receiving at least one user-generated interrupt in response to a stimulus generated in response to content received by the device, wherein the action taken upon receiving the user-generated interrupt depends on a classification of the content, the classification identifying the content as trusted or not trusted. The method includes detecting a request for sensitive information in content, determining if an interrupt is generated, determining if the content is trusted, allowing the collection of the sensitive information if the interrupt is generated and the content is trusted, and performing an alternative action if the interrupt is generated and the content is not trusted. The method may include instructions stored on a computer readable medium.

First claim

Opening claim text (preview).

What is claimed is: 1. A device comprising: a display; a network interface component configured to receive content; a user interface that receives at least one user-generated device interrupt in response to a stimulus generated in response to the received content; and at least one processor that: in response to receiving content from a webpage, classifies the content as trusted or not trusted and determines that the webpage has a login screen; in response to determining that the webpage has a login screen, displays a request for the at least one user-generated interrupt on the display; receives the at least one user-generated interrupt; displays the login screen in response to receiving the at least one-user generated interrupt when the content is classified as trusted; and terminates the webpage and prevents the display of the login screen in response to receiving the at least one user-generated interrupt when the content is classified as not trusted. 2. The device of claim 1 , wherein the classification comprises at least one of a whitelist and a blacklist. 3. The device of claim 2 , wherein the at least one whitelist and blacklist is dynamically generated. 4. The device of claim 1 , wherein the classification comprises at least one of rule-based or anomaly-based classification. 5. The device of claim 1 , wherein the at least one user-generated device interrupt comprises at least one of a button press, a button-combination press, a power cycling, a shake of the device, and a touch detected on the device. 6. The device of claim 1 , wherein the the at least one processor activates a password manager in response to receiving the at least one user-generated interrupt when the content is classified as trusted. 7. The device of claim 1 , further comprising: a memory, wherein the memory stores one or more sets of instructions for execution by the at least one processor. 8. The device of claim 1 , wherein when the device does not receive the user-generated interrupt and the content is classified to be on the whitelist, an alert is displayed on the display. 9. A non-transitory computer-readable medium having instructions for execution by a processor that, when executed, cause the processor of a device to perform a method for collecting sensitive information, the method comprising: receiving content from a website; determining whether the content is trusted or not trusted and whether the content is requesting a login; in response to determining the content is requesting a login, requesting a user-generated device interrupt; determining when a user-generated device interrupt is generated; in response to the generated user-generated device interrupt, allowing the request for the login from the content when the content is determined as trusted; in response to the generated user-generated device interrupt, preventing the request for login from the content when the content is determined as not trusted and terminating the webpage. 10. The method of claim 9 , further comprising: generating an alert if the content is trusted and the device interrupt is not generated. 11. The method of claim 9 , wherein determining if the content is trusted comprises determining if the content is on a whitelist. 12. The method of claim 9 , wherein determining if the content is trusted comprises determining if the content is on a blacklist. 13. The method of claim 9 , further comprising: generating a user stimulus, wherein generating a user stimulus comprises displaying a login screen. 14. The method of claim 9 , wherein determining if a user-generated device interrupt is generated comprises determining if a user engages an interrupt mechanism on the device. 15. The method of claim 14 , wherein the interrupt mechanism comprises at least one of a mechanical button, a combination of mechanical buttons, a capacitive sensor detecting a touch, and an accelerometer detecting a particular motion. 16. The method of claim 9 , wherein the sensitive information comprises personally identifiable information. 17. The method of claim 9 , wherein collecting sensitive information comprises performing a biometric identity reading. 18. The method of claim 9 , further comprising scanning for keyloggers and viruses if the device interrupt is generated. 19. The method of claim 9 , further comprising enabling the use of a password manager if the device interrupt is generated. 20. The method of claim 9 , further comprising: detecting a request for sensitive information in the content.

Assignees

Inventors

Classifications

  • G06F21/31Primary

    User authentication · CPC title

  • input devices, e.g. keyboards, mice or controllers thereof · CPC title

  • Authenticating web pages, e.g. with suspicious links · CPC title

  • using interrupt (G06F13/32 takes precedence) · CPC title

  • H04L63/123Primary

    received data contents, e.g. message integrity · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9286449B2 cover?
A method, system and device for allowing the secure collection of sensitive information is provided. The device includes a display, and a user interface capable of receiving at least one user-generated interrupt in response to a stimulus generated in response to content received by the device, wherein the action taken upon receiving the user-generated interrupt depends on a classification of th…
Who is the assignee on this patent?
Jakobsson Bjorn Markus, Leddy William, Paypal Inc
What technology area does this patent fall under?
Primary CPC classification G06F21/31. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Mar 15 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).