Invention Grant
- Patent Title: Account hijacking counter-measures
- Patent Title (中): 帐号劫持对策
-
Application No.: US12365575Application Date: 2009-02-04
-
Publication No.: US08707407B2Publication Date: 2014-04-22
- Inventor: Richard S. Craddock , Krishna C. Vitaldevara
- Applicant: Richard S. Craddock , Krishna C. Vitaldevara
- Applicant Address: US WA Redmond
- Assignee: Microsoft Corporation
- Current Assignee: Microsoft Corporation
- Current Assignee Address: US WA Redmond
- Agent Bryan Webster; Sade Fashokun; Micky Minhas
- Main IPC: G06F7/04
- IPC: G06F7/04

Abstract:
A method for providing an additional layer of authentication prior to accessing a user's account even though the user's credentials have previously been verified. User accounts are often accessed via a sign-in page that verifies the user's credentials. Upon detecting a device accessing the sign-in page, an identifier associated with the device is obtained. One such type of identifier is the IP address assigned to the device. Based on the identifier, it is determined whether the device is trusted or not. Even thought the user's credentials are verified via the sign-in page, if the device is not trusted, a second authentication page is presented to the user prior to proceeding to the account. The second authentication page presents at least one security question. The security question is based on information contained in the user's account (e.g., contact information, event information, electronic messages, etc.). The user is required to correctly answer the security question in order to access the account.
Public/Granted literature
- US20100199338A1 ACCOUNT HIJACKING COUNTER-MEASURES Public/Granted day:2010-08-05
Information query