IP Library Granted Patent US 12,069,095
Granted Patent B2
US 12,069,095 · App. 17/328,759 · Granted Aug 20, 2024

Automated authentication and authorization in a communication system

Inventors: Ashley Duane Wilson (San Francisco, CA); Seth Joshua Blank (San Francisco, CA); Peter Martin Goldstein (San Francisco, CA); Jack William Abbott (Parker, CO); Robert Benjamin Barclay (Thornton, CO)
Assignee: ValiMail Inc.
H04L63/20G06F16/903G06Q10/103G06Q10/105H04L63/0876H04L63/0884H04L63/101G06Q10/107
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,069,095
App. No.
17/328,759
Granted
Aug 20, 2024
Kind
B2
Abstract

An application-operating organization may delegate a third-party server to serve as an automated contextual authentication responder and an authorization responder. The third-party server may manage a delegated section of the organization's namespace that includes the public identities of various devices controlled by the organization. The third-party server may also dynamically generate interaction control list that is tailored to a requesting device's context based on the interaction control policies set forth by the organization. The interaction control list may include information that determines the authorization of the requesting device to interact with another device. The third-party server may also automatically determine the role of a new device to which existing policies are inapplicable and provide guided workflow for the organization to set up new interaction control policies in governing the new device. The determination of the roles of devices may be based on an iterative process using external data sources.

Claims (52)

1. A computer-implemented method, comprising:

receiving, by a third-party server, a forwarded message or message metadata from a recipient device that receives an original message from a sender device which attempts to perform an action, the third-party server delegated by a first organization for managing one or more policies set forth by the first organization;

determining, based on information associated with the sender device, that a sender associated with the sender device is unknown to the third-party server;

identifying metadata of the sender device from the forwarded message or message metadata;

determining a sender identity of the sender associated with the sender device based on the metadata;

determining that one of the policies applies to the sender based on the sender identity;

transmitting a response to the recipient device comprising information related to the sender identity of the sender device, wherein the information guides the recipient device to respond to the sender device; and

storing, by the third-party server, the sender identity associated with sender in a list of authorized senders, wherein information in the list of authorized senders is provided by the third-party server to a plurality of unrelated organizations including the first organization.

2. The computer-implemented method of claim 1 , further comprising:

transmitting a recommendation to the first organization for a potential policy modification based on the sender identity of the sender;

receiving an approval from the first organization or automatically approving in accordance with the first organization's configurations; and

implementing automatically the potential policy modification to reflect the approval.

3. The computer-implemented method of claim 2 , the third-party server transmits the recommendation and receives the approval through a guided workflow, the guided workflow comprising one or more questions or suggested actions for the first organization to characterize the sender.

4. The computer-implemented method of claim 1 , wherein the third-party server maintaining a plurality of guided workflow plans, the guided workflow is selected from one of the guided workflow plans based on a likely role of the sender.

5. The computer-implemented method of claim 1 , wherein the sender identity of the sender is authenticated by the recipient device through a DNS record associated with the sender.

6. The computer-implemented method of claim 4 , wherein determining the likely role of the sender device is based on a recursive process.

7. The computer-implemented method of claim 4 , wherein determining the likely role of the sender device is based on one or more searches of open-source intelligence sources.

8. The computer-implemented method of claim 1 , wherein the message metadata is included in an authentication report.

9. A system, comprising:

one or more processors;

memory for storing computer code comprising instructions, the instructions, when executed by the one or more processors, cause the one or more processors to at least:

receive, by a third-party server, a forwarded message or message metadata from a recipient device that receives an original message from a sender device which attempts to perform an action, the third-party server delegated by a first organization for managing one or more policies set forth by the first organization;

determine, based on information associated with the sender device, that a sender associated with the sender device is unknown to the third-party server;

identify metadata of the sender device from the forwarded message or message metadata;

determine a sender identity of the sender associated with the sender device based on the metadata;

determine that one of the policies applies to the sender based on the sender identity;

transmit a response to the recipient device comprising information related to the sender identity of the sender device, wherein the information guides the recipient device to respond to the sender device; and

store, by the third-party server, the sender identity associated with sender in a list of authorized senders, wherein information in the list of authorized senders is provided by the third-party server to a plurality of unrelated organizations including the first organization.

