IP Library › Granted Patent US 12,273,366
Granted Patent B2
US 12,273,366 · App. 17/539,816 · Granted Apr 8, 2025

Risk based session resumption

Inventor: Abhinav Bansal (San Jose, CA)
Assignee: Zscaler, Inc.
H04L63/1433H04L63/12H04L63/14H04L63/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,273,366
App. No.
17/539,816
Granted
Apr 8, 2025
Kind
B2
Abstract

The present disclosure relates to systems and methods for risk-based session resumption. The present disclosure addresses the security gaps in the access control workflow of an organization while significantly enhancing the user experience. Instead of users being inquired to reauthenticate at a periodic interval, the present disclosure provides risk-based session resumption and reauthentication established on a verdict determination based on changes detected in metadata. The present disclosure not only prevents unnecessary prompts for user to authenticate again but also improves the security profile of an organization as users need to reauthenticate only if something has changed, malicious activity is detected, and there is a real risk to access control.

Claims (56)

1. A method implemented by a user device, the method comprising steps of:

requesting a resource, by an agent operating on the user device, from a server, the resource is associated with any of an online application and a cloud service;

prompting the user for identity;

receiving user entry input for the identity and metadata, and providing the user entry input and metadata to the server for an authentication request;

receiving and storing a session cookie for the resource, wherein the user device has a session for the resource based on the session cookie;

after authenticating the request, listening for a change in the metadata, wherein the listening occurs continuously via the agent operating in a secure location on the user device;

responsive to the listening detecting a change in the metadata, providing the session cookie and the change in the metadata via the agent to the server; and

receiving a response from the server based on the change in the metadata, and accessing the resource based thereon.

2. The method of claim 1 , wherein the accessing the resource based thereon is based on a verdict issued by the server includes one of

resuming the session,

blocking the session, and

reauthenticating the session.

3. The method of claim 2 , wherein the reauthenticating the session based on the verdict issued by the server and is one of with or without one of multifactor authentication or post authentication.

4. The method of claim 1 , wherein the metadata includes an internet protocol (IP) address, and wherein, when there is a change in the IP address, the response includes accessing the resource via reauthenticating the session.

5. The method of claim 1 , wherein the metadata includes details related to the user device and wherein, when there is a change in the details, the response includes accessing the resource via reauthenticating the session with multifactor authentication.

6. The method of claim 1 , wherein the metadata includes installed applications on the user device, and wherein the steps comprise:

responsive to identifying, via the agent operating on the user device, a change in the installed applications on the user device, providing the session cookie and the change in the installed applications to the server; and

receiving a response from the server based thereon.

7. The method of claim 1 , wherein the metadata includes any of details related to the user device, user provided details, internet protocol (IP) address, network configuration, installed applications, installed certificates, geolocation, and network type.

8. The method of claim 7 , wherein the accessing the resource based thereon includes resuming the session based on minor changes to the metadata.

9. A non-transitory computer-readable medium comprising instructions that, when executed, cause a processor to perform the steps of:

requesting a resource, by an agent operating on a user device, from a server, the resource is associated with any of an online application and a cloud service;

prompting the user for identity;

receiving user entry input for the identity and metadata, and providing the user entry input and metadata to the server for an authentication request;

receiving and storing a session cookie for the resource, wherein the user device has a session for the resource based on the session cookie;

after authenticating the request, listening for a change in the metadata, wherein the listening occurs continuously via the agent operating in a secure location on the user device;

responsive to the listening detecting a change in the metadata, providing the session cookie and the change in the metadata via the agent to the server; and

receiving a response from the server based on the change in the metadata, and accessing the resource based thereon.

10. The non-transitory computer-readable medium of claim 9 , wherein the accessing the resource based thereon includes one of

resuming the session,

blocking the session, and

reauthenticating the session.

11. The non-transitory computer-readable medium of claim 10 , wherein the reauthenticating the session is one of with or without multifactor authentication.

12. The non-transitory computer-readable medium of claim 9 , wherein the metadata includes an internet protocol (IP) address, and wherein, when there is a change in the IP address, the response includes accessing the resource via reauthenticating the session.

