IP Library Granted Patent US 10,742,647
Granted Patent B2
US 10,742,647 · App. 15/790,860 · Granted Aug 11, 2020

Contextual and risk-based multi-factor authentication

Inventors: Jason Crabtree (Vienna, VA); Andrew Sellers (Monument, CO); Ian MacLeod (Arlington, VA)
Assignee: QOMPLX, INC.
H04L63/0861H04L43/04H04L63/083H04L63/0876H04L63/105H04L63/1433H04L63/1408H04L2463/082
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,742,647
App. No.
15/790,860
Granted
Aug 11, 2020
Kind
B2
Abstract

A system for contextual and risk-based multi-factor authentication having a multi-dimensional time series data server configured to monitor and record a network's traffic data and to serve the traffic data to other modules and a directed computation graph module configured to receive network traffic data from the multi-dimensional time series data server, determine a network traffic baseline from the network traffic data, and determine a verification score needed before granting access based at least in part by the network traffic baseline. A plurality of verification methods build up a user's verification score to required level to gain access.

Claims (37)

1. A system for contextual and risk-based multi-factor authentication, comprising:

a computing device comprising a memory and a processor connected to a computer network;

a multi-dimensional time series data module comprising a first plurality of programming instructions stored in the memory of, and operable on the processor of, the computing device, wherein the first plurality of programming instructions, when operating on the processor, cause the computing device to:

monitor and store time series data regarding the network's traffic, the time series data comprising a time of an attempted access to a resource on the network, an identifier for the resource, and a credential used in the attempted access to the resource; and

serve traffic data to other modules; and

a validation module comprising a second plurality of programming instructions stored in the memory of, and operable on the processor of, the computing device, wherein the second plurality of programming instructions, when operating on the processor, cause the computing device to:

receive the time series data from the multi-dimensional time series data server;

determine a context in which the attempted access is being made from the time series data; and

establish a required verification score for granting access to the resource based on the context;

select a plurality of verification methods, wherein:

each verification method is associated with a number of points;

the successful completion of a verification method awards the number of points associated with that verification method;

the total number of points available for successful completion of the plurality of verification methods is equal to or greater than the verification score; and

at least one of the verification methods is a non-automated verification method requiring a manual input; and

wherein, when the number of points awarded is equal to or greater than the verification score, access to the resource is granted.

2. The system of claim 1 , wherein the time series data further comprises a security-level associated with the resources.

3. The system of claim 1 , wherein the time series data further comprises the origin of the attempted access.

4. The system of claim 1 , wherein one of the verification methods verifies visual media pertaining to a user associated with the credential.

5. The system of claim 1 , wherein one of the verification methods checks and verifies biometric features of a user associated with the credential.

6. The system of claim 1 , wherein one of the verification methods used is based on information obtained from untrusted parties.

7. The system of claim 1 , wherein one of the verification methods used is based on information pertaining to a device used by a user associated with the credential to access the resource.

8. A method for contextual and risk-based multi-factor authentication, comprising the steps of:

monitoring and storing time series data regarding the network's traffic, the time series data comprising a time of an attempted access to a resource on the network, an identifier for the resource, and a credential used in the attempted access to the resource;

determining a context in which the attempted access is being made from the time series data;

establishing a required verification score for granting access to the resource based on the context computation graph module;

selecting a plurality of verification methods, wherein:

each verification method is associated with a number of points;

the successful completion of a verification method awards the number of points associated with that verification method;

the total number of points available for successful completion of the plurality of verification methods is equal to or greater than the verification score; and

at least one of the verification methods is a non-automated verification method requiring a manual input; and

allowing access to the resource when the number of points awarded is equal to or greater than the verification score.

9. The method of claim 8 , wherein the time series data further comprises a security-level associated with the resource.

10. The method of claim 8 , wherein the time series data further comprises the origin of the attempted access.

11. The method of claim 8 , wherein one of the verification methods verifies visual media pertaining to a user associated with the credential.

12. The method of claim 8 , wherein the verification methods checks and verifies biometric features of a user associated with the credential.

13. The method of claim 8 , wherein one of the verification methods used is based on information obtained from untrusted parties.

14. The method of claim 8 , wherein one of the verification methods used is based on information pertaining to a device used by a user associated with the credential to access the resource.

Assignments (9)
CHANGE OF ADDRESS Recorded Oct 1, 2024
From: QOMPLX LLC
To: QOMPLX LLC
Reel/Frame 069083/0279 →
CHANGE OF NAME Recorded Sep 27, 2023
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 065036/0449 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY PREVIOUSLY RECORDED AT REEL: 064674 FRAME: 0408. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 20, 2023
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 064966/0863 →
PATENT ASSIGNMENT AGREEMENT TO ASSET PURCHASE AGREEMENT Recorded Aug 23, 2023
From: QOMPLX, INC.
To: QPX, LLC.
Reel/Frame 064674/0407 →
CHANGE OF ADDRESS Recorded Dec 29, 2022
From: QOMPLX, INC.
To: QOMPLX, INC.
Reel/Frame 062251/0629 →
CHANGE OF ADDRESS Recorded Oct 27, 2020
From: QOMPLX, INC.
To: QOMPLX, INC.
Reel/Frame 054298/0094 →
CHANGE OF ADDRESS Recorded Aug 7, 2019
From: FRACTAL INDUSTRIES, INC.
To: QOMPLX, INC.
Reel/Frame 049996/0683 →
CHANGE OF NAME Recorded Aug 7, 2019
From: FRACTAL INDUSTRIES, INC.
To: QOMPLX, INC.
Reel/Frame 049996/0698 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 31, 2017
From: CRABTREE, JASON; SELLERS, ANDREW; MACLEOD, IAN
To: FRACTAL INDUSTRIES, INC.
Reel/Frame 043998/0451 →
Continuity (11)
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15206195 · Jul 8, 2016
Continuation In Part 15186453 · Jun 18, 2016
Continuation In Part 15166158 · May 26, 2016
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 15091563 · Apr 5, 2016
Continuation In Part 14986536 · Dec 31, 2015
Continuation In Part 14925974 · Oct 28, 2015
Provisional Application 62574708 · Oct 19, 2017
Related Publication 20180159852A1 · Jun 7, 2018
Cited By (3)
US 12,519,764 US 12,519,777 US 12,598,179