IP Library Granted Patent US 12,301,555
Granted Patent B2
US 12,301,555 · App. 17/461,303 · Granted May 13, 2025

Automating responses to authentication requests using unsupervised computer learning techniques

Inventors: Joshua David Alexander (Austin, TX); Seth Holloway (Austin, TX); Alexa Staudt (Atlanta, GA); Ian Michael Glazer (Washington, DC); William C. Mortimore, Jr. (San Francisco, CA)
Assignee: Salesforce, Inc.
H04L63/0815G06N5/02H04L63/0853H04L63/0884H04W12/06H04W12/64H04L63/083H04L2463/082
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,301,555
App. No.
17/461,303
Granted
May 13, 2025
Kind
B2
Abstract

Techniques are disclosed relating to automating authentication decisions for a multi-factor authentication scheme based on computer learning. In disclosed embodiments, a mobile device receives a first request corresponding to a factor in a first multi-factor authentication procedure. Based on user input approving or denying the first request, the mobile device sends a response to the first request and stores values of multiple parameters associated with the first request. The mobile device receives a second request corresponding to a factor in a second multi-factor authentication procedure where the second request is for authentication for a different account than the first request. The mobile device automatically generates an approval response to the second request based on performing a computer learning process on inputs that include values of multiple parameters for the second request and the stored values of the multiple parameters associated with the first request. The approval response is automatically generated and sent without receiving user input to automate the second request.

Claims (46)

1. A method comprising:

receiving, by a server system, a login request, wherein the login request corresponds to a first factor in a multi-factor authentication (MFA) procedure;

requesting, by the server system and in response to the login request, a response from a mobile device corresponding to a second factor in the MEA procedure;

receiving, by the server system, a response token from the mobile device, wherein the response token comprises:

an MFA token automatically generated by a machine learning module at the mobile device based on MFA data received from the server system and without receiving input from a user of the mobile device to automate the MFA token; and

one or more context values of the mobile device;

determining, by the server system, that the MEA token is valid and that at least one of the one or more context values complies with a login policy; and

sending, by the server system, an approval response to the login request.

2. The method of claim 1 , wherein at least one of the context values is one of: type of device, proximity to another device, location of device, time of day, current weather, and signal strength.

3. The method of claim 1 , further comprising, prior to receiving the login request:

training, by the server system a plurality of machine learning modules using different context values of a plurality of mobile devices; and

transmitting, by the server system to the mobile device, a trained machine learning module that is unique to the mobile device based on the training being based on a plurality of context values of the mobile device.

4. The method of claim 1 , wherein the mobile device stores at least one value based on the MEA data.

5. The method of claim 4 , wherein the MFA token generated by the machine learning module is generated based on the at least one stored value.

6. The method of claim 1 , wherein the one or more context values that are received at the server system from the mobile device include a frequency of login parameter that indicates how often the user of the mobile device logs into a set of one or more accounts.

7. The method of claim 1 , wherein the one or more context values include a wearable device parameter that indicates whether a wearable device is being worn by the user of the mobile device and whether the wearable device is unlocked.

8. The method of claim 1 , wherein the one or more context values include one or more values that indicate personally identifiable information (PII) that is stored on the mobile device that is not shared with other devices.

9. A non-transitory computer-readable medium having instructions stored thereon that are capable of causing a server computing system to implement operations comprising:

receiving, a login request, wherein the login request corresponds to a first factor in a multi- factor authentication (MFA) procedure;

evaluating data associated with the login request based on a login policy;

requesting, in response to the login request, a response from a mobile device corresponding to a second factor in the MFA procedure, the requesting comprising sending MFA data from the server computing system to the mobile device indicating a required level of security based on the login policy;

receiving a response token from the mobile device, wherein the response token is generated at the mobile device by a machine learning module based on the MEA data and without receiving input from a user of the mobile device to automate the response token; and

sending an approval response based on the received response token.

10. The non-transitory computer-readable medium of claim 9 , wherein the response token is one of:

a null token comprising data which cannot be approved by the server computing system;

an automated token comprising data generated using the machine learning module; and

a user token comprising data based on further requested user input.

11. The non-transitory computer-readable medium of claim 10 , wherein the generating by the machine learning module is based on the MFA data.

12. The non-transitory computer-readable medium of claim 10 , wherein the MFA data comprises one or more context parameters to be used by the machine learning module, wherein the one or more context parameters include environmental parameters for the mobile device.

