Customer notification program alerting customer-specified network address of unauthorized access attempts to customer account
Abstract
A network security system includes a server configured to receive an access request via a network from a remote computing device, a database storing customer account information accessible by the server, and memory accessible by the server and storing a customer notification program. When executed by the server, the program identifies the remote computing device by a device fingerprint and requesting location, determines whether the device fingerprint matches any authorized device fingerprints stored in the database, and sends, responsive to a mismatch between the device fingerprint and the authorized device fingerprints, a notification of the request to a customer-specified address. The notification indicates the request, the identity of the remote computing device, and the requesting location. The program may resolve the request responsive to a reply to the notification from the customer-specified address.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A system for authorizing a request for remote access to customer account information, comprising:
a server configured to receive the request via a network from a remote computing device; a database storing the customer account information accessible by the server; and memory accessible by the server and storing a customer notification program which, when executed by the server, performs steps for
(a) identifying, responsive to the server receiving the request, the remote computing device by a device fingerprint and by a requesting location;
(b) determining whether the device fingerprint matches any of a number of device fingerprints authorized to access the customer account information; and
(c) sending, responsive to determining a mismatch between the device fingerprint and each of the previously authorized device fingerprints, a notification of the request to a customer-specified address, the notification indicating (i) the request, (ii) identity of the remote computing device, and (iii) the requesting location.
2 . The system of claim 1 wherein the customer notification program when executed further performs a step for (d) resolving the request responsive to a reply to the notification.
3 . The system of claim 2 wherein the reply is received from the customer-specified address.
4 . The system of claim 2 wherein the customer notification program when executed further performs a step for (e) storing the device fingerprint and associating the device fingerprint with the customer account information.
5 . The system of claim 2 wherein the notification further interrogates for an answer approving or disapproving the request, and wherein the resolving step further comprises approving or disapproving the request according to the answer.
6 . The system of claim 5 further comprising storing, responsive to approving the request, the device fingerprint as an authorized device fingerprint.
7 . The system of claim 5 further comprising storing, responsive to disapproving the request, the device fingerprint as an unauthorized device fingerprint.
8 . The system of claim 5 wherein the notification interrogates by effecting display of selectable answers on a user interface.
9 . The system of claim 1 wherein the identifying step further comprises interrogating the remote computing device for user-configurable device parameters, and generating the device fingerprint using multiple user-configurable device parameters.
10 . The system of claim 9 wherein the generated device fingerprint is unlike any other device fingerprint generatable responsive to a request to the server from another remote computing device.
11 . The system of claim 1 wherein the number of device fingerprints are stored in a second database accessible by the server.
12 . The system of claim 1 wherein the determining step further comprises determining whether the device fingerprint matches any of a number of unauthorized device fingerprints corresponding to a remote computing device previously disapproved from accessing the customer account information, and if a match to such an unauthorized device fingerprint is determined, bypassing the sending step and disapproving the request.
13 . The system of claim 1 wherein the device fingerprints authorized to access the customer account information consist of all device fingerprints having accessed the customer account information via the network within a predetermined time period prior to the request.
14 . The system of claim 1 wherein the requesting location comprises a geographic location.
15 . The system of claim 1 wherein the identity of the remote computing device includes information selected from the group consisting of manufacturer name, model name, and device type.
16 . The system of claim 1 wherein the notification further indicates a time of the request.
17 . The system of claim 1 wherein the determining step further comprises:
determining based on the device fingerprint whether the remote computing device is a non-mobile computing device;
determining whether the requesting location is an abnormal location; and
if the remote computing device is a non-mobile computing device and if the requesting location is an abnormal location, bypassing the sending step and disapproving the request.
18 . The system of claim 1 wherein the determining step further comprises:
determining based on the device fingerprint whether the remote computing device is a mobile device;
determining whether the requesting location is a preauthorized temporary location specified in the customer account information;
determining whether timing of the request falls within time limits specified for the temporary location; and
if the remote computing device is a mobile device, if the requesting location matches the preauthorized temporary location, and if the timing of the request falls within the specified time limits, bypassing the sending step and approving the request.
19 . The system of claim 1 wherein the customer-specified address is selected from the group consisting of a telephone number and an e-mail address.
20 . The system of claim 1 wherein the notification is selected from the group consisting of a voice message, a text message, and a substantially concurrent transmission of voice and text messages.
21 . The system of claim 1 wherein the request comprises a monetary transaction.
22 . The system of claim 2 wherein the reply to the notification includes a device fingerprint of a customer-specified system transmitting the reply to the notification.
23 . The system of claim 22 wherein the resolving step includes:
determining whether the reply to the notification is a valid reply or an invalid reply based on the device fingerprint of the customer-specified system; and
disregarding the reply to the notification when the reply to the notification is determined to be an invalid reply.Join the waitlist — get patent alerts
Track US2015154604A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.