IP Library Granted Patent US 8,881,266
Granted Patent B2
US 8,881,266 · App. 12/270,159 · Granted Nov 4, 2014

Enterprise password reset

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,881,266
App. No.
12/270,159
Granted
Nov 4, 2014
Kind
B2
Abstract

One embodiment of the present invention provides a system for automatically authenticating a user. During operation, the system receives a user's request for authentication. The system then extracts information associated with the user from user-specific information stored in an enterprise computer. The extracted user information does not explicitly relate to a password. The system further generates one or more challenges based on the extracted user information, and receives the user's response to the challenges. Subsequently, the system compares the user's response to the extracted user information, and authenticates the user.

Claims (71)

1. A computer-executed method for authenticating a user, the method comprising:

receiving a request from the user for authentication;

extracting, by a server computer, user-behavior information associated with the user from user-specific information stored in an enterprise computer, wherein the extracted user-behavior information includes one or more temporal activities associated with the user, and wherein the user-behavior information is extracted by the server computer so that the user's privacy is not compromised by a clerk of an enterprise information help-desk;

generating one or more challenges based on the extracted user-behavior information for the user, wherein generating a respective challenge involves:

selecting a behavior-information item from the extracted user-behavior information;

generating a question so that the selected behavior-information item is the answer to the question, wherein the question is formulated in a way that the question does not reveal the selected behavior-information item; and

formulating the respective challenge using the generated question;

receiving respective responses from the user to the challenges;

comparing the user's responses to the behavior-information items used to formulate the corresponding challenges; and

authenticating the user using the challenges without asking the user to input a password.

2. The method of claim 1 , further comprising identifying a risk indication.

3. The method of claim 1 , further comprising subsequently resetting a password of the authenticated user.

4. The method of claim 1 , wherein the user-specific information includes one or more of:

calendar entries of the user;

file usage history of the user;

emails of the user;

web browsing history of the user;

contact list of the user; and

past activities of the user.

5. The method of claim 1 , further comprising presenting the challenges to the user using a web-based application.

6. The method of claim 1 , wherein the user response is generated by a human.

7. The method of claim 1 , wherein the user response is generated by a proxy for the user.

8. The method of claim 1 , further comprising generating the challenges based on temporal information associated with computer work files of the user, wherein the temporal information is extracted from time stamps of the work files.

9. A non-transitory computer-readable storage medium storing instructions which when executed by a computer cause the computer to perform a method for authenticating a user, the method comprising:

receiving a request from the user for authentication;

extracting user-behavior information associated with the user from user-specific information stored in an enterprise computer, wherein the extracted user-behavior information includes one or more temporal activities associated with the user, and wherein the user-behavior information is extracted by a server computer so that the user's privacy is not compromised by a clerk of an enterprise information help-desk;

generating one or more challenges based on the extracted user-behavior information for the user, wherein generating a respective challenge involves:

selecting a behavior-information item from the extracted user-behavior information;

generating a question so that the selected behavior-information item is the answer to the question, wherein the question is formulated in a way that the question does not reveal the selected behavior-information item; and

formulating the respective challenge using the generated question;

receiving respective responses from the user to the challenges;

comparing the user's responses to the behavior-information items used to formulate the corresponding challenges; and

authenticating the user using the challenges without asking the user to input a password.

10. The computer-readable storage medium of claim 9 , wherein the method further comprises identifying a risk indication.

11. The computer-readable storage medium of claim 9 , wherein the method further comprises subsequently resetting a password of the authenticated user.

12. The computer-readable storage medium of claim 9 , wherein the user-specific information includes one or more of:

calendar entries of the user;

file usage history of the user;

emails of the user;

web browsing history of the user;

contact list of the user; and

past activities of the user.

13. The computer-readable storage medium of claim 9 , wherein the method further comprises presenting the challenges to the user using a web-based application.