13. The non-transitory computer-readable medium of claim 9 , wherein a context parameter is one of: type of device, proximity to another device, location of device, time of day, current weather, and signal strength.

14. A method comprising:

receiving, by a server system, a login request, wherein the login request corresponds to a first factor in a multi-factor authentication (MFA) procedure;

evaluating, by the server system, data associated with the login request based on a login policy;

requesting, by the server system and in response to the login request, a response from a mobile device corresponding to a second factor in the MFA procedure, the requesting comprising sending security data from the server system to the mobile device indicating a required level of security based on the login policy;

receiving, by the server system, a response token from the mobile device, wherein the response token is generated at the mobile device by a machine learning module based on the security data and without receiving input from a user of the mobile device to automate the response token; and

sending, by the server system, an approval response based on the received response token.

15. The method of claim 14 , wherein the response token is one of:

a null token comprising data which cannot be approved by the server system;

an automated token comprising data generated using the machine learning module; and

a user token comprising data based on further requested user input.

16. The method of claim 15 , wherein the generating by the machine learning module is based on the security data.

17. The method of claim 16 , wherein the security data comprises one or more context values to be used by the machine learning module, wherein the one or more context values are associated with the mobile device.

18. The method of claim 15 , wherein the machine learning module at the mobile device is unique to the mobile device based on training of the machine learning module including training on a plurality of previous context values of the mobile device.

19. The method of claim 18 , further comprising:

transmitting, by the server system, to a new mobile device utilized by the user of the mobile device, the machine learning module trained on the plurality of previous context values of the mobile device.

20. The method of claim 15 , wherein the mobile device stores at least one value based on the security data, and wherein the generating by the machine learning module is based on the at least one stored value.

