IP Library Granted Patent US 11,962,586
Granted Patent B2
US 11,962,586 · App. 17/329,761 · Granted Apr 16, 2024

Secondary multifactor authentication

Inventor: Ashish Gujarathi (Parkland, FL)
H04L63/0876H04L63/107H04L63/108
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,962,586
App. No.
17/329,761
Filed
May 25, 2021
Granted
Apr 16, 2024
Kind
B2
Art Unit
2498
USPC
726/6
Abstract

Described embodiments provide systems, methods, non-transitory computer-readable medium for initiating one-factor or multi-factor authentication. A device comprising one or more processors and coupled to memory. The device can receive a request to authenticate a user to enable access to an application by the user. The request can originate from an Internet Protocol (IP) address external to a network hosting the application. The device can determine that a previous request to authenticate the user originated from the IP address and was approved based on successful completion of multi-factor authentication by the user. The device can provide, responsive to the determination, the user with access to the application using one-factor authentication instead of the multi-factor authentication.

Claims (31)

1. A method comprising:

receiving, by a device, a request to authenticate a user to enable access to an application by the user, the request originating from an Internet Protocol (IP) address external to a network hosting the application;

determining, by the device, that a previous request to authenticate the user originated from the IP address and was approved based on successful completion of multi-factor authentication by the user; and

providing, by the device based on determining that the previous request to authenticate the user originated from the IP address and was approved based on successful completion of multi-factor authentication, the user with access to the application using one-factor authentication instead of the multi-factor authentication.

2. The method of claim 1 , further comprising determining, by the device, that a number of times that the user had authenticated from that IP address is greater than a second threshold.

3. The method of claim 2 , further comprising using the one-factor authentication instead of another multi-factor authentication responsive to determining that the user had authenticated the number of times from the IP address using the multi-factor authentication greater than the second threshold and within a threshold of a time period from the previous request.

4. The method of claim 1 , further comprising determining, by the device, that no other user has authenticated from the IP address within at least a time period from the previous request.

5. The method of claim 4 , further comprising using the one-factor authentication instead of another multi-factor authentication responsive to determining that the user had authenticated from the IP address using the multi-factor authentication within a threshold of the time period from the previous request and that no other user has authenticated from that IP address within at least the time period.

6. The method of claim 1 , further comprising determining, by the device, that a time of the request falls within an established time pattern for the user.

7. The method of claim 6 , further comprising using the one-factor authentication instead of another multi-factor authentication responsive to determining that the user had authenticated from the IP address using the multi-factor authentication within a threshold of a time period from the previous request and that the time of the request falls within the established time pattern for the user.

8. The method of claim 1 , further comprising identifying, by the device, that a second device with which the user has performed the multi-factor authentication is at a location of a third device having the IP address.

9. The method of claim 8 , further comprising using the one-factor authentication instead of another multi-factor authentication responsive to determining that the user had authenticated from the IP address using the multi-factor authentication within a threshold of a time period from the previous request and identifying that the second device is at the location of the third device.

10. A device comprising:

one or more processors, coupled to memory and configured to:

receive a request to authenticate a user to enable access to an application by the user, the request originating from an Internet Protocol (IP) address external to a network hosting the application;

determine that a previous request to authenticate the user originated from the IP address and was approved based on successful completion of multi-factor authentication by the user; and

provide, based on determining that the previous request to authenticate the user originated from the IP address and was approved based on successful completion of multi-factor authentication, the user with access to the application using one-factor authentication instead of the multi-factor authentication.

11. The device of claim 10 , wherein the one or more processors are further configured to determine that a number of times that the user had authenticated from that IP address is greater than a second threshold.

12. The device of claim 11 , wherein the one or more processors are further configured to use the one-factor authentication instead of another multi-factor authentication responsive to determining that the user had authenticated the number of times from the IP address using the multi-factor authentication greater than the second threshold and within a threshold of a time period from the previous request.

13. The device of claim 10 , wherein the one or more processors are further configured to determine that no other user has authenticated from the IP address within at least a time period from the previous request.

14. The device of claim 13 , wherein the one or more processors are further configured to use

the one-factor authentication instead of another multi-factor authentication responsive to determining that the user had authenticated from the IP address using the multi-factor authentication within a threshold of the time period from the previous request and that no other user has authenticated from that IP address within at least the time period.

15. The device of claim 10 , wherein the one or more processors are further configured to determine that a time of the request falls within an established time pattern for the user.

16. The device of claim 15 , wherein the one or more processors are further configured to use the one-factor authentication instead of another multi-factor authentication responsive to determining that the user had authenticated from the IP address using the multi-factor authentication within a threshold of a time period from the previous request and that the time of the request falls within the established time pattern for the user.

17. The device of claim 10 , wherein the one or more processors are further configured to identify that a second device with which the user has performed the multi-factor authentication is at a location of a third device having the IP address.

18. The device of claim 17 , wherein the one or more processors are further configured to use the one-factor authentication instead of another multi-factor authentication responsive to determining that the user had authenticated from the IP address using the multi-factor authentication within a threshold of a time period from the previous request and identifying that the second device is at the location of the third device.

19. A non-transitory computer-readable medium storing program instructions to cause one or more processors to:

receive a request to authenticate a user to enable access to an application by the user, the request originating from an Internet Protocol (IP) address external to a network hosting the application;

determine that a previous request to authenticate the user originated from the IP address and was approved based on successful completion of multi-factor authentication by the user; and

provide, based on determining that the previous request to authenticate the user originated from the IP address and was approved based on successful completion of multi-factor authentication, the user with access to the application using one-factor authentication instead of the multi-factor authentication.

20. The non-transitory computer-readable medium of claim 19 , wherein the program instructions cause the one or more processors to use the one-factor authentication instead of another multi-factor authentication responsive to determining that the user had authenticated from the IP address using the multi-factor authentication within a threshold of a time period from the previous request and identifying that a second device with which the user has performed the multi-factor authentication is at a location of a third device having the IP address.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 25, 2021
From: GUJARATHI, ASHISH
To: CITRIX SYSTEMS, INC.
Reel/Frame 056344/0563 →
Continuity (1)
Related Publication 20220385656A1 · Dec 1, 2022
Cited By (1)
US 12,225,003