IP Library Granted Patent US 10,104,071
Granted Patent B2
US 10,104,071 · App. 15/825,523 · Granted Oct 16, 2018

Revoking sessions using signaling

Inventors: Ariel Gordon (Kirkland, WA); Samuel Devasahayam (Kirkland, WA); Lu Zhao (Redmond, WA); Yordan Rouskov (Seattle, WA); Parmeshwar Miguel Sequeira Arewar (Bothell, WA); Venkatesh Gopalakrishnan (Bellevue, WA); Sarat Chandra Subramaniam (Redmond, WA); Titus Constantin Miron (Seattle, WA)
Assignee: Microsoft Technology Licensing, LLC
H04L63/083H04L63/08H04L63/102H04L67/14H04L69/28H04L63/1416H04L67/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,104,071
App. No.
15/825,523
Granted
Oct 16, 2018
Kind
B2
Abstract

Embodiments are directed to revoking user sessions using signaling. In one scenario, an identity platform operating on a computer system receives an indication indicating that a user's login account has been compromised, where the user's login account has an associated login session and corresponding session artifact that is valid for a specified amount of time. The identity platform generates a signal indicating that the login session is no longer trusted and that the user is to be re-directed to the identity platform to re-authenticate and renew the session artifact and provides the generated signal to various relying parties including at least one relying party that is hosting the login session for the user.

Claims (45)

1. A computer system comprising:

one or more processors; and

one or more computer-readable hardware storage devices having stored thereon computer-executable instructions which, when executed by the one or more processors, cause the computer system to operate with an architecture that performs a method of improving user sign-in security by facilitating selective revocation of one or more sessions which purport to have been previously initiated by a user, and wherein the method comprises:

receiving at an identity platform sign-in credentials for a user who is signing into an application;

based on the sign-in credentials, initiating at the identity platform a new active session for the user;

determining that one or more additional sessions which purport to have been previously initiated by the user are active for the user such that the user is associated with multiple currently active sessions, wherein the multiple currently active sessions comprise the new active session and the one or more additional sessions;

at the identity platform, presenting to the user an identification of the multiple currently active sessions for the user;

in response to the identification of the multiple currently active sessions presented to the user at the identity platform, receiving at the identity platform the user's selection for revocation of one or more sessions for which the user's login credentials have been changed, or one or more sessions which purport to have been previously initiated by the user but are otherwise suspect;

the identity platform revoking the selected one or more sessions; and

the identity platform signaling one or more applications or one or more relying parties of the revocation.

2. The computer system of claim 1 , wherein execution of the computer-executable instructions further causes the computer system to cause subsequent sign-ins of the user to require an authentication means that is different than an authentication means that the user used when initially signing into the application.

3. The computer system of claim 1 , wherein a cookie file is stored on the computer system when the new active session is initiated for the user.

4. The computer system of claim 1 , wherein execution of the computer-executable instructions further causes the computer system to monitor a login activity associated with the user.

5. The computer system of claim 4 , wherein the login activity includes information corresponding to a geographic location where the user signed into the application.

6. The computer system of claim 1 , wherein the selected revocation is initiated by the user such that the user selectively chooses when the one or more sessions are to be revoked.

7. The computer system of claim 1 , wherein execution of the computer-executable instructions further causes the computer system to record a time corresponding to when the user signed into the application.

8. A method for operating an architecture that improves user sign-in security by selectively revoking a user session, the method being performed by a computer system that operates with the architecture, the method comprising:

receiving at an identity platform sign-in credentials for a user who is signing into an application;

based on the sign-in credentials, initiating at the identity platform a new active session for the user;

determining that one or more additional sessions which purport to have been previously initiated by the user are active for the user such that the user is associated with multiple currently active sessions, wherein the multiple currently active sessions comprise the new active session and the one or more additional sessions;

at the identity platform, presenting to the user an identification of the multiple currently active sessions for the user;

in response to the identification of the multiple currently active sessions presented to the user at the identity platform, receiving at the identity platform the user's selection for revocation of one or more sessions for which the user's login credentials have been changed, or one or more sessions which purport to have been previously initiated by the user but are otherwise suspect;

the identity platform revoking the selected one or more sessions; and

the identity platform signaling one or more applications or one or more relying parties of the revocation.

9. The method of claim 8 , wherein the method further includes:

after the new active session is initiated for the user, detecting an occurrence of a particular condition; and

in response to detecting the occurrence of the particular condition, requiring that the user sign into the application using an authentication means that is different than an authentication means that the user used when initially signing into the application.

10. The method of claim 8 , wherein a cookie file is stored on the computer system when the new active session is initiated for the user.

