IP Library › Granted Patent US 12,574,412
Granted Patent B2
US 12,574,412 · App. 17/389,650 · Granted Mar 10, 2026

Method and system for processing authentication requests

Inventor: Jerry Jean (Terrebonne, CA)
Assignee: 9287-2621 QUÉBEC INC.
H04L63/20H04L63/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,574,412
App. No.
17/389,650
Granted
Mar 10, 2026
Kind
B2
Abstract

A method for managing an authentication request in a computer network comprising a domain controller. The method comprising the steps of: capturing an authentication request received from a client computer after the authentication request is treated by the domain controller but before any final decision is generated by the domain controller; piling the authentication request in a cache; determining whether the authentication request is a background refresh call or an interactive logon request by inspecting a log of the client computer from which the authentication request has been received; sending a notification to an electronic device associated with a user account indicated in the authentication request; applying a policy to the authentication request based on at least one of the user account identifier and an identification of the client computer; and generating a final decision based on the policy applied to the authentication request.

Claims (39)

1 . A method for managing an authentication request in a computer network, the computer network comprising a plurality of domain controllers comprising a domain controller configured to use Kerberos protocol, the method comprising the steps of:

capturing, at the domain controller, an authentication request received from a client computer after the authentication request is treated by the domain controller but before any final decision is generated by the domain controller;

determining, by a sub-authentication routine installed in the domain controller, whether the authentication request is a background refresh call or an interactive logon request by inspecting a log of the client computer from which the authentication request has been received;

in response to determining by the sub-authentication routine installed in the domain controller that the authentication request is an interactive logon request, sending a notification to an electronic device associated with a user account indicated in the authentication request;

applying a policy at the domain controller to the authentication request based on at least one of the user account identifiers and an identification of the client computer; and

generating, at the domain controller, a final decision based on the policy applied to the authentication request, wherein

prior to determining if the authentication request is the background refresh call or the interactive logon request, piling the authentication request in a pile in a cache located in the domain controller, the background refresh call being automated and the interactive logon request involving user interaction,

in response to receiving another authentication request, piling the other authentication request in the pile in the cache after the authentication request for later execution, and

sharing the pile with other domain controllers of the plurality of the domain controllers.

2 . The method of claim 1 , further comprising, prior to capturing the incoming authentication request, receiving a parameter for a notification to a personal electronic device in a control panel of an administrator of the domain controller.

3 . The method of claim 1 , wherein the steps are performed by a server hosting the domain controller.

4 . The method of claim 1 , wherein applying the policy further comprises applying the policy on a group object.

5 . The method of claim 1 , wherein applying the policy further comprises applying a policy on a computer object which is a client.

6 . The method of claim 1 , wherein applying the policy further comprises applying a policy on a user object.

7 . The method of claim 1 , further comprising:

determining whether the client computer belongs to a domain to which the domain controller belongs, and,

in response to determining that the client computer belongs to the domain, sending the notification to the electronic device associated with the user account indicated in the authentication request.

8 . The method of claim 1 , further comprising designating one of the domain controllers as a master domain controller and every other one of the domain controllers as slave domain controllers, authentication being treated by the master domain controller to avoid redundant treatment by every other one of the domain controllers.

9 . A method for managing an authentication request in a computer network, the computer network comprising a plurality of domain controllers comprising a domain controller configured to use Kerberos protocol, the method comprising the steps of:

capturing, at the domain controller, an authentication request received from a client computer after the authentication request is treated by the domain controller but before any final decision is generated by the domain controller;

determining, by a sub-authentication routine installed in the domain controller, if the authentication request received from a client computer is received from within a domain to which the domain controller belongs, or from outside the domain, by inspecting an IP address in the authentication request;

if the authentication request received from a client computer is received from within a domain to which the domain controller belongs, determining, by the sub-authentication routine installed in the domain controller, whether the authentication request is a background refresh call or an interactive logon request by inspecting a log of the client computer from which the authentication request has been received;

if the authentication request received from a client computer is received from outside the domain to which the domain controller belongs, determining, by the sub-authentication routine installed in the domain controller, whether the authentication request is a background refresh call by comparing with a register of prior authentication requests and associated IP addresses, and if no, determining, at the domain controller, that the authentication request is an interactive logon request and registering the IP address, wherein

prior to determining if the authentication request is the background refresh call or the interactive logon request, piling the authentication request in a pile in a cache located in the domain controller, the background refresh call being automated and the interactive logon request involving user interaction,

in response to receiving another authentication request, piling the other authentication request in the pile in the cache after the authentication request for later execution, and

sharing the pile with the other domain controllers of the plurality of the domain controllers.

