IP Library Granted Patent US 12,671,715
Granted Patent B2
US 12,671,715 · App. 18/672,024 · Granted Jun 30, 2026

Detecting and mitigating forged authentication attacks within a domain

Inventors: Jason Crabtree (Vienna, VA); Andrew Sellers (Monument, CO)
Assignee: QOMPLX LLC
H04L63/1466H04L9/0643H04L63/1416H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,671,715
App. No.
18/672,024
Granted
Jun 30, 2026
Kind
B2
Abstract

A system for detecting and mitigating attacks using forged authentication objects within a domain is provided, comprising an authentication object inspector configured to observe a new authentication object generated by an identity provider, and retrieve the new authentication object; and a hashing engine configured to retrieve the new authentication object from the authentication object inspector, calculate a cryptographic hash for the new authentication object, and store the cryptographic hash for the new authentication object in a data store; wherein subsequent access requests accompanied by authentication objects are validated by comparing hashes for each authentication object to previous generated hashes.

Claims (45)

1 . A computing system for detecting and mitigating forged authentication attacks within a domain, comprising:

one or more hardware processors configured for:

receiving and storing a plurality of first authentication objects known to be generated by an identity provider associated with an authentication domain;

calculating and storing an authentication object identifier for each first authentication object;

receiving a request for access to a network resource associated with the authentication domain accompanied by a second authentication object;

calculating an authentication object identifier of the second authentication object;

determining whether the authentication object identifier of the second authentication object matches the stored first authentication object identifier; and

when the authentication object identifier of the second authentication object does not match the stored first authentication object identifier, generating a notification that the identity provider may be compromised.

2 . The computing system of claim 1 , wherein the authentication object identifiers are calculated by performing a plurality of calculations and transformations on each received authentication object.

3 . The computing system of claim 1 , wherein the computing system is operated by the identity provider.

4 . The computing system of claim 1 , wherein the computing system is operated by a client device communicating with the identity provider over a network.

5 . The computing system of claim 1 , wherein the computing system is operated by a Software-as-a-Service provider or a client-hosted device communicating with the identity provider, endpoint, or network infrastructure devices over a network.

6 . A computer-implemented method for detecting and mitigating forged authentication attacks within a domain, the computer-implemented method comprising:

receiving and storing a plurality of first authentication objects known to be generated by an identity provider associated with an authentication domain;

calculating and storing an authentication object identifier for each first authentication object;

receiving a request for access to a network resource associated with the authentication domain accompanied by a second authentication object;

calculating an authentication object identifier of the second authentication object;

determining whether the authentication object identifier of the second authentication object matches the stored first authentication object identifier; and

when the authentication object identifier of the second authentication object does not match the stored first authentication object identifier, generating a notification that the identity provider may be compromised.

7 . The computer-implemented method of claim 6 , wherein the authentication object identifiers are calculated by performing a plurality of calculations and transformations on each received authentication object.

8 . The computer-implemented method of claim 6 , wherein the computing system is operated by the identity provider.

9 . The computer-implemented method of claim 6 , wherein the computing system is operated by a client device communicating with the identity provider over a network.

10 . The computer-implemented method of claim 6 , wherein the computing system is operated by a Software-as-a-Service provider or a client-hosted device communicating with the identity provider, endpoint, or network infrastructure devices over a network.

11 . A system for detecting and mitigating forged authentication attacks within a domain, comprising one or more computers with executable instructions that, when executed, cause the system to:

receive and store a plurality of first authentication objects known to be generated by an identity provider associated with an authentication domain;

calculate and store an authentication object identifier for each first authentication object;

receive a request for access to a network resource associated with the authentication domain accompanied by a second authentication object;

calculate an authentication object identifier of the second authentication object;

determine whether the authentication object identifier of the second authentication object matches the stored first authentication object identifier; and

when the authentication object identifier of the second authentication object does not match the stored first authentication object identifier, generate a notification that the identity provider may be compromised.

12 . The system of claim 11 , wherein the authentication object identifiers are calculated by performing a plurality of calculations and transformations on each received authentication object.

13 . The system of claim 11 , wherein the computing system is operated by the identity provider.

14 . The system of claim 11 , wherein the computing system is operated by a client device communicating with the identity provider over a network.

15 . The system of claim 11 , wherein the computing system is operated by a Software-as-a-Service provider or a client-hosted device communicating with the identity provider, endpoint, or network infrastructure devices over a network.

