IP Library Granted Patent US 12,231,426
Granted Patent B2
US 12,231,426 · App. 18/885,510 · Granted Feb 18, 2025

Contextual and risk-based multi-factor authentication

Inventors: Jason Crabtree (Vienna, VA); Andrew Sellers (Monument, CO); Ian MacLeod (Arlington, VA)
Assignee: QOMPLX LLC
H04L63/0861H04L43/04H04L63/083H04L63/0876H04L63/105H04L63/1433H04L63/1408H04L2463/082
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,231,426
App. No.
18/885,510
Granted
Feb 18, 2025
Kind
B2
Abstract

A system for contextual and risk-based multi-factor authentication having a multi-dimensional time series data server configured to monitor and record a network's traffic data and to serve the traffic data to other modules and a directed computation graph module configured to receive network traffic data from the multi-dimensional time series data server, determine a network traffic baseline from the network traffic data, and determine a verification score needed before granting access based at least in part by the network traffic baseline. A plurality of verification methods build up a user's verification score to required level to gain access.

Claims (99)

1. A computer system configured to execute software instructions stored on nontransitory machine-readable storage media, wherein the software instructions comprise instructions that:

receive a request to authenticate a client, wherein the request comprises a first identifier and a password,

store, in a multidimensional time-series database, information about the request,

determine whether the password corresponds to a first user account identified by the first identifier,

determine whether an additional verification is required to grant access,

wherein determining whether the additional verification is required to grant access comprises:

retrieving, from the multidimensional time-series database, historical information about previous access requests associated with the first user account, and

determining, based at least on the historical information, whether the first user account is associated with a previous request to authenticate, wherein the previous request to authenticate comprised a second identifier not associated with the first user account; and,

based on the additional verification being required to grant access:

select an additional verification method from a plurality of verification methods,

cause the client to be prompted to complete the additional verification method, and

determine whether the additional verification method has been completed correctly.

2. The computer system of claim 1 , wherein determining whether the additional verification is required to grant access further comprises processing endpoint data from entities connected to the network.

3. The computer system of claim 1 , wherein determining whether the additional verification is required to grant access further comprises processing an external threat intelligence feed.

4. The computer system of claim 1 , wherein the second identifier is associated with a second user account, and wherein the second user account is different from the first user account.

5. The computer system of claim 1 , wherein the software instructions further comprise instructions that:

based on the additional verification being required to grant access;

determine that a probable cyberattack is detected, and

provide an alert,

wherein the alert includes the first identifier and an indicator that a probable cyberattack is detected, and

wherein the alert is designated to be provided to an administrator of the network.

6. The computer system of claim 5 , wherein the alert further includes an indication of where the probable cyberattack may have originated.

7. The computer system of claim 5 , wherein the alert further includes an indication of what enterprise information may be at risk in the probable cyberattack.

8. The computer system of claim 5 , wherein the alert further includes predictive information.

9. A method implemented on a computer system connected to a network, the method comprising:

receiving a request to authenticate a client, wherein the request comprises a first identifier and a password,

storing, in a multidimensional time-series database, information about the request,

determining whether the password corresponds to a first user account identified by the first identifier,

determining whether an additional verification is required to grant access,

wherein determining whether the additional verification is required to grant access comprises:

retrieving, from the multidimensional time-series database, historical information about previous access requests associated with the first user account,

determining, based at least on the historical information, whether the first user account is associated with a previous request to authenticate, wherein the previous request to authenticate comprised a second identifier not associated with the first user account; and,

based on the additional verification being required to grant access:

selecting an additional verification method from a plurality of verification methods,

causing the client to be prompted to complete the additional verification method, and

determining whether the additional verification method has been completed correctly.

10. The method of claim 9 , wherein determining whether the additional verification is required to grant access further comprises processing endpoint data from entities connected to the network.

11. The method of claim 9 , wherein determining whether the additional verification is required to grant access further comprises processing an external threat intelligence feed.

12. The method of claim 9 , wherein the second identifier is associated with a second user account, and wherein the second user account is different from the first user account.

13. The method of claim 9 , further comprising:

based on the additional verification being required to grant access:

determining that a probable cyberattack is detected, and

delivering an alert,

wherein the alert includes the first identifier and an indicator that a probable cyberattack is detected, and

wherein the alert is designated to be delivered to an administrator of the network.

14. The method of claim 13 , wherein the alert further includes an indication of where the probable cyberattack may have originated.

15. The method of claim 13 , wherein the alert further includes an indication of what enterprise information may be at risk in the probable cyberattack.

