IP Library Granted Patent US 11,818,169
Granted Patent B2
US 11,818,169 · App. 17/974,257 · Granted Nov 14, 2023

Detecting and mitigating attacks using forged authentication objects within a domain

Inventors: Jason Crabtree (Vienna, VA); Andrew Sellers (Monument, CO)
Assignee: QOMPLX LLC
H04L63/1466H04L9/0643H04L63/1416H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,818,169
App. No.
17/974,257
Granted
Nov 14, 2023
Kind
B2
Abstract

A system for detecting and mitigating attacks using forged authentication objects within a domain is provided, comprising an authentication object inspector configured to observe a new authentication object generated by an identity provider, and retrieve the new authentication object; and a hashing engine configured to retrieve the new authentication object from the authentication object inspector, calculate a cryptographic hash for the new authentication object, and store the cryptographic hash for the new authentication object in a data store; wherein subsequent access requests accompanied by authentication objects are validated by comparing hashes for each authentication object to previous generated hashes.

Claims (33)

1. A system for detecting and mitigating attacks using forged authentication objects within a domain, comprising:

a computing device comprising a memory and a processor;

an authentication object inspector comprising a plurality of programming instructions stored in the memory which, when operating on the processor, causes the computing device to:

receive a plurality of first authentication objects known to be generated by an identity provider associated with an authentication domain;

store a record of each received first authentication object, with attached metadata comprising a timestamp of when each first authentication object was received, in a time-series database;

calculate an authentication object identifier for each first authentication object;

store the authentication object identifier of each first authentication object in a database of authentication object identifiers for the identity provider;

receive a request for access to a network resource associated with the authentication domain accompanied by a second authentication object;

calculate an authentication object identifier of the second authentication object;

compare the authentication object identifier of the second authentication object with the authentication object identifiers of the first authentication objects stored in the database of authentication object identifiers to determine whether the authentication object identifier of the second authentication object already exists in the database of authentication object identifiers;

where the authentication object identifier of the second authentication object does not exist in the database of authentication object identifiers, generate a notification that the identity provider may be compromised.

2. The system of claim 1 , wherein the authentication object identifiers are calculated using a hashing engine comprising a second plurality of programming instructions which, when operating on the processor, cause the computing device to:

receive authentication objects from the authentication object inspector;

calculate cryptographic hashes for received authentication objects by performing a plurality of calculations and transformations on each received authentication object; and

return the cryptographic hashes of authentication objects received to the authentication object inspector as an authentication object identifier for the received authentication object.

3. The system of claim 1 , wherein the authentication object inspector is operated by the identity provider.

4. The system of claim 1 , wherein the authentication object inspector is operated by a client device communicating with the identity provider over a network.

5. A method of detecting and mitigating attacks using forged authentication objects within a domain, comprising the steps of:

using an authentication object inspector operating on a computing device comprising a memory and a processor to:

receive a plurality of first authentication objects known to be generated by an identity provider associated with an authentication domain;

store a record of each received authentication object, with attached metadata comprising a timestamp of when the authentication object was received, in a time-series database;

calculate an authentication object identifier of each first authentication object;

store the authentication object identifier of the first authentication objects in a database of authentication object identifiers for the identity provider;

received a request for access to a network resource associated with the authentication domain accompanies by a second authentication object;

calculate an authentication object identifier of the second authentication object;

compare the authentication object identifier of the second authentication object with the authentication object identifiers of the first authentication objects stored in the database of authentication object identifiers to determine whether the authentication object identifier of the second authentication object already exists in the database; and

where the authentication object identifier of the second authentication object does not exist in the database of authentication object identifiers, generate a notification that the identity provider may be compromised.

6. The method of claim 5 , wherein a hashing engine operating on the computing device is used to:

receive authentication objects from the authentication object inspector;

calculate cryptographic hashes of authentication objects received by performing a plurality of calculations and transformations on each authentication object received; and

return the calculated cryptographic hashes to the authentication object inspector as an authentication object identifier for the received authentication object.

7. The method of claim 5 , wherein the authentication object inspector is operated by the identity provider.

8. The method of claim 5 , wherein the authentication object inspector is operated by a client device communicating with the identity provider over a network.

Assignments (5)
CHANGE OF ADDRESS Recorded Oct 1, 2024
From: QOMPLX LLC
To: QOMPLX LLC
Reel/Frame 069083/0279 →
CHANGE OF NAME Recorded Sep 27, 2023
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 065036/0449 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY PREVIOUSLY RECORDED AT REEL: 064674 FRAME: 0408. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 20, 2023
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 064966/0863 →
PATENT ASSIGNMENT AGREEMENT TO ASSET PURCHASE AGREEMENT Recorded Aug 23, 2023
From: QOMPLX, INC.
To: QPX, LLC.
Reel/Frame 064674/0407 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2023
From: CRABTREE, JASON; SELLERS, ANDREW
To: QOMPLX, INC.
Reel/Frame 064428/0881 →
Continuity (17)
Continuation 17169924 · Feb 8, 2021
Continuation In Part 15837845 · Dec 11, 2017
Continuation In Part 15825350 · Nov 29, 2017
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 15655113 · Jul 20, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15206195 · Jul 8, 2016
Continuation In Part 15186453 · Jun 18, 2016
Continuation In Part 15166158 · May 26, 2016
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 15091563 · Apr 5, 2016
Continuation In Part 14986536 · Dec 31, 2015
Continuation In Part 14925974 · Oct 28, 2015
Continuation In Part 14925974 · Oct 28, 2015
Provisional Application 62596105 · Dec 7, 2017
Related Publication 20230123314A1 · Apr 20, 2023
Cited By (2)
US 12,438,906 US 12,621,311