IP Library Granted Patent US 10,313,329
Granted Patent B2
US 10,313,329 · App. 15/786,400 · Granted Jun 4, 2019

On-demand service security system and method for managing a risk of access as a condition of permitting access to the on-demand service

Inventors: Forrest A. Junod (San Francisco, CA); Robert C. Fly (Moraga, CA); Peter Dapkus (Lafayette, CA); Scott W. Yancey (San Francisco, CA); Steven S. Lawrance (San Francisco, CA); Simon Z. Fell (Corte Madera, CA)
Assignee: salesforce.com, inc.
H04L63/083G06F21/42G06F21/60G06F21/6218H04L51/04H04L63/08H04L63/10H04L63/14H04L67/42
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,313,329
App. No.
15/786,400
Granted
Jun 4, 2019
Kind
B2
Abstract

In accordance with embodiments, there are provided mechanisms and methods for managing a risk of access to an on-demand service as a condition of permitting access to the on-demand service. These mechanisms and methods for providing such management can enable embodiments to help prohibit an unauthorized user from accessing an account of an authorized user when the authorized user inadvertently loses login information. The ability of embodiments to provide such management may lead to an improved security feature for accessing on-demand services.

Claims (43)

1. A non-transitory machine-readable medium carrying one or more sequences of instructions which, when executed by one or more processors, cause the one or more processors to:

receiving, with one or more hardware processors, a request to access an on-demand service from a requestor associated with one of a plurality of entities of the on-demand service;

determining, with the one or more hardware processors, that the request to access the on-demand service is from a source providing a risk of access, the determination being based at least in part on stored information associated with at least one of a plurality of users or the one of the plurality of entities, wherein the request has an associated one-time use token that cannot be reused and expires after a predetermined amount of time; and

managing, with the one or more hardware processors, the risk of access to the on-demand service by the requestor as a condition of permitting the requestor to access the on-demand service by providing an additional authentication sequence selected based on whether a requestor device is known, wherein the additional authentication sequence comprises completing additional subsequent authentication communications with the requestor device.

2. The non-transitory machine-readable medium of claim 1 , wherein the on-demand service includes an on-demand database service.

3. The non-transitory machine-readable medium of claim 2 , wherein the on-demand service includes a multi-tenant on-demand database service.

4. The non-transitory machine-readable medium of claim 1 , wherein managing the risk of access to the on-demand service by the requestor includes generating a document.

5. The non-transitory machine-readable medium of claim 1 , wherein the determination that the request is from the source providing the risk of access is further based, at least in part, on the device associated with the requestor.

6. The non-transitory machine-readable medium of claim 5 , wherein it is determined that the request is from the source providing the risk of access because the device associated with the requestor has not previously been associated with the at least one of a plurality of users identified by stored information of the one of the plurality of entities of the on-demand service to which the access is requested.

7. The non-transitory machine-readable medium of claim 5 , wherein it is determined that the request is from the source providing the risk of access because the device associated with the requestor has previously been associated with the at least one of a plurality of users identified by stored information of the one of the plurality of entities of the on-demand service to which the access is requested.

8. The non-transitory machine-readable medium of claim 6 , wherein managing the risk of access includes generating a document and permitting the requestor access to the on-demand service in response to:

the device associated with the requestor not being previously associated with the at least one of the plurality of users identified by the stored information of the one of the plurality of entities of the on-demand service to which the access is requested, and

providing the valid token to the requestor.

9. The non-transitory machine-readable medium of claim 6 , wherein managing the risk of access includes generating a document and providing the requestor access to the on-demand service in response to:

the device associated with the requestor being previously associated with the at least one of the plurality of users identified by the stored information of the one of the plurality of entities of the on-demand service to which the access is requested, and

providing the valid token to the requestor.

10. The non-transitory machine-readable medium of claim 1 , wherein managing the risk of access to the on-demand service by the requestor includes comparing information in the request to access the on-demand service with a list of at least one of users and entities pre-determined to be granted access to the on-demand service.