16. The method of claim 13 , wherein the alert further includes predictive information.

17. The method of claim 12 , further comprising:

based on the additional verification being required to grant access:

determining that a probable cyberattack is detected, and

delivering an alert,

wherein the alert includes the first identifier and an indicator that a probable cyberattack is detected, and

wherein the alert is designated to be delivered to an administrator of the network.

18. The method of claim 17 , wherein the alert further includes predictive information.

19. A computer system configured to execute software instructions stored on nontransitory machine-readable storage media, wherein the software instructions comprise instructions that:

receive a request to authenticate a client, wherein the request comprises a first identifier and a password,

store, in a multidimensional time-series database, information about the request,

determine whether the password corresponds to a user account identified by the first identifier,

determine whether an additional verification is required to grant access,

wherein determining whether the additional verification is required to grant access comprises:

retrieving, from the multidimensional time-series database, historical information about previous access requests associated with the user account,

determining, based at least on the historical information, whether the user account is associated with a plurality of previous requests to authenticate, wherein the plurality of previous requests to authenticate comprises at least one second identifier not associated with any user account; and,

based on the additional verification being required to grant access:

select an additional verification method from a plurality of verification methods,

cause the client to be prompted to complete the additional verification method, and

determine whether the additional verification method has been completed correctly.

20. The computer system of claim 19 , wherein determining whether the additional verification is required to grant access further comprises processing endpoint data from entities connected to the network.

21. The computer system of claim 19 wherein determining whether the additional verification is required to grant access further comprises processing an external threat intelligence feed.

22. The computer system of claim 19 , wherein selecting an additional verification method from a plurality of verification methods comprises processing at least a portion of the plurality of previous requests to authenticate.

23. The computer system of claim 19 , wherein the software instructions further comprise instructions that:

based on the additional verification being required to grant access:

determine that a probable cyberattack is detected, and

provide an alert,

wherein the alert includes the first identifier and an indicator that a probable cyberattack is detected, and

wherein the alert is designated to be provided to an administrator of the network.

24. The computer system of claim 23 , wherein the alert further includes an indication of where the probable cyberattack may have originated.

25. The computer system of claim 23 , wherein the alert further includes an indication of what enterprise information may be at risk in the probable cyberattack.

26. A method implemented on a computer system connected to a network, the method comprising:

receiving a request to authenticate a client, wherein the request comprises a first identifier and a password,

storing, in a multidimensional time-series database, information about the request,

determining whether the password corresponds to a user account identified by the first identifier,

determining whether an additional verification is required to grant access,

wherein determining whether the additional verification is required to grant access comprises:

retrieving, from the multidimensional time-series database, historical information about previous access requests associated with the user account,

determining, based at least on the historical information, whether the user account is associated with a plurality of previous requests to authenticate, wherein the plurality of previous requests to authenticate comprises at least one second identifier not associated with any user account; and

based on the additional verification being required to grant access:

selecting an additional verification method from a plurality of verification methods,

causing the client to be prompted to complete the additional verification method, and

determining whether the additional verification method has been completed correctly.

27. The method of claim 26 , wherein determining whether the additional verification is required to grant access further comprises processing endpoint data from entities connected to the network.

28. The method of claim 26 , wherein determining whether the additional verification is required to grant access further comprises processing an external threat intelligence feed.

29. The method of claim 26 , wherein selecting an additional verification method from a plurality of verification methods comprises processing at least a portion of the plurality of previous requests to authenticate.

30. The method of claim 29 , further comprising:

based on the additional verification being required to grant access:

determining that a probable cyberattack is detected, and

delivering an alert,

wherein the alert includes the first identifier and an indicator that a probable cyberattack is detected, and

wherein the alert is designated to be delivered to an administrator of the network.