Assignments (2)
CHANGE OF NAME Recorded Apr 14, 2025
From: SALESFORCE.COM, INC.
To: SALESFORCE, INC.
Reel/Frame 070836/0877 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 30, 2021
From: ALEXANDER, JOSHUA DAVID; HOLLOWAY, SETH; STAUDT, ALEXA; GLAZER, IAN MICHAEL; MORTIMORE, WILLIAM C., JR.
To: SALESFORCE.COM, INC.
Reel/Frame 057330/0718 →
Continuity (2)
Continuation 16025885 · Jul 2, 2018
Related Publication 20220060465A1 · Feb 24, 2022
References Cited (81)
US 5950207A · Mortimore et al. · 1999 [cited by applicant]
US 5963646A · Fielder et al. · 1999 [cited by applicant]
US 5995624A · Fielder et al. · 1999 [cited by applicant]
US 6049612A · Fielder et al. · 2000 [cited by applicant]
US 6105133A · Fielder et al. · 2000 [cited by applicant]
US 7104444B2 · Suzuki · 2006 [cited by applicant]
US 7548886B2 · Kirkland et al. · 2009 [cited by applicant]
US 7669760B1 · Zettner · 2010 [cited by applicant]
US 7801304B1 · Harvey et al. · 2010 [cited by applicant]
US 7805749B1 · Harvey et al. · 2010 [cited by applicant]
US 7860131B1 · Harvey et al. · 2010 [cited by applicant]
US 7908638B1 · Harvey et al. · 2011 [cited by applicant]
US 8155948B2 · Ruano et al. · 2012 [cited by applicant]
US 8607322B2 · Hinton et al. · 2013 [cited by applicant]
US 8627438B1 · Bhimanaik · 2014 [cited by applicant]
US 8806567B1 · Venable, Sr. · 2014 [cited by applicant]
US 8955063B2 · Shibuya · 2015 [cited by applicant]
US 10705860B2 · Koren et al. · 2020 [cited by applicant]
US 10726491B1 · Hockey · 2020 [cited by examiner]
US 10812476B2 · Alexander · 2020 [cited by applicant]
US 11108764B2 · Alexander · 2021 [cited by examiner]
US 11416784B2 · Ibrahim · 2022 [cited by examiner]
US 20030182194A1 · Choey et al. · 2003 [cited by applicant]
US 20060136334A1 · Atkinson et al. · 2006 [cited by applicant]
US 20060282500A1 · Kiuchi et al. · 2006 [cited by applicant]
US 20070055878A1 · Sandhu et al. · 2007 [cited by applicant]
US 20070174082A1 · Singh · 2007 [cited by applicant]
US 20090172402A1 · Tran · 2009 [cited by applicant]
US 20100006642A1 · Boutcher et al. · 2010 [cited by applicant]
US 20100100454A1 · Sines et al. · 2010 [cited by applicant]
US 20100174649A1 · Bouchard · 2010 [cited by applicant]
US 20100217880A1 · Venezia et al. · 2010 [cited by applicant]
US 20100293598A1 · Collart et al. · 2010 [cited by applicant]
US 20100299529A1 · Fielder · 2010 [cited by applicant]
US 20110007901A1 · Ikeda et al. · 2011 [cited by applicant]
US 20110047597A1 · Mahaffey et al. · 2011 [cited by applicant]
US 20110142234A1 · Rogers · 2011 [cited by applicant]
US 20110202466A1 · Carter · 2011 [cited by applicant]
US 20110219230A1 · Oberheide et al. · 2011 [cited by applicant]
US 20110307699A1 · Fielder · 2011 [cited by applicant]
US 20110307705A1 · Fielder · 2011 [cited by applicant]
US 20110307706A1 · Fielder · 2011 [cited by applicant]
US 20110307707A1 · Fielder · 2011 [cited by applicant]
US 20110312278A1 · Matsushita et al. · 2011 [cited by applicant]
US 20110314281A1 · Fielder · 2011 [cited by applicant]
US 20120066745A1 · Wuthnow et al. · 2012 [cited by applicant]
US 20120068812A1 · Yamamoto et al. · 2012 [cited by applicant]
US 20120096277A1 · Perez Soria · 2012 [cited by applicant]
US 20120110329A1 · Brown et al. · 2012 [cited by applicant]
US 20120144468A1 · Pratt et al. · 2012 [cited by applicant]
US 20120158821A1 · Barros · 2012 [cited by applicant]
US 20120159591A1 · Payne et al. · 2012 [cited by applicant]
US 20120280784A1 · Gaviria Velez et al. · 2012 [cited by applicant]
US 20130191884A1 · Leicher et al. · 2013 [cited by applicant]
US 20140189808A1 · Mahaffey et al. · 2014 [cited by applicant]
US 20140378063A1 · Nathwani et al. · 2014 [cited by applicant]
US 20150286813A1 · Jakobsson · 2015 [cited by applicant]
US 20150347734A1 · Beigi · 2015 [cited by examiner]
US 20150347959A1 · Skaaksrud · 2015 [cited by applicant]
US 20160283933A1 · Orlando et al. · 2016 [cited by applicant]
US 20160378843A1 · Cherwonka et al. · 2016 [cited by applicant]
US 20170206365A1 · Garcia et al. · 2017 [cited by applicant]
US 20180004079A1 · Chen et al. · 2018 [cited by applicant]
US 20180293393A1 · Effendi · 2018 [cited by examiner]
US 20190036932A1 · Bathen · 2019 [cited by examiner]
US 20190238532A1 · Alexander et al. · 2019 [cited by applicant]
US 20190327230A1 · Wong et al. · 2019 [cited by applicant]
US 20200007532A1 · Alexander et al. · 2020 [cited by applicant]
US 20200007535A1 · Barhudarian · 2020 [cited by examiner]
US 20200033011A1 · Deal et al. · 2020 [cited by applicant]
US 20200099682A1 · Alexander et al. · 2020 [cited by applicant]
US 20200099683A1 · Alexander et al. · 2020 [cited by applicant]
US 20200099696A1 · Alexander et al. · 2020 [cited by applicant]
US 20200234605A1 · Shuart · 2020 [cited by examiner]
US 20200280552A1 · Alexander et al. · 2020 [cited by applicant]
US 20200311285A1 · Jochems · 2020 [cited by applicant]
US 20210297258A1 · Keith, Jr. · 2021 [cited by examiner]
DE 2259178A1 · 1973 [cited by applicant]
Google 2-step Verification, Article published Dec. 20, 2013 as verified by Internet Archive (4 pages); http://web.archive.org/web/20131220004531/http://www.google.com/landing/2step/#tab-why-you-need-it/ [Retrieved Apr. … [cited by applicant]
Office Action in U.S. Appl. No. 17/649,479 mailed Jan. 19, 2024, 17 pages. [cited by applicant]
Office Action in U.S. Appl. No. 17/649,479 mailed Jun. 11, 2024, 19 pages. [cited by applicant]