IP Library › Granted Patent US 12,743,532
Granted Patent B2
US 12,743,532 · App. 17/515,288 · Granted Sep 22, 2026

Dynamic security challenge authentication

Inventor: Nan Zheng (Nanjing, CN)
G06F21/6209G06F21/31G06F21/45G06F2221/2103G06F2221/2131
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,743,532
App. No.
17/515,288
Filed
Oct 29, 2021
Granted
Sep 22, 2026
Kind
B2
Art Unit
2494
USPC
726/19
Abstract

A method for dynamic security challenge authentication may include generating, based on data about one or more previous interactions of the user with a plurality of applications, files, and devices, one or more security challenges. Examples of interactions include launching an application, editing a file, and logging onto a device. The data may be retrieved from services or components involved with the interactions. The identity of the user may be authenticated based on the responses to the security challenges. Related systems and computer program products are also provided.

Claims (51)

1 . A system, comprising:

at least one data processor; and

at least one memory storing instructions, which when executed by the at least one data processor, cause the at least one data processor to at least:

receive a request to authenticate an identity of a user as part of a process to access one or more applications, the request including a user identifier;

receive a plurality of device identifiers for a plurality of devices associated with the user identifier;

retrieve, using each of the plurality of device identifiers, from one or more services or components configured to monitor usage on the plurality of devices, first data corresponding to one or more previous interactions of the user with the one or more applications on a respective device of the plurality of devices;

retrieve, according to the first data, from the one or more services or components, second data corresponding to one or more files including information indicative of access linked to the user identifier via a respective device;

generate, based on the first data and the second data, a security challenge including a question relating to the one or more previous interactions of the user via at least one of the plurality of devices; and

authenticate, using multi-factor authentication, based at least on a response to the question of the security challenge, the identity of the user to enable the user to access the one or more applications or a computing resource, wherein the response to the question is one factor in the multi-factor authentication.

2 . The system of claim 1 , wherein the security challenge is generated based on the one or more previous interactions that occurred within a threshold period of time.

3 . The system of claim 1 , wherein the one or more previous interactions include at least one of launching at least one of the one or more applications, editing a file, and logging onto a device of the plurality of devices.

4 . The system of claim 1 , wherein the first data and the second data are retrieved by at least one of querying a database and making an application programming interface (API) call.

5 . The system of claim 1 , wherein the at least one data processor is further caused to at least:

identify at least one the one or more applications that the user interacted with; and

generate, for the security challenge, at least one correct response corresponding to the at least one the one or more applications that the user interacted with.

6 . The system of claim 1 , wherein the at least one data processor is further caused to at least:

identify at least one of the one or more applications that the user did not interact with; and

generate, for the security challenge, at least one incorrect response corresponding to at least one of the one or more applications that the user did not interact with.

7 . The system of claim 1 , wherein the security challenge is in a multipart format, and wherein the identity of the user is authenticated in response to receiving a correct response to the question which is at least a first part of the security challenge.

8 . The system of claim 7 , wherein a second part of the security challenge is generated in response to receiving an incorrect response to the first part of the security challenge.

9 . The system of claim 1 , wherein the at least one data processor is further caused to at least:

in response to authenticating the identity of the user, perform at least one of a reset and recovery of a password associated with at least one of the one or more applications.

10 . The system of claim 1 , wherein the operations further comprise at least one data processor is further caused to at least:

in response to authenticating the identity of the user, enable access to at least one of the one or more applications.

11 . A computer-implemented method, comprising:

receiving a request to authenticate an identity of a user as part of a process to access one or more applications, the request including a user identifier;

receiving a plurality of device identifiers for a plurality of devices associated with the user identifier;

retrieving, using each of the plurality of device identifiers, from one or more services or components configured to monitor usage on the plurality of devices, first data corresponding to one or more previous interactions of the user with the one or more applications on a respective device of the plurality of devices;

retrieving, according to the first data, from the one or more services or components, second data corresponding to one or more files including information indicative of access linked to the user identifier via a respective device;

in response to the request, generating, based on the first data and the second data, a security challenge including a question relating to the one or more previous interactions of the user via at least one of the plurality of devices; and

authenticating, using multi-factor authentication, based at least on a response to the question of the security challenge, the identity of the user to enable the user to access the one or more applications or a computing resource, wherein the response to the question is one factor in the multi-factor authentication.

