Identifying accounts having shared credentials

    公开(公告)号:US10469497B2

    公开(公告)日:2019-11-05

    申请号:US15166194

    申请日:2016-05-26

    Applicant: Dropbox, Inc.

    Abstract: Disclosed are systems, methods, and non-transitory computer-readable storage media for identifying accounts having shared credentials. In some implementations, a content management system can collect user login context data when a user logs in to or accesses a user account of the content management system. For example, the content management system can collect client device data, client application data, internet protocol (IP) address data, and/or other data from the user's device when the user logs in to the user account. The content management system can analyze the login context data to determine patterns that indicate that the user account login credentials are being shared among multiple users.

    SYSTEM AND METHOD FOR ROTATING CLIENT SECURITY KEYS

    公开(公告)号:US20190312724A1

    公开(公告)日:2019-10-10

    申请号:US16451351

    申请日:2019-06-25

    Applicant: Dropbox, Inc

    Inventor: Anton Mityagin

    Abstract: Systems, methods, and non-transitory computer-readable storage media for rotating security keys for an online synchronized content management system client. A client having a first security key as an active security key may send a request to a server for a new security key as a replacement for the first security key. The server may receive the request and generate a candidate security key. The server can issue the candidate security key to the client device. After receiving the candidate security key, the client may send a key receipt confirmation message to the server. In response to the confirmation message, the server may mark the candidate key as the new security key for the client and discard the client's old security key. The server may send an acknowledgment message to the client device. In response, the client may also mark the candidate key as its new active key.

    Advanced security protocol for broadcasting and synchronizing shared folders over local area network

    公开(公告)号:US10425391B2

    公开(公告)日:2019-09-24

    申请号:US15483751

    申请日:2017-04-10

    Applicant: Dropbox, Inc.

    Abstract: A method, system, and manufacture for securely broadcasting shared folders from one client device to other client devices and synchronizing the shared folders over a local area network. A first client device, associated with a content management system, generates a secure identifier for a shared folder, using a shared secret key that is associated with the shared folder. The first client device announces the secure identifier over a local area network to other client devices on the local area network including a second client device. The first client device receives a synchronization request for the shared folder from the second client device. After authenticating, using the shared secret key, that the second client device has authorization to access the shared folder, the first client device synchronizes the shared folder with the second client device over the local area network.

    Identifying related user accounts based on authentication data

    公开(公告)号:US10091174B2

    公开(公告)日:2018-10-02

    申请号:US14499959

    申请日:2014-09-29

    Applicant: Dropbox, Inc.

    Inventor: Anton Mityagin

    Abstract: In some embodiments, upon detecting malicious activity associated with a user account, a content management system can identify other user accounts related to the malicious user account. The content management system can identify related user accounts by comparing authentication information collected for the malicious user account with authentication information collected for other user accounts. Authentication information can include IP address information, geographic information, device type, browser type, email addresses, and/or referral information, for example. The content management system can compare the content items associated with the malicious user account to content items associated with other user accounts to determine relatedness or maliciousness. After identifying related malicious user accounts, the content management system can block all related malicious user accounts.

    Placing a user account in escrow
    45.
    发明授权

    公开(公告)号:US09961132B2

    公开(公告)日:2018-05-01

    申请号:US14446707

    申请日:2014-07-30

    Applicant: Dropbox, Inc.

    Inventor: Anton Mityagin

    CPC classification number: H04L67/10 H04L63/08 H04L63/10

    Abstract: Disclosed are systems, methods, and non-transitory computer-readable storage media for placing a user account in escrow to remove it from an administered account. An employee and/or an employer can select to remove a user account from an administered account associated with the employer. To ensure that the each party, the employer and employee, has an opportunity to retain their content stored in the removed user account, the user account can be placed into escrow, requiring login credentials of both the user and the administrator (employer) to access the user account. The user account can therefore not be accessed unless both the employer and employee each login to the account at the same time. By placing the user account in escrow, both parties can be assured that they can access the content items in the user account, and that the other party cannot access the content without their knowledge.

    PLACING A USER ACCOUNT IN ESCROW
    46.
    发明申请
    PLACING A USER ACCOUNT IN ESCROW 有权
    在ESCROW中安装用户帐户

    公开(公告)号:US20160036802A1

    公开(公告)日:2016-02-04

    申请号:US14446707

    申请日:2014-07-30

    Applicant: Dropbox, Inc.

    Inventor: Anton Mityagin

    CPC classification number: H04L67/10 H04L63/08 H04L63/10

    Abstract: Disclosed are systems, methods, and non-transitory computer-readable storage media for placing a user account in escrow to remove it from an administered account. An employee and/or an employer can select to remove a user account from an administered account associated with the employer. To ensure that the each party, the employer and employee, has an opportunity to retain their content stored in the removed user account, the user account can be placed into escrow, requiring login credentials of both the user and the administrator (employer) to access the user account. The user account can therefore not be accessed unless both the employer and employee each login to the account at the same time. By placing the user account in escrow, both parties can be assured that they can access the content items in the user account, and that the other party cannot access the content without their knowledge.

    Abstract translation: 公开了用于将用户帐户放置在托管中以将其从管理帐户中移除的系统,方法和非暂时计算机可读存储介质。 雇员和/或雇主可以选择从与雇主相关联的管理帐户中删除用户帐户。 为了确保每一方,雇主和雇员都有机会保留存储在已删除的用户帐户中的内容,用户帐户可以被放置在托管中,需要用户和管理员(雇主)的登录凭证才能访问 用户帐号。 因此,除非雇主和雇员都同时登录到帐户,否则无法访问用户帐户。 通过将用户帐户放置在托管中,双方可以确保他们可以访问用户帐户中的内容项,而另一方在不了解的情况下就无法访问该内容。

    ADVANCED SECURITY PROTOCOL FOR BROADCASTING AND SYNCHRONIZING SHARED FOLDERS OVER LOCAL AREA NETWORK
    47.
    发明申请
    ADVANCED SECURITY PROTOCOL FOR BROADCASTING AND SYNCHRONIZING SHARED FOLDERS OVER LOCAL AREA NETWORK 有权
    用于在本地区域网络广播和同步共享文件夹的高级安全协议

    公开(公告)号:US20150249647A1

    公开(公告)日:2015-09-03

    申请号:US14193316

    申请日:2014-02-28

    Applicant: Dropbox, Inc.

    Abstract: A method, system, and manufacture for securely broadcasting shared folders from one client device to other client devices and synchronizing the shared folders over a local area network. A first client device, associated with a content management system, generates a secure identifier for a shared folder, using a shared secret key that is associated with the shared folder. The first client device announces the secure identifier over a local area network to other client devices on the local area network including a second client device. The first client device receives a synchronization request for the shared folder from the second client device. After authenticating, using the shared secret key, that the second client device has authorization to access the shared folder, the first client device synchronizes the shared folder with the second client device over the local area network.

    Abstract translation: 一种用于将共享文件夹从一个客户端设备安全地广播到其他客户端设备并通过局域网同步共享文件夹的方法,系统和制造。 与内容管理系统相关联的第一客户端设备使用与共享文件夹相关联的共享秘密密钥来生成用于共享文件夹的安全标识符。 第一客户端设备通过局域网向局域网上的其他客户端设备通知包括第二客户端设备的安全标识符。 第一客户端设备从第二客户端设备接收到共享文件夹的同步请求。 在使用所述共享秘密密钥认证所述第二客户端设备具有访问所述共享文件夹的权限之后,所述第一客户端设备通过所述局域网与所述第二客户端设备同步所述共享文件夹。

Patent Agency Ranking