16 . Non-transitory, computer-readable storage media having computer-executable instructions embodied thereon that, when executed by one or more processors of a computing system for detecting and mitigating forged authentication attacks within a domain, cause the computing system to:

receive and store a plurality of first authentication objects known to be generated by an identity provider associated with an authentication domain;

calculate and store an authentication object identifier for each first authentication object;

receive a request for access to a network resource associated with the authentication domain accompanied by a second authentication object;

calculate an authentication object identifier of the second authentication object;

determine whether the authentication object identifier of the second authentication object matches the stored first authentication object identifier; and

when the authentication object identifier of the second authentication object does not match the stored first authentication object identifier, generate a notification that the identity provider may be compromised.

17 . The non-transitory, computer-readable storage media of claim 16 , wherein the authentication object identifiers are calculated by performing a plurality of calculations and transformations on each received authentication object.

18 . The non-transitory, computer-readable storage media of claim 16 , wherein the computing system is operated by the identity provider.

19 . The non-transitory, computer-readable storage media of claim 16 , wherein the computing system is operated by a client device communicating with the identity provider over a network.

20 . The non-transitory, computer-readable storage media of claim 16 , wherein the computing system is operated by a Software-as-a-Service provider or a client-hosted device communicating with the identity provider, endpoint, or network infrastructure devices over a network.

