IP Library Granted Patent US 11,627,129
Granted Patent B2
US 11,627,129 · App. 17/070,602 · Granted Apr 11, 2023

Method and system for contextual access control

Inventors: Harsh Shah (Pompano Beach, FL); Manbinder Pal Singh (Coral Springs, FL); Rachelle Tobkes (Davie, FL); Jacob Summers (Coral Springs, FL)
Assignee: Citrix Systems, Inc.
H04L63/0876H04L63/102H04L63/1433H04L63/20H04L2463/082
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,627,129
App. No.
17/070,602
Granted
Apr 11, 2023
Kind
B2
Abstract

Described embodiments provide systems and methods for contextual confidence scoring-based access control. The systems and methods can include one or more processors configured to receive a request from the client device to access an item of content. The one or more processors can select a first subset of authentication techniques. The authentication techniques identifiable with a score. The one or more processors can determine that a sum of the scores of the selected first subset of the authentication techniques exceeds a threshold. The one or more processors can transmit, to the client device, one or more authentication requests utilizing the selected first subset of authentication techniques. The one or more processors can provide, responsive to successful authentication by the client device, access to the item of content to the client device.

Claims (50)

1. A method comprising:

receiving, by a computing device, a request from the client device to access an item of content;

selecting, by the computing device, responsive to receiving the request, a first subset of a plurality of authentication techniques associated with access to the item of content by the client device, each of the plurality of authentication techniques associated with a context score;

determining, by the computing device, that a sum of the context scores of the selected first subset of the plurality of authentication techniques exceeds a score threshold;

transmitting, by the computing device to the client device, responsive to the determination that the sum of the context scores exceeds the score threshold, one or more authentication requests utilizing the selected first subset of the plurality of authentication techniques;

receiving, from the client device, one or more responses to the one or more authentication requests comprising, for the first subset of the plurality of authentication techniques, an indication of successful or unsuccessful authentication;

comparing, by the computing device, a sum of the context scores of the plurality of authentication techniques having an indication of successful authentication in the one or more responses to the score threshold;

identifying, by the computing device, that the client device has not successfully authenticated, responsive to the sum of the context scores of each of the plurality of authentication techniques having the indication of successful authentication being less than the score threshold;

identifying, by the computing device, an additional authentication technique based on the additional authentication technique being associated with a context score that when added to the sum of the context scores of the plurality of authentication techniques having the indication of successful authentication exceeds the score threshold;

selecting, by the computing device, the identified additional authentication technique,

transmitting, by the computing device to the client device, an additional authentication request utilizing the selected additional authentication technique; and

providing, by the computing device responsive to successful authentication by the client device, access to the item of content to the client device.

2. The method of claim 1 , wherein selecting the first subset of the plurality of authentication techniques further comprises:

selecting a first authentication technique;

determining that the context score of the first authentication technique is less than the score threshold; and

selecting a second authentication technique responsive to the determination that the context score of the first authentication technique is less than the score threshold.

3. The method of claim 1 , further comprising:

receiving, from the client device, one or more responses to the one or more authentication requests comprising, for the plurality of authentication techniques, an indication of successful or unsuccessful authentication;

comparing, by the computing device, a sum of the context scores of the plurality of authentication techniques having an indication of successful authentication in the one or more responses to the score threshold; and

identifying, by the computing device, that the client device has successfully authenticated, responsive to the sum of the context scores of the plurality of authentication techniques having the indication of successful authentication exceeding the score threshold.

4. The method of claim 3 , wherein the indication of successful authentication comprises a match between a received value and a stored value for at least one authentication technique.

5. The method of claim 3 , wherein at least one response comprises an indication of unsuccessful authentication, and wherein the sum of the context scores of the plurality of authentication techniques having an indication of successful authentication in the one or more responses is less than the sum of the context scores of the selected first subset of the plurality of authentication techniques.

6. The method of claim 1 , further comprising increasing the context score of a first authentication technique of the plurality of authentication techniques responsive to an historical rate of successful authentication with the client device using the first authentication technique exceeding a threshold.

7. The method of claim 1 , further comprising decreasing the context score of a first authentication technique of the plurality of authentication techniques responsive to an historical rate of successful authentication with the client device using the first authentication technique being less than a threshold.

8. A system comprising:

a computing device comprising one or more processors and a network interface in communication with a client device;

wherein the one or more processors are configured to:

receive a request from the client device to access an item of content,

select, responsive to receiving the request, a first subset of a plurality of authentication techniques associated with access to the item of content by the client device, each of the plurality of authentication techniques associated with a context score,

determine that a sum of the context scores of the selected first subset of the plurality of authentication techniques exceeds a score threshold,

transmit, to the client device, responsive to the determination that the sum of the context scores exceeds the score threshold, one or more authentication requests utilizing the selected first subset of the plurality of authentication techniques,

receive, from the client device, one or more responses to the one or more authentication requests comprising, for the first subset of the plurality of authentication techniques, an indication of successful or unsuccessful authentication;

compare a sum of the context scores of the plurality of authentication techniques having an indication of successful authentication in the one or more responses to the score threshold;

identify that the client device has not successfully authenticated, responsive to the sum of the context scores of each of the plurality of authentication techniques having the indication of successful authentication being less than the score threshold;

identify an additional authentication technique based on the additional authentication technique being associated with a context score that when added to the sum of the context scores of the plurality of authentication techniques having the indication of successful authentication exceeds the score threshold;

select the identified additional authentication technique,

transmit, to the client device, an additional authentication request utilizing the selected additional authentication technique, and

provide, responsive to successful authentication by the client device, access to the item of content to the client device.

9. The system of claim 8 , wherein the one or more processors are further configured to:

select a first authentication technique;

determine that the context score of the first authentication technique is less than the score threshold; and

select a second authentication technique responsive to the determination that the context score of the first authentication technique is less than the score threshold.

10. The system of claim 8 , wherein the one or more processors are further configured to:

receive, from the client device, one or more responses to the one or more authentication requests comprising, for the plurality of authentication techniques, an indication of successful or unsuccessful authentication;

compare a sum of the context scores of the plurality of authentication techniques having an indication of successful authentication in the one or more responses to the score threshold; and

identify that the client device has successfully authenticated, responsive to the sum of the context scores of the plurality of authentication techniques having the indication of successful authentication exceeding the score threshold.

11. The system of claim 10 , wherein the indication of successful authentication comprises a match between a received value and a stored value for at least one authentication technique.

12. The system of claim 10 , wherein at least one response comprises an indication of unsuccessful authentication, and wherein the sum of the context scores of the plurality of authentication techniques having an indication of successful authentication in the one or more responses is less than the sum of the context scores of the selected first subset of the plurality of authentication techniques.

13. The system of claim 8 , wherein the one or more processors are further configured to increase the context score of a first authentication technique of the plurality of authentication techniques responsive to an historical rate of successful authentication with the client device using the first authentication technique exceeding a threshold.

14. The system of claim 8 , wherein the one or more processors are further configured to decrease the context score of a first authentication technique of the plurality of authentication techniques responsive to an historical rate of successful authentication with the client device using the first authentication technique being less than a threshold.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 20, 2020
From: SHAH, HARSH; SINGH, MANBINDER PAL; TOBKES, RACHELLE; SUMMERS, JACOB
To: CITRIX SYSTEMS, INC.
Reel/Frame 054110/0482 →
Continuity (1)
Related Publication 20220116392A1 · Apr 14, 2022
Cited By (1)
US 12,657,277