10 . The method of claim 9 , further comprising the steps of:

in response to determining that the authentication request is an interactive logon request, sending a notification to an electronic device associated with a user account indicated in the authentication request;

applying a policy to the authentication request based on at least one of the user account identifiers and an identification of the client computer; and

generating a final decision based on the policy applied to the authentication request.

11 . The method of claim 9 , further comprising, prior to capturing the incoming authentication request, receiving a parameter for a notification to a personal electronic device in a control panel of an administrator of the domain controller.

12 . The method of claim 9 , wherein the steps are performed by a server hosting the domain controller.

13 . The method of claim 10 , wherein applying the policy further comprises applying the policy on a group object.

14 . The method of claim 10 , wherein applying the policy further comprises applying a policy on a computer object which is a client.

15 . The method of claim 10 , wherein applying the policy further comprises applying a policy on a user object.

16 . The method of claim 10 , further comprising:

determining whether the client computer belongs to a domain to which the domain controller belongs, and,

in response to determining that the client computer belongs to the domain, sending the notification to the electronic device associated with the user account indicated in the authentication request.

17 . The method of claim 9 , further comprising designating one of the domain controllers as a master domain controller and every other one of the domain controllers as slave domain controllers, authentication being treated by the master domain controller to avoid redundant treatment by every other one of the domain controllers.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 17, 2021
From: JEAN, JERRY
To: 9287-2621 QUÉBEC INC.
Reel/Frame 057204/0315 →
Continuity (2)
Provisional Application 63058624 · Jul 30, 2020
Related Publication 20220038502A1 · Feb 3, 2022
References Cited (34)
US 7100195B1 · Underwood · 2006 [cited by applicant]
US 7607164B2 · Vasishth et al. · 2009 [cited by applicant]
US 8015597B2 · Libin et al. · 2011 [cited by applicant]
US 8045486B2 · Swan · 2011 [cited by examiner]
US 8341270B2 · Mazzaferri et al. · 2012 [cited by applicant]
US 8355407B2 · Wookey et al. · 2013 [cited by applicant]
US 8621587B2 · Halls · 2013 [cited by applicant]
US 9064124B1 · Davis · 2015 [cited by examiner]
US 9419968B1 · Thakre · 2016 [cited by applicant]
US 9674173B2 · Fox · 2017 [cited by applicant]
US 9690924B2 · McClure et al. · 2017 [cited by applicant]
US 10057234B1 · Murchison · 2018 [cited by examiner]
US 10169562B2 · Bandyopadhyay · 2019 [cited by examiner]
US 10367835B1 · Raviv · 2019 [cited by examiner]
US 10628294B2 · Datta · 2020 [cited by applicant]
US 10666673B2 · Rieke et al. · 2020 [cited by applicant]
US 10958640B2 · Divoux et al. · 2021 [cited by applicant]
US 20020095497A1 · Satagopan · 2002 [cited by examiner]
US 20150222614A1 · Johnson · 2015 [cited by examiner]
US 20160094546A1 · Innes · 2016 [cited by examiner]
US 20160182488A1 · Mowers · 2016 [cited by examiner]
US 20170061112A1 · Bandyopadhyay · 2017 [cited by examiner]
US 20180097789A1 · Murthy · 2018 [cited by examiner]
US 20190116196A1 · Sancheti et al. · 2019 [cited by applicant]
US 20190273731A1 · Kassner · 2019 [cited by examiner]
US 20190311093A1 · Moloian · 2019 [cited by examiner]
US 20190386979A1 · Khylkouskaya · 2019 [cited by examiner]
US 20200137097A1 · Zimmermann et al. · 2020 [cited by applicant]
US 20220294794A1 · Liu · 2022 [cited by examiner]
EP 3258374B1 · 2019 [cited by applicant]
GB 2577067B · 2020 [cited by applicant]
WO 2016044359A1 · 2016 [cited by applicant]
WO 2016176686A1 · 2016 [cited by applicant]
WO 2018063583A1 · 2018 [cited by applicant]