11. The method of claim 8 , wherein the method further includes monitoring a login activity associated with the user.

12. The method of claim 11 , wherein the login activity includes information corresponding to a geographic location where the user signed into the application.

13. The method of claim 8 , wherein the selective revocation is initiated by the user such that the user selectively chooses when the one or more sessions are to be revoked.

14. The method of claim 8 , wherein a time corresponding to when the user signed into the application is recorded.

15. One or more hardware storage devices having stored thereon computer-executable instructions which, when executed by one or more processors of a computer system, cause the computer system to operate with an architecture that performs a method of improving user sign-in security by facilitating selective revocation of one or more sessions which purport to have been previously initiated by a user, and wherein the method comprises:

receiving at an identity platform sign-in credentials for a user who is signing into an application;

based on the sign-in credentials, initiating at the identity platform a new active session for the user;

determining that one or more additional sessions which purport to have been previously initiated by the user are active for the user such that the user is associated with multiple currently active sessions, wherein the multiple currently active sessions comprise the new active session and the one or more additional sessions;

at the identity platform, presenting to the user an identification of the multiple currently active sessions for the user;

in response to the identification of the multiple currently active sessions presented to the user at the identity platform, receiving at the identity platform the user's selection for revocation of one or more sessions for which the user's login credentials have been changed, or one or more sessions which purport to have been previously initiated by the user but are otherwise suspect;

the identity platform revoking the selected one or more sessions; and

the identity platform signaling one or more applications or one or more relying parties of the revocation.

16. The one or more hardware storage devices of claim 15 , wherein execution of the computer-executable instructions further causes the computer system to cause subsequent sign-ins of the user to require an authentication means that is different than an authentication means that the user used when initially signing into the application.

17. The one or more hardware storage devices of claim 15 , wherein a cookie file is stored on the computer system when the new active session is initiated for the user.

18. The one or more hardware storage devices of claim 15 , wherein execution of the computer-executable instructions further causes the computer system to monitor a login activity associated with the user.

19. The one or more hardware storage devices of claim 18 , wherein the login activity includes information corresponding to a geographic location where the user signed into the application.

20. The one or more hardware storage devices of claim 15 , wherein the selective revocation is initiated by the user such that the user selectively chooses when the one or more sessions are to be revoked.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 7, 2018
From: GORDON, ARIEL; DEVASAHAYAM, SAMUEL; ZHAO, LU; ROUSKOV, YORDAN; AREWAR, PARMESHWAR; GOPALAKRISHNAN, VENKATESH; SUBRAMANIAM, SARAT CHANDRA; MIRON, TITUS CONSTANTIN
To: MICROSOFT CORPORATION
Reel/Frame 046569/0238 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 7, 2018
From: MICROSOFT CORPORATION
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 046569/0431 →
Continuity (3)
Continuation 15365726 · Nov 30, 2016
Division 14452726 · Aug 6, 2014
Related Publication 20180139200A1 · May 17, 2018
Cited By (86)
US 12,206,696 US 12,244,621 US 12,267,345 US 12,309,185 US 12,323,449 US 12,335,286 US 12,335,348 US 12,341,797 US 12,348,545 US 12,355,626 US 12,355,787 US 12,355,793 US 12,363,148 US 12,368,745 US 12,368,746 US 12,368,747 US 12,375,573 US 12,395,573 US 12,401,669 US 12,405,849 US 12,407,701 US 12,407,702 US 12,418,552 US 12,418,555 US 12,425,428 US 12,425,430 US 12,445,474 US 12,452,279 US 12,457,231 US 12,463,995 US 12,463,996 US 12,463,997 US 12,464,003 US 12,470,577 US 12,470,578 US 12,483,576 US 12,489,770 US 12,495,052 US 12,500,910 US 12,500,911 US 12,500,912 US 12,505,126 US 12,506,762 US 12,513,221 US 12,537,836 US 12,537,837 US 12,537,839 US 12,537,840 US 12,537,884 US 12,549,575 US 12,549,577 US 12,556,548 US 12,556,559 US 12,563,060 US 12,563,064 US 12,563,071 US 12,563,072 US 12,580,934 US 12,580,935 US 12,580,936 US 12,580,937 US 12,587,553 US 12,592,950 US 12,598,205 US 12,613,930 US 12,615,271 US 12,621,324 US 12,621,329 US 12,627,686 US 12,627,687 US 12,627,690 US 12,634,312 US 12,634,376 US 12,652,302 US 12,659,325 US 12,659,326 US 12,659,327 US 12,659,333 US 12,676,874 US 12,689,638 US 12,689,640 US 12,695,768 US 12,706,932 US 12,706,933 US 12,712,897 US 12,719,896