13. The non-transitory computer-readable medium of claim 9 , wherein the metadata includes details related to the user device and wherein, when there is a change in the details, the response includes accessing the resource via reauthenticating the session with multifactor authentication.

14. The non-transitory computer-readable medium of claim 9 , wherein the metadata includes installed applications on the user device, and wherein the steps comprise:

responsive to identifying, via the agent operating on the user device, a change in the installed applications on the user device, providing the session cookie and the change in the installed applications to the server; and

receiving a response from the server based thereon.

15. The non-transitory computer-readable medium of claim 9 , wherein the metadata includes any of details related to the user device, internet protocol (IP) address, network configuration, installed applications, installed certificates, geolocation, and network type.

16. The non-transitory computer-readable medium of claim 15 , wherein the accessing the resource based thereon includes resuming the session based on minor changes to the metadata.

17. A user device comprising:

a processing device;

a memory device configured to store a computer program having instructions that, when executed, cause the processing device to perform the steps of:

requesting a resource, by an agent operating on the user device, from a server, the resource is associated with any of an online application and a cloud service;

prompting the user for identity;

receiving user entry input for the identity and metadata, and providing the user entry input and metadata to the server for an authentication request;

receiving and storing a session cookie for the resource, wherein the user device has a session for the resource based on the session cookie;

after authenticating the request, listening for a change in the metadata, wherein the listening occurs continuously via the agent operating in a secure location on the user device;

responsive to the listening detecting a change in the metadata, providing the session cookie and the change in the metadata via the agent to the server; and

receiving a response from the server based on the change in the metadata, and accessing the resource based thereon.

18. The server of claim 17 , wherein the accessing the resource based thereon includes one of

resuming the session,

blocking the session, and

reauthenticating the session.

19. The server of claim 18 , wherein the metadata includes details related to the user device and wherein, when there is a change in the details, the response includes accessing the resource via reauthenticating the session with or without multifactor authentication.

20. The server of claim 17 , wherein the metadata includes an internet protocol (IP) address, and wherein, when there is a change in the IP address, the response includes accessing the resource via reauthenticating the session.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 1, 2021
From: BANSAL, ABHINAV
To: ZSCALER, INC.
Reel/Frame 058259/0450 →
Continuity (1)
Related Publication 20230171280A1 · Jun 1, 2023
References Cited (26)
US 9621574B2 · Desai et al. · 2017 [cited by applicant]
US 9935955B2 · Desai et al. · 2018 [cited by applicant]
US 10225740B2 · Bansal et al. · 2019 [cited by applicant]
US 10243997B2 · Desai et al. · 2019 [cited by applicant]
US 10404733B1 · Shavell · 2019 [cited by examiner]
US 10579794B1 · Gates · 2020 [cited by examiner]
US 10708233B2 · Goyal et al. · 2020 [cited by applicant]
US 11295015B1 · Roundy · 2022 [cited by examiner]
US 20030200202A1 · Hsiao · 2003 [cited by examiner]
US 20090055912A1 · Choi · 2009 [cited by examiner]
US 20170223024A1 · Desai et al. · 2017 [cited by applicant]
US 20170289136A1 · Ramalingam · 2017 [cited by examiner]
US 20170331859A1 · Bansal et al. · 2017 [cited by applicant]
US 20180198791A1 · Desai et al. · 2018 [cited by applicant]
US 20190081981A1 · Bansal · 2019 [cited by applicant]
US 20190158503A1 · Bansal et al. · 2019 [cited by applicant]
US 20190332790A1 · Kukehalli Subramanya · 2019 [cited by examiner]
US 20200067949A1 · Bansal et al. · 2020 [cited by applicant]
US 20200077265A1 · Singh et al. · 2020 [cited by applicant]
US 20200110870A1 · Girdhar · 2020 [cited by examiner]
US 20200322414A1 · Ashraf · 2020 [cited by examiner]
US 20210105275A1 · Bansal et al. · 2021 [cited by applicant]
US 20210135869A1 · Barhudarian · 2021 [cited by examiner]
US 20210234860A1 · Bansal et al. · 2021 [cited by applicant]
US 20210288973A1 · Dimble · 2021 [cited by examiner]
US 20210390170A1 · Olden · 2021 [cited by examiner]