Methods for fraud detection

US9590973B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9590973-B2
Application numberUS-201514710221-A
CountryUS
Kind codeB2
Filing dateMay 12, 2015
Priority dateDec 8, 2014
Publication dateMar 7, 2017
Grant dateMar 7, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Method and systems for validating a client user in a secured network are provided. Upon authentication, a user is supplied a login cookie that includes verification data. When requesting access to a secured resource, the verification data is compared to the data in the request to confirm that the requestor is a legitimate user and not a user who has stolen the login cookie.

First claim

Opening claim text (preview).

What is claimed is: 1. A computerized-method of validating a client user in a secured network, the method comprising: receiving, by a first server computing device, a first request from a client to login to a protected domain of the first server, the first request including user login credentials and a first set of verification data, the first set of verification data recorded by the client at the time the login credentials were entered; determining, by the first server computing device, whether the login credentials are recognized; transmitting, by the first server computing device, a first cookie to the client, the first cookie including the login credentials and a second set of verification data, the second set of verification is a subset or derived from the first set of verification data; transmitting, by the first server computing device, a second cookie to the client, the second cookie including a third set of verification data that is sufficient to confirm the first cookie; receiving, by a second server computing device, a request to gain access to a protected resource of the protected domain, the second request including the first cookie and a fourth set of verification data; determining, by the server computing device, whether the request was transmitted by the client associated with the first cookie based on the first cookie and the fourth set of verification data; wherein determining whether the request was transmitted by the client associated with the first cookie further comprises: determining, by the second server computing device, whether the first cookie passes a first level review; and if the first cookie does not pass a first level review, then: redirecting, by the second server computing device, the client to the first server computing device; detecting, by the first server computing device, the second cookie is received from the client; determining, by the first server computing device, whether the first cookie passes a second level review based on the first cookie and the second cookie; if the request was transmitted by the client associated with the first cookie, allowing access to the protected resource of the protected domain; and if the request was not transmitted by the client associated with the first cookie, denying access to the protected resource of the protected domain or redirect the user to reenter login credentials. 2. The computerized-method of claim 1 wherein determining whether the request was transmitted by the client associated with the first cookie further comprises: determining, by the second server computing device, whether a first IP address included in the second set of verification data in the cookie is equal to a second IP address included in the fourth set of verification data transmitted with the second request. 3. The computerized-method of claim 2 wherein determining whether the request was transmitted by the client associated with the first cookie further comprises: determining, by the first server computing device, a first value to include in the first cookie, the first value is determined by performing a cryptographic hash on the at least a portion of the second set of verification data; determining, by the second server, a second value, the second value is determined by performing a cryptographic hash on a subset of the fourth set of verification data, the subset of the fourth set of verification data based on fields present in the second set of verification data; and comparing, by the second server, the first value and the second value. 4. The computerized-method of claim 1 wherein the first level review comprises determining, by the first server computing device, whether a first location included in the second set of verification data is equal to a second location included in the fourth set of verification data. 5. The computerized-method of claim 4 wherein the first level review comprises determining, by the second server computing device, a time lapse between the second set of verification data and the fourth set of verification data. 6. The computerized-method of claim 1 wherein the second set of verification data is derived by performing a cryptographic hash on at least a portion of the first set of verification data. 7. The computerized-method of claim 1 wherein the fields to include from the first set of verification in the second set of verification data is specified in a file. 8. The computerized-method of claim 1 wherein the second set of verification data includes one or more of IP address, user agent, screen size, available fonts, and software version. 9. The computerized-method of claim 1 wherein the third set of verification data includes an encryption key and the first set of verification data encrypted with the encryption key. 10. The computerized-method of claim 1 wherein the fourth set of verification data is based on an indicator in the first cookie, the indicator specifies data fields that are present in the second set of verification data. 11. The computerized-method of claim 1 wherein the fourth set of verification data includes one or more of IP address, user agent, screen size, available fonts, and software version.

Assignees

Inventors

Classifications

  • service impersonation, e.g. phishing, pharming or web spoofing (detection of rogue wireless access points H04W12/12) · CPC title

  • providing single-sign-on or federations · CPC title

  • H04L63/08Primary

    for authentication of entities (cryptographic mechanisms or cryptographic arrangements for entity authentication H04L9/32) · CPC title

  • above the transport layer · CPC title

  • for controlling access to devices or network resources · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9590973B2 cover?
Method and systems for validating a client user in a secured network are provided. Upon authentication, a user is supplied a login cookie that includes verification data. When requesting access to a secured resource, the verification data is compared to the data in the request to confirm that the requestor is a legitimate user and not a user who has stolen the login cookie.
Who is the assignee on this patent?
Fmr Llc
What technology area does this patent fall under?
Primary CPC classification H04L63/0815. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Mar 07 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 2 related publications on this page (citations in our corpus or others sharing the same primary CPC).