IP Library Granted Patent US 9,667,622
Granted Patent B2
US 9,667,622 · App. 14/788,309 · Granted May 30, 2017

Managing access to an on-demand service

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,667,622
App. No.
14/788,309
Granted
May 30, 2017
Kind
B2
Abstract

In accordance with embodiments, there are provided mechanisms and methods for managing a risk of access to an on-demand service as a condition of permitting access to the on-demand service. These mechanisms and methods for providing such management can enable embodiments to help prohibit an unauthorized user from accessing an account of an authorized user when the authorized user inadvertently loses login information. The ability of embodiments to provide such management may lead to an improved security feature for accessing on-demand services.

Claims (30)

1. A method comprising:

receiving, from a client device, a first request including authentication information for a user and information identifying the client device, the information identifying the client device including an IP address;

validating the authentication information of the user, the authentication information associated with a user account;

responsive to validating the authentication information of the user, determining whether the IP address is associated with a location associated with the user account; and

responsive to determining that the IP address is not associated with the location associated with the user account:

sending a token to a channel associated with the user account,

receiving, from the client device, a second request including the token sent to the channel associated with the user account, and

responsive to receiving the second request including the token from the client device, authenticating the user.

2. The method of claim 1 , wherein the token is a password.

3. The method of claim 1 , wherein the token is a PIN.

4. The method of claim 1 , wherein the token is a one time password.

5. The method of claim 1 , wherein the channel is one selected from a group consisting of: an email and a short message service (SMS).

6. The method of claim 1 , wherein the token is time-constrained.

7. The method of claim 1 , wherein the first request is a login request submitted via a user interface to access a database system.

8. The method of claim 1 , wherein determining whether the IP address is associated with a user account associated with the authentication information includes determining whether the first request is from an unknown source.

9. A non-transitory computer readable medium configured to store instruction, the instructions when executed by a processor, cause the processor to:

receive, from a client device, a first request including authentication information for a user and information identifying the client device, the information identifying the client device including an IP address;

validate the authentication information of the user, the authentication information associated with a user account;

responsive to validating the authentication information of the user, determine whether the IP address is associated with a location associated with user account; and

responsive to determining that the IP address is not associated with the location associated with the user account:

send a token to a channel associated with the user account,

receive, from the client device, a second request including the token sent to the channel associated with the user account, and

responsive to receiving the second request including the token from the client device, authenticate the user.

10. The non-transitory computer readable medium of claim 9 , wherein the token is a password.

11. The non-transitory computer readable medium of claim 9 , wherein the token is a PIN.

12. The non-transitory computer readable medium of claim 9 , wherein the token is a one time password.

13. The non-transitory computer readable medium of claim 9 , wherein the channel is one selected from a group consisting of: a voice message, and an instant message.

14. The non-transitory computer readable medium of claim 9 , wherein the token is time-constrained.

15. The non-transitory computer readable medium of claim 9 , wherein the first request is a login request via a user interface.

16. The non-transitory computer readable medium of claim 9 , wherein determining whether the IP address is associated with a user account associated with the authentication information includes determining whether the first request is from an unknown source.

Assignments (2)
CHANGE OF NAME Recorded Oct 25, 2024
From: SALESFORCE.COM, INC.
To: SALESFORCE, INC.
Reel/Frame 069268/0034 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 2, 2015
From: JUNOD, FORREST A.; FLY, ROBERT C.; DAPKUS, PETER; YANCEY, SCOTT W.; LAWRANCE, STEVEN S.; FELL, SIMON Z.
To: SALESFORCE.COM, INC.
Reel/Frame 035973/0444 →