14. The computer-readable storage medium of claim 9 , wherein the user response is generated by a human.

15. The computer-readable storage medium of claim 9 , wherein the user response is generated by a proxy for the user.

16. The computer-readable storage medium of claim 9 , wherein the method further comprises generating the challenges based on temporal information associated with computer work files of the user, wherein the temporal information is extracted from time stamps of the work files.

17. A computer system for authenticating a user, comprising:

a processor;

a memory;

a receiving mechanism configured to receive a request from the user for authentication;

an extracting mechanism configured to extract user-behavior information associated with the user from user-specific information stored in an enterprise computer, wherein the extracted user-behavior information includes one or more temporal activities associated with the user, and wherein the user-behavior information is extracted by the computer system so that the user's privacy is not compromised by a clerk of an enterprise information help-desk;

a formulating mechanism configured to:

select a behavior-information item from the extracted user-behavior information; and

generate a question so that the selected behavior-information item is the answer to the question, wherein the question is formulated in a way that the question does not reveal the selected behavior-information item;

a generating mechanism configured to generate one or more challenges using the generated questions;

a receiving mechanism configured to receive respective responses from the user to the challenges;

a comparing mechanism configured to compare the user's responses to the behavior-information items used to formulate the corresponding challenges; and

an authenticating mechanism configured to authenticate the user using the challenges without asking the user to input a password.

18. The computer system of claim 17 , further comprising an identifying mechanism configured to identify a risk indication.

19. The computer system of claim 17 , further comprising a password resetting mechanism configured to subsequently reset a password of the authenticated user.

20. The computer system of claim 17 , wherein the user-specific information includes one or more of:

calendar entries of the user;

file usage history of the user;

emails of the user;

web browsing history of the user;

contact list of the user; and

past activities of the user.

21. The computer system of claim 17 , further comprising a presenting mechanism configured to present the challenges to the user using a web-based application.

22. The computer system of claim 17 , wherein the user response is generated by a human.

23. The computer system of claim 17 , wherein the user response is generated by a proxy for the user.

24. The computer system of claim 17 , wherein the challenges are generated based on temporal information associated with computer work files of the user, wherein the temporal information is extracted from time stamps of the work files.

Assignments (10)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 6, 2025
From: XEROX CORPORATION
To: GENESEE VALLEY INNOVATIONS, LLC
Reel/Frame 073842/0479 →
SECOND LIEN NOTES PATENT SECURITY AGREEMENT Recorded Jul 2, 2025
From: XEROX CORPORATION
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 071785/0550 →
FIRST LIEN NOTES PATENT SECURITY AGREEMENT Recorded Apr 11, 2025
From: XEROX CORPORATION
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 070824/0001 →
SECURITY INTEREST Recorded Feb 13, 2024
From: XEROX CORPORATION
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 066741/0001 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT RF 064760/0389 Recorded Feb 13, 2024
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: XEROX CORPORATION
Reel/Frame 068261/0001 →
SECURITY INTEREST Recorded Nov 20, 2023
From: XEROX CORPORATION
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 065628/0019 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVAL OF US PATENTS 9356603, 10026651, 10626048 AND INCLUSION OF US PATENT 7167871 PREVIOUSLY RECORDED ON REEL 064038 FRAME 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 28, 2023
From: PALO ALTO RESEARCH CENTER INCORPORATED
To: XEROX CORPORATION
Reel/Frame 064161/0001 →
SECURITY INTEREST Recorded Jun 22, 2023
From: XEROX CORPORATION
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 064760/0389 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 20, 2023
From: PALO ALTO RESEARCH CENTER INCORPORATED
To: XEROX CORPORATION
Reel/Frame 064038/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 13, 2008
From: CHOW, RICHARD; GOLLE, PHILIPPE J. P.; JAKOBSSON, BJORN MARKUS; STADDON, JESSICA N.
To: PALO ALTO RESEARCH CENTER INCORPORATED
Reel/Frame 021831/0154 →