10. The system of claim 9 , wherein the instructions, when executed, further cause the one or more processors to at least:

transmit a recommendation to the first organization for a potential policy modification based on the sender identity of the sender;

receive an approval from the first organization or automatically approving in accordance with the first organization's configurations; and

implement automatically the potential policy modification to reflect the approval.

11. The system of claim 10 , wherein the system transmits the recommendation and receives the approval through a guided workflow, the guided workflow comprising one or more questions or suggested actions for the first organization to characterize the sender device.

12. The system of claim 9 , wherein the system maintains a plurality of guided workflow plans, the guided workflow is selected from one of the guided workflow plans based on a likely role of the sender.

13. The system of claim 9 , wherein the sender identity of the sender is authenticated by the recipient device through a DNS record associated with the sender.

14. The system of claim 12 , wherein determining the likely role of the sender device is based on a recursive process.

15. The system of claim 12 , wherein determining the likely role of the sender device is based on one or more searches of open-source intelligence sources.

16. The system of claim 9 , wherein the message metadata is included in an authentication report.

17. A non-transitory computer readable medium for storing computer code comprising instructions, the instructions, when executed by one or more processors, cause the one or more processors to at least:

receive, by a third-party server, a forwarded message or message metadata from a recipient device that receives an original message from a sender device which attempts to perform an action, the third-party server delegated by a first organization for managing one or more policies set forth by the first organization;

determine, based on information associated with the sender device, that a sender associated with the sender device is unknown to the third-party server;

identify metadata of the sender device from the forwarded message or message metadata;

determine a sender identity of the sender associated with the sender device based on the metadata;

determine that one of the policies applies to the sender based on the sender identity;

transmit a response to the recipient device comprising information related to the sender identity of the sender device, wherein the information guides the recipient device to respond to the sender device; and

store, by the third-party server, the sender identity associated with sender in a list of authorized senders, wherein information in the list of authorized senders is provided by the third-party server to a plurality of unrelated organizations including the first organization.

18. The non-transitory computer readable medium of claim 17 , wherein the instructions, when executed, further cause the one or more processors to at least:

transmit a recommendation to the first organization for a potential policy modification based on the sender identity of the sender;

receive an approval from the first organization or automatically approving in accordance with the first organization's configurations; and

implement automatically the potential policy modification to reflect the approval.

19. The non-transitory computer readable medium of claim 18 , wherein the third-party server transmits the recommendation and receives the approval through a guided workflow, the guided workflow comprising one or more questions or suggested actions for the first organization to characterize the sender device.

20. The non-transitory computer readable medium of claim 17 , wherein the third-party server maintaining a plurality of guided workflow plans, the guided workflow is selected from one of the guided workflow plans based on a likely role of the sender.

Assignments (3)
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jan 9, 2026
From: VALIMAIL INC.
To: HPS INVESTMENT PARTNERS, LLC, AS COLLATERAL AGENT
Reel/Frame 074281/0239 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 10, 2025
From: VALIMAIL INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 073910/0374 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 8, 2021
From: WILSON, ASHLEY DUANE; BLANK, SETH JOSHUA; GOLDSTEIN, PETER MARTIN; ABBOTT, JACK WILLIAM; BARCLAY, ROBERT BENJAMIN
To: VALIMAIL INC.
Reel/Frame 056470/0365 →
Continuity (4)
Continuation In Part 17155091 · Jan 22, 2021
Provisional Application 63093723 · Oct 19, 2020
Provisional Application 62964624 · Jan 22, 2020
Related Publication 20210289001A1 · Sep 16, 2021