Assignments (4)
CHANGE OF NAME Recorded Sep 28, 2024
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 069070/0283 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 26, 2024
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 069053/0339 →
CHANGE OF NAME Recorded Sep 18, 2024
From: FRACTAL INDUSTRIES, INC.
To: QOMPLX, INC.
Reel/Frame 068989/0708 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 15, 2024
From: CRABTREE, JASON; SELLERS, ANDREW; MACLEOD, IAN
To: FRACTAL INDUSTRIES, INC.
Reel/Frame 068590/0988 →
Continuity (16)
Continuation 18464623 · Sep 11, 2023
Continuation 17539137 · Nov 30, 2021
Continuation 16856827 · Apr 23, 2020
Continuation 15790860 · Oct 23, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15206195 · Jul 8, 2016
Continuation In Part 15186453 · Jun 18, 2016
Continuation In Part 15166158 · May 26, 2016
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 15091563 · Apr 5, 2016
Continuation In Part 14986536 · Dec 31, 2015
Continuation In Part 14925974 · Oct 28, 2015
Continuation In Part 14925974 · Oct 28, 2015
Provisional Application 62574708 · Oct 19, 2017
Related Publication 20250016154A1 · Jan 9, 2025
References Cited (56)
US 6256544B1 · Weissinger · 2001 [cited by examiner]
US 6477572B1 · Elderton · 2002 [cited by examiner]
US 6857073B2 · French · 2005 [cited by examiner]
US 7139747B1 · Najork · 2006 [cited by examiner]
US 7171515B2 · Ohta · 2007 [cited by examiner]
US 7227948B2 · Ohkuma · 2007 [cited by examiner]
US 7310632B2 · Meek · 2007 [cited by examiner]
US 7322044B2 · Hrastar · 2008 [cited by examiner]
US 7530105B2 · Gilbert · 2009 [cited by examiner]
US 7546333B2 · Alon · 2009 [cited by examiner]
US 7685296B2 · Brill · 2010 [cited by examiner]
US 7818224B2 · Boerner · 2010 [cited by examiner]
US 7818417B2 · Ginis · 2010 [cited by examiner]
US 7925561B2 · Xu · 2011 [cited by examiner]
US 8069190B2 · McColl · 2011 [cited by examiner]
US 8346753B2 · Hayes · 2013 [cited by examiner]
US 8457996B2 · Winkler · 2013 [cited by examiner]
US 8751867B2 · Marvasti · 2014 [cited by examiner]
US 8832840B2 · Zhu · 2014 [cited by examiner]
US 8949960B2 · Berkman · 2015 [cited by examiner]
US 9069976B2 · Toole · 2015 [cited by examiner]
US 9110706B2 · Yu · 2015 [cited by examiner]
US 9152727B1 · Balducci · 2015 [cited by examiner]
US 9256735B2 · Stute · 2016 [cited by examiner]
US 9400962B2 · Prasad · 2016 [cited by examiner]
US 9466041B2 · Simitsis · 2016 [cited by examiner]
US 9558220B2 · Nixon · 2017 [cited by examiner]
US 9560065B2 · Neil · 2017 [cited by examiner]
US 9652538B2 · Shivaswamy · 2017 [cited by examiner]
US 9774522B2 · Vasseur · 2017 [cited by examiner]
US 10044726B2 · Dulkin · 2018 [cited by examiner]
US 10191768B2 · Bishop · 2019 [cited by examiner]
US 10210246B2 · Stojanovic · 2019 [cited by examiner]
US 10216485B2 · Misra · 2019 [cited by examiner]
US 10270748B2 · Briceno · 2019 [cited by examiner]
US 10333992B2 · Kinder · 2019 [cited by examiner]
US 10643144B2 · Bowers · 2020 [cited by examiner]
US 10846391B1 · Bonney · 2020 [cited by examiner]
US 20050000165A1 · Dischinat · 2005 [cited by examiner]
US 20050165822A1 · Yeung · 2005 [cited by examiner]
US 20070226796A1 · Gilbert · 2007 [cited by examiner]
US 20110307467A1 · Severance · 2011 [cited by examiner]
US 20130111592A1 · Zhu · 2013 [cited by examiner]
US 20130117852A1 · Stute · 2013 [cited by examiner]
US 20140324521A1 · Mun · 2014 [cited by examiner]
US 20140359552A1 · Misra · 2014 [cited by examiner]
US 20150020199A1 · Neil · 2015 [cited by examiner]
US 20150319156A1 · Guccione · 2015 [cited by examiner]
US 20160006629A1 · Ianakiev · 2016 [cited by examiner]
US 20160012235A1 · Lee · 2016 [cited by examiner]
US 20160275123A1 · Lin · 2016 [cited by examiner]
US 20170090893A1 · Aditya · 2017 [cited by examiner]
US 20180082304A1 · Summerlin · 2018 [cited by examiner]
Huang, Alex, A Comparison of Value at Risk Approaches and a New Method with Extreme Value Theory and Kernel Estimator. [cited by applicant]
Marozzo, Fabrizio; Talia, Domenico; Trunfio, Paolo; P2P-MapReduce—Parallel Data Processing in Dynamic Cloud Environments, Journal of Computer and System Sciences, 78 (2012) 1382-1402. [cited by applicant]
Simonian, Joseph, Davis, Josh., Robust Value-At-Risk: An Information Theoretic Approach, Applied Economic Letters, 2010, 17, 1551-1553. [cited by applicant]