Security systems for protecting an asset
Abstract
Security systems for protecting assets are described, including password-based security systems that can provide different levels of access responsive to entry of a primary or secondary password. In some versions, user-configurable security rules can provide customized responses to entry of primary or secondary passwords, including feigned or limited access, security alerts, etc. Passwords comprising overt and covert components can be used to provide enhanced security and improved user control over system response. Improved security systems involving transactions between multiple parties are also considered, with options for user-customized security rules including primary and secondary passwords, and reverse challenge and response methods. Systems for Limited Use Credentials are also disclosed to reduce the risk of identity theft.
Claims
exact text as granted — not AI-modifiedI claim:
1 . A method for protecting a secure asset controlled via a user's electronic account, comprising:
receiving, from a computing device, a request for access to the user's account, the request comprising information associated with a password; retrieving information pertaining to user credentials from customized security rules for the user's account, wherein the customized security rules specify that full access to the user's account requires a primary password comprising an overt password and a covert cue, determining if the overt password is correct, and if correct, then determining if the provided information associated with the password confirms that the required covert cue was provided, and if so, then giving full access to the user's account, otherwise giving one of feigned access, limited access, or no access to the account, according to the customized security rules.
2 . The method of claim 1 , wherein the covert cue comprises an action performed on a user operated device selected from the computing device or a device in a communication with the computing device, selected from one of a predetermined timing of an action made on user operated device, the location of an action made on the user operated device, a deliberate error in entry of user credentials, pressing a pressure-sensitive region on the user operated device, touching a touch-sensitive region of the user operated device, holding the user operated device in a particular orientation, modifying the amount of light received by a photosensitive portion of the user operated device, and opening or closing a switch associated with the user operated device.
3 . The method of claim 2 , wherein the computing device comprises a graphical interface display and is adapted to receive and detect said action.
4 . The method of claim 1 , wherein the computing device is one of a telephone and a personal digital assistant and wherein the secure asset comprises one of an electronic bank account, a credit card account, a brokerage account, an electronic payment service, and a repository of confidential information.
5 . The method of claim 1 , wherein the customized security rules are stored on the computing device or in a memory accessible by the computing device.
6 . The method of claim 1 , wherein in response to a secondary password, limited access to the account is given, the limited access being selected from at least one of a geographical limitation for a purchase and a maximum transaction amount.
7 . The method of claim 1 , wherein the overt cue comprises information obtained through a challenge and response method.
8 . The method of claim 1 , wherein the computing device is installed in a vehicle.
9 . A method for using a portable electronic device to provide improved security for a secure asset, the portable electronic device comprising a graphical interface, the method comprising:
providing via the graphical interface an account access interface for accessing the secure asset, wherein the account access interface is governed by customizable security rules with predetermined settings selected by the user, wherein the rules are adapted to require a primary password comprising an overt password and a covert cue for full access to the asset, and are further adapted to, in response to receiving a secondary password, result in giving one of feigned or limited access to the asset.
10 . The method of claim 9 , wherein the overt cue is an action selected from one of pressing a pressure-sensitive region on the portable electronic device, touching a touch-sensitive region of the portable device, holding the portable device in a particular orientation, modifying the amount of light received by a photosensitive portion of the portable device, and opening or closing a switch associated with the portable electronic device.
11 . The method of claim 9 , further comprising, in response to a request from an authorized user, providing a computerized administrative interface accessible via the graphical interface, the computerized administrative interface being adapted to enable the authorized user to customize the customized security rules, the security rules being stored in the memory of the electronic device or in remote memory in communication therewith,
wherein the computerized administrative interface is adapted to receive commands from the authorized user to customize the security rules to provide different levels of account access responsive to entry via the account access interface of user credentials, and wherein the computerized administrative interface provides a selection for the user to specify one or more of a plurality of covert cue actions to form part of the primary password.
12 . The method of claim 9 , wherein the secure asset comprises one of a safe, a storage device, and a vehicle, and wherein the portable electronic device in response to entry of a primary password transmits an electronic signal resulting in granting full access to the secure asset.
13 . The method of claim 9 , wherein the customized rules specifying the covert cue comprise altering visible information associated with one of a credit card and an electronic one-time password system.
14 . The method of claim 9 , wherein the secure asset is a vehicle and wherein in response to a secondary password, limited access is provided to the vehicle.
15 . A method for accessing a secure account via an electronic user interface, comprising:
receiving a request via the electronic user interface for entry of user credentials with an input system configured to receive input of an overt password and a covert password cue according to predetermined customized security rules stored electronically in a memory, receiving the entered user credentials and confirming that the overt password is correct, according to the predetermined customized security rules, and in response to entry of the correct overt password, determining if the covert cue has been properly provided, and in response to providing the covert cue, giving access to the user's account, otherwise, in the absence of the covert cue, giving one of limited access, feigned access, or denial of access to the account, according to the customized security rules.
16 . The method of claim 15 , wherein the electronic user interface is provided by a smartphone, and wherein the secure asset comprises an electronic financial account.
17 . The method of claim 15 , wherein the electronic user interface is provided by a computing device, and wherein the covert cue comprises one of the timing of an action made on the computing device, the location of an action made on the computing device, a deliberate error entered via the graphical user interface, a physical action made with the computing device, pressing a pressure-sensitive region on the computing device, touching a touch-sensitive region of the computing device, holding the computing device in a particular orientation, modifying the amount of light received by a photosensitive portion of the computing device, and opening or closing a switch associated with the computing device.
18 . The method of claim 15 , wherein the primary password comprises electronically entered credentials and a covert cue comprises a verbal statement, wherein the verbal statement is validated by comparison with the customized security rules.
19 . The method of claim 18 , wherein the covert cue comprises information provided over a telephone connection with at least one of an automated telephony service and a human operator.
20 . The method of claim 15 , wherein the customized security rules have been customized by the user through at least one of one more selections entered via a computerized administrative interface via a graphical user interface, a data file transmitted electronically, entry of user selections entered with the assistance of a remote operator, and user selections made through an automated telephony system.Join the waitlist — get patent alerts
Track US2018247483A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.