11. A method, comprising:

receiving, with one or more hardware processors, a request to access an on-demand service from a requestor associated with one of a plurality of entities of the on-demand service;

determining, with the one or more hardware processors, that the request to access the on-demand service is from a source providing a risk of access, the determination being based at least in part on stored information associated with at least one of a plurality of users or the one of the plurality of entities, wherein the request has an associated one-time use token that cannot be reused and expires after a predetermined amount of time; and

managing, with the one or more hardware processors, the risk of access to the on-demand service by the requestor as a condition of permitting the requestor to access the on-demand service by providing an additional authentication sequence selected based on whether a requestor device is known, wherein the additional authentication sequence comprises completing additional subsequent authentication communications with the requestor device.

12. An apparatus, comprising:

a processor; and

one or more stored sequences of instructions which, when executed by the processor, cause the processor to:

receiving, with one or more hardware processors, a request to access an on-demand service from a requestor associated with one of a plurality of entities of the on-demand service;

determining, with the one or more hardware processors, that the request to access the on-demand service is from a source providing a risk of access, the determination being based at least in part on stored information associated with at least one of a plurality of users or the one of the plurality of entities, wherein the request has an associated one-time use token that cannot be reused and expires after a predetermined amount of time; and

managing, with the one or more hardware processors, the risk of access to the on-demand service by the requestor as a condition of permitting the requestor to access the on-demand service by providing an additional authentication sequence selected based on whether a requestor device is known, wherein the additional authentication sequence comprises completing additional subsequent authentication communications with the requestor device.

13. The method of claim 11 , wherein it is determined that the request is from the source providing the risk of access because the device associated with the requestor has not previously been associated with the at least one of a plurality of users identified by stored information of the one of the plurality of entities of the on-demand service to which the access is requested.

14. The method of claim 11 , wherein it is determined that the request is from the source providing the risk of access because the device associated with the requestor has previously been associated with the at least one of a plurality of users identified by stored information of the one of the plurality of entities of the on-demand service to which the access is requested.

15. The method of claim 11 , wherein managing the risk of access includes generating a document and permitting the requestor access to the on-demand service in response to:

the device associated with the requestor not being previously associated with the at least one of the plurality of users identified by the stored information of the one of the plurality of entities of the on-demand service to which the access is requested, and

providing the valid token to the requestor.

16. The method of claim 11 , wherein managing the risk of access includes generating a document and providing the requestor access to the on-demand service in response to:

the device associated with the requestor being previously associated with the at least one of the plurality of users identified by the stored information of the one of the plurality of entities of the on-demand service to which the access is requested, and

providing the valid token to the requestor.

17. The apparatus of claim 12 , wherein it is determined that the request is from the source providing the risk of access because the device associated with the requestor has not previously been associated with the at least one of a plurality of users identified by stored information of the one of the plurality of entities of the on-demand service to which the access is requested.

18. The apparatus of claim 12 , wherein it is determined that the request is from the source providing the risk of access because the device associated with the requestor has previously been associated with the at least one of a plurality of users identified by stored information of the one of the plurality of entities of the on-demand service to which the access is requested.

19. The apparatus of claim 12 , wherein managing the risk of access includes generating a document and permitting the requestor access to the on-demand service in response to:

the device associated with the requestor not being previously associated with the at least one of the plurality of users identified by the stored information of the one of the plurality of entities of the on-demand service to which the access is requested, and

providing the valid token to the requestor.

20. The apparatus of claim 12 , wherein managing the risk of access includes generating a document and providing the requestor access to the on-demand service in response to:

the device associated with the requestor being previously associated with the at least one of the plurality of users identified by the stored information of the one of the plurality of entities of the on-demand service to which the access is requested, and

providing the valid token to the requestor.

Assignments (2)
CHANGE OF NAME Recorded Nov 21, 2024
From: SALESFORCE.COM, INC.
To: SALESFORCE, INC.
Reel/Frame 069431/0231 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 2, 2018
From: JUNOD, FORREST A.; FLY, ROBERT C.; DAPKUS, PETER; YANCEY, SCOTT W.; LAWRANCE, STEVEN S.; FELL, SIMON Z.
To: SALESFORCE.COM, INC.
Reel/Frame 044517/0667 →
Continuity (8)
Continuation 14486857 · Sep 15, 2014
Continuation 13874349 · Apr 30, 2013
Continuation 13424271 · Mar 19, 2012
Continuation 13424285 · Mar 19, 2012
Continuation 12271661 · Nov 14, 2008
Continuation 12271661 · Nov 14, 2008
Provisional Application 60988263 · Nov 15, 2007
Related Publication 20180054433A1 · Feb 22, 2018