12 . The method of claim 11 , wherein the security challenge is generated based on the one or more previous interactions that occurred within a threshold period of time.

13 . The method of claim 11 , wherein the one or more previous interactions include at least one of launching at least one of the one or more applications, editing a file, and logging onto a device of the plurality of devices.

14 . The method of claim 11 , wherein the first data and the second data are retrieved by at least one of querying a database and making an application programming interface (API) call.

15 . The method of claim 11 , further comprising:

identifying at least one of the one or more applications that the user interacted with; and

generating, for the security challenge, at least one correct response corresponding to the at least one of the one or more applications that the user interacted with.

16 . The method of claim 11 , further comprising:

identifying at least one of the one or more applications that the user did not interact with; and

generating, for the security challenge, at least one incorrect response corresponding to at least one of the one or more applications that the user did not interact with.

17 . The method of claim 11 , wherein the security challenge is in a multipart format, and wherein the identity of the user is authenticated in response to receiving a correct response to the question which is at least a first part of the security challenge.

18 . The method of claim 17 , wherein a second part of the security challenge is generated in response to receiving an incorrect response to the first part of the security challenge.

19 . The method of claim 11 , further comprising:

in response to authenticating the identity of the user, performing at least one of a reset of a password associated with at least one of the one or more applications, a recovery of the password associated with at least one of the one or more applications, and an enablement of access to the at least one of the one or more applications.

20 . A non-transitory computer readable medium storing instructions, which when executed by at least one data processor, result in operations comprising:

receiving a request to authenticate an identity of a user as part of a process to access an one or more applications, the request including a user identifier;

receiving a plurality of device identifiers for a plurality of devices associated with the user identifier;

retrieving, using each of the plurality of device identifiers, from one or more services or components configured to monitor usage on the plurality of devices, first data corresponding to one or more previous interactions of the user with the one or more applications on a respective device of the plurality of devices;

retrieving, according to the first data, from the one or more services or components, second data corresponding to one or more files including information indicative of access linked to the user identifier via a respective device;

generating, based on the first data and the second data, a security challenge including a question relating to the one or more previous interactions of the user via at least one of the plurality of devices; and

authenticating, using multi-factor authentication, based at least on a response to the question of the security challenge, the identity of the user to enable the user to access the one or more applications or a computing resource, wherein the response to the question is one factor in the multi-factor authentication.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 12, 2021
From: ZHENG, NAN
To: CITRIX SYSTEMS, INC.
Reel/Frame 058096/0664 →
Continuity (2)
Continuation PCTCN2021122016 · Sep 30, 2021
Related Publication 20230098536A1 · Mar 30, 2023
References Cited (20)
US 9396316B1 · Altman · 2016 [cited by examiner]
US 10255558B1 · Kronrod · 2019 [cited by examiner]
US 11552953B1 · Avadhanam · 2023 [cited by examiner]
US 20100122329A1 · Jakobsson · 2010 [cited by examiner]
US 20110191838A1 · Yanagihara · 2011 [cited by examiner]
US 20140137219A1 · Castro · 2014 [cited by examiner]
US 20150026796A1 · Alan · 2015 [cited by examiner]
US 20160057110A1 · Li · 2016 [cited by examiner]
US 20160191498A1 · Marien · 2016 [cited by examiner]
US 20160378973A1 · Melzer · 2016 [cited by examiner]
US 20170317993A1 · Weber · 2017 [cited by examiner]
US 20180191699A1 · Assali · 2018 [cited by examiner]
US 20180205727A1 · Hwang · 2018 [cited by examiner]
US 20180295146A1 · Kovega · 2018 [cited by examiner]
US 20190188374A1 · Arunkumar · 2019 [cited by examiner]
US 20200110866A1 · Greenberger · 2020 [cited by examiner]
US 20200159731A1 · Gino · 2020 [cited by examiner]
US 20200380112A1 · Allen · 2020 [cited by examiner]
US 20210099458A1 · Su · 2021 [cited by examiner]
US 20230035570A1 · Edwards · 2023 [cited by examiner]