Assignments (3)
CHANGE OF NAME Recorded Jul 8, 2024
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 067930/0619 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 6, 2024
From: CRABTREE, JASON; SELLERS, ANDREW
To: QOMPLX, INC.
Reel/Frame 067920/0477 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 6, 2024
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 068969/0262 →
Continuity (18)
Continuation 18501977 · Nov 3, 2023
Continuation 17974257 · Oct 26, 2022
Continuation 17169924 · Feb 8, 2021
Continuation In Part 15837845 · Dec 11, 2017
Continuation In Part 15825350 · Nov 29, 2017
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 15655113 · Jul 20, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15206195 · Jul 8, 2016
Continuation In Part 15186453 · Jun 18, 2016
Continuation In Part 15166158 · May 26, 2016
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 15091563 · Apr 5, 2016
Continuation In Part 14986536 · Dec 31, 2015
Continuation In Part 14925974 · Oct 28, 2015
Provisional Application 62596105 · Dec 7, 2017
Related Publication 20240314162A1 · Sep 19, 2024
References Cited (83)
US 5669000A · Jessen et al. · 1997 [cited by applicant]
US 6256544B1 · Weissinger · 2001 [cited by applicant]
US 6477572B1 · Elderton et al. · 2002 [cited by applicant]
US 7281125B2 · Challener et al. · 2007 [cited by applicant]
US 7702821B2 · Feinberg et al. · 2010 [cited by applicant]
US 7743421B2 · Cosquer et al. · 2010 [cited by applicant]
US 8281121B2 · Nath et al. · 2012 [cited by applicant]
US 8601554B2 · Gordon et al. · 2013 [cited by applicant]
US 8601587B1 · Powell et al. · 2013 [cited by applicant]
US 8615800B2 · Baddour et al. · 2013 [cited by applicant]
US 8793758B2 · Raleigh et al. · 2014 [cited by applicant]
US 8914878B2 · Burns et al. · 2014 [cited by applicant]
US 9137024B2 · Swingler et al. · 2015 [cited by applicant]
US 9185124B2 · Chakraborty · 2015 [cited by applicant]
US 9202040B2 · Rosenblatt et al. · 2015 [cited by applicant]
US 9253643B2 · Pattar et al. · 2016 [cited by applicant]
US 9292692B2 · Wallrabenstein · 2016 [cited by applicant]
US 9602530B2 · Ellis et al. · 2017 [cited by applicant]
US 9652604B1 · Johansson et al. · 2017 [cited by applicant]
US 9654495B2 · Hubbard et al. · 2017 [cited by applicant]
US 9762443B2 · Dickey · 2017 [cited by applicant]
US 9781144B1 · Otvagin et al. · 2017 [cited by applicant]
US 9887933B2 · Lawrence, III · 2018 [cited by applicant]
US 10038559B2 · Burrows et al. · 2018 [cited by applicant]
US 10061635B2 · Ellwein · 2018 [cited by applicant]
US 10242406B2 · Kumar et al. · 2019 [cited by applicant]
US 10248910B2 · Crabtree et al. · 2019 [cited by applicant]
US 10305902B2 · Kim · 2019 [cited by applicant]
US 10367829B2 · Huang et al. · 2019 [cited by applicant]
US 10410214B2 · Doyle · 2019 [cited by applicant]
US 10445482B2 · Ren · 2019 [cited by examiner]
US 10628578B2 · Eksten et al. · 2020 [cited by applicant]
US 10645086B1 · Hadler · 2020 [cited by applicant]
US 10791131B2 · Nor et al. · 2020 [cited by applicant]
US 20030041254A1 · Challener et al. · 2003 [cited by applicant]
US 20030145225A1 · Bruton, III et al. · 2003 [cited by applicant]
US 20050021025A1 · Buysse et al. · 2005 [cited by applicant]
US 20060002556A1 · Paul · 2006 [cited by examiner]
US 20070150744A1 · Cheng et al. · 2007 [cited by applicant]
US 20080021866A1 · Hinton et al. · 2008 [cited by applicant]
US 20090089227A1 · Sturrock et al. · 2009 [cited by applicant]
US 20090094372A1 · Nyang · 2009 [cited by examiner]
US 20090182672A1 · Doyle · 2009 [cited by applicant]
US 20090222562A1 · Liu et al. · 2009 [cited by applicant]
US 20110087888A1 · Rennie · 2011 [cited by examiner]
US 20120266244A1 · Green et al. · 2012 [cited by applicant]
US 20130073062A1 · Smith et al. · 2013 [cited by applicant]
US 20130117831A1 · Hook et al. · 2013 [cited by applicant]
US 20130132149A1 · Wei et al. · 2013 [cited by applicant]
US 20130304623A1 · Kumar et al. · 2013 [cited by applicant]
US 20140156806A1 · Karpistsenko et al. · 2014 [cited by applicant]
US 20140159150A1 · Kirisawa · 2014 [cited by applicant]
US 20140279762A1 · Xaypanya et al. · 2014 [cited by applicant]
US 20150128258A1 · Novozhenets · 2015 [cited by applicant]
US 20150149979A1 · Talby et al. · 2015 [cited by applicant]
US 20150163242A1 · Laidlaw et al. · 2015 [cited by applicant]
US 20150169294A1 · Brock et al. · 2015 [cited by applicant]
US 20150195192A1 · Vasseur et al. · 2015 [cited by applicant]
US 20150281225A1 · Schoen · 2015 [cited by examiner]
US 20150317481A1 · Gardner et al. · 2015 [cited by applicant]
US 20150339263A1 · Abu El Ata et al. · 2015 [cited by applicant]
US 20150379424A1 · Dirac et al. · 2015 [cited by applicant]
US 20160028758A1 · Ellis et al. · 2016 [cited by applicant]
US 20160072845A1 · Chiviendacz et al. · 2016 [cited by applicant]
US 20160078361A1 · Brueckner et al. · 2016 [cited by applicant]
US 20160140519A1 · Trepca et al. · 2016 [cited by applicant]
US 20160275123A1 · Lin et al. · 2016 [cited by applicant]
US 20160285732A1 · Brech et al. · 2016 [cited by applicant]
US 20160364307A1 · Garg et al. · 2016 [cited by applicant]
US 20170019678A1 · Kim et al. · 2017 [cited by applicant]
US 20170075543A1 · Ainalem · 2017 [cited by applicant]
US 20170126712A1 · Crabtree et al. · 2017 [cited by applicant]
US 20170139763A1 · Ellwein · 2017 [cited by applicant]
US 20170149802A1 · Huang et al. · 2017 [cited by applicant]
US 20170193110A1 · Crabtree et al. · 2017 [cited by applicant]
US 20170323089A1 · Duggal et al. · 2017 [cited by applicant]
US 20180300930A1 · Kennedy et al. · 2018 [cited by applicant]
US 20190082305A1 · Proctor · 2019 [cited by applicant]
US 20210099868A1 · Damlaj et al. · 2021 [cited by applicant]
WO 2014159150A1 · 2014 [cited by applicant]
WO 2017075543A1 · 2017 [cited by applicant]
Kbar, Ghassan. “Wireless network token-based fast authentication.” 2010 17th International Conference on Telecommunications. IEEE, 2010. (Year: 2010). [cited by examiner]
Kbar, “Wireless Network Token-Based Fast Authentication”, 2010, 17th International Conference on Telecommunications, p. 227-233. [cited by applicant]