IP Library Granted Patent US 10,313,343
Granted Patent B2
US 10,313,343 · App. 15/392,454 · Granted Jun 4, 2019

Fabric assisted identity and authentication

Inventors: James Tischart (Parker, CO); Jonathan Anderson (Alpharetta, GA)
Assignee: MCAFEE, LLC
H04L63/0876H04L63/0272H04L63/0281H04L63/08H04L63/105H04L63/1433H04L63/162H04W12/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,313,343
App. No.
15/392,454
Granted
Jun 4, 2019
Kind
B2
Abstract

Context-based authentication in a secure network comprised of multiple interconnected programmable devices is described. One technique includes receiving, from a programmable device, identity data and contextual data associated with a current authentication of a user attempting to access a secure network. The user is associated with the programmable device. The technique may include determining, based on the identity data and the contextual data, one or more patterns associated with the current authentication of the user. Furthermore, a risk level associated with the current authentication of the user may be determined based on the identity data, the contextual data, and the one or more patterns. In at least one scenario, access is granted to the secure network in response to the determined risk level. Other advantages and embodiments are described.

Claims (39)

1. A machine readable storage device or storage disk comprising instructions that, when executed, cause a machine for context-based authentication in a secure network including multiple interconnected programmable devices to at least:

obtain, from a programmable device, identity data and contextual data associated with a current authentication of a user attempting to access the secure network, the user being associated with the programmable device, the contextual data indicating a number of authentication factors implementable by the programmable device in connection with the current authentication, whether the programmable device is an approved device for the secure network, and whether the programmable device is attempting to access the secure network via a physical communication mechanism;

determine, based on the identity data and the contextual data, one or more patterns associated with the current authentication of the user;

determine, based on the identity data, the number of authentication factors indicated by the contextual data, and the one or more patterns, a risk level associated with the current authentication of the user;

access the secure network in response to the determined risk level satisfying a threshold;

request additional identity data in response to the determined risk level not satisfying the threshold; and

determine whether to permit access to the secure network based on the current authentication and the additional identity data.

2. The machine readable storage device or storage disk of claim 1 , wherein the requested additional identity data is randomized.

3. The machine readable storage device or storage disk of claim 1 , wherein the instructions, when executed, further cause the machine to invoke an authorization entity based on the determined risk level not satisfying the threshold and the additional identity data.

4. The machine readable storage device or storage disk of claim 1 , wherein one or more of the identity data, the contextual data, and the one or more patterns is communicated via an enterprise service bus (ESB).

5. The machine readable storage device or storage disk of claim 4 , wherein the ESB includes a data exchange layer.

6. The machine readable storage device or storage disk of claim 4 , wherein the ESB is to utilize message queuing telemetry transport messages for data exchange.

7. A method for context-based authentication in a secure network including multiple interconnected programmable devices, the method comprising:

obtaining, from a programmable device, identity data and contextual data associated with a current authentication of a user attempting to access the secure network, the user being associated with the programmable device, the contextual data indicating a number of authentication factors implementable by the programmable device in connection with the current authentication, whether the programmable device is an approved device for the secure network, and whether the programmable device is attempting to access the secure network via a physical communication mechanism;

determining, based on the identity data and the contextual data, one or more patterns associated with the current authentication of the user;

determining, based on the identity data, the number of authentication factors indicated by the contextual data, and the one or more patterns, a risk level associated with the current authentication of the user;

permitting access to the secure network in response to one or more processors determining the determined risk level satisfies a threshold;

requesting additional identity data in response to the one or more processors determining the determined risk level does not satisfy the threshold; and

determining whether to permit access to the secure network based on the current authentication and the additional identity data.

8. The method of claim 7 , wherein the requested additional identity data is randomized.

9. The method of claim 7 , further including invoking an authorization entity based on the determined risk level not satisfying the threshold and the additional identity data.

10. The method of claim 7 , further including communicating one or more of the identity data, the contextual data, and the one or more patterns via an enterprise service bus (ESB).

11. The method of claim 10 , further including utilizing a data exchange layer of the ESB.

12. The method of claim 10 , further including utilizing message queuing telemetry transport messages for data exchange via the ESB.

13. A system for context-based authentication in a secure network including multiple interconnected programmable devices, the system comprising:

one or more processors; and

a memory including instructions that, when executed, cause the one or more processors to:

access identity data and contextual data associated with a current authentication of a user attempting to access the secure network with a programmable device of the multiple interconnected programmable devices, the contextual data indicating a number of authentication factors implementable by the programmable device in connection with the current authentication, whether the programmable device is an approved device for the secure network, and whether the programmable device is attempting to access the secure network via a physical communication mechanism;

determine, based on the identity data and the contextual data, one or more patterns associated with the current authentication of the user;

determine, based on the identity data, the number of authentication factors indicated by the contextual data, and the one or more patterns, a risk level associated with the current authentication of the user;

permit access to the secure network in response the determined risk level satisfying a threshold;

request additional identity data in response to the determined risk level not satisfying the threshold; and

determine whether to permit access to the secure network based on the current authentication and the additional identity data.

14. The system of claim 13 , wherein the requested additional identity data is randomized.

15. The system of claim 13 , wherein the one or more processors are to invoke an authorization entity based on the determined risk level not satisfying the threshold and the additional identity information.

16. The system of claim 13 , wherein the one or more processors are to communicate one or more of the identity data, the contextual data, and the one or more patterns via an enterprise service bus (ESB).

17. The system of claim 16 , wherein the ESB includes a data exchange layer.

18. The system of claim 16 , wherein the ESB is to utilize message queuing telemetry transport messages for data exchange.

19. The system of claim 13 , wherein at least one of the one or more processors is a crypto processor.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Sep 15, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043969/0057 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 5, 2017
From: TISCHART, JAMES; ANDERSON, JONATHAN
To: MCAFEE, INC.
Reel/Frame 040864/0039 →
Continuity (1)
Related Publication 20180183789A1 · Jun 28, 2018