IP Library Granted Patent US 10,326,748
Granted Patent B1
US 10,326,748 · App. 14/631,826 · Granted Jun 18, 2019

Systems and methods for event-based authentication

Inventors: Michel Albert Brisebois (Renfrew, CA); Curtis T. Johnstone (Ottawa, CA)
Assignee: Quest Software Inc.
H04L63/08G06F21/31
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,326,748
App. No.
14/631,826
Granted
Jun 18, 2019
Kind
B1
Abstract

In one embodiment, a method is performed by a computer system. The method includes receiving a request to authenticate a user of an enterprise computing system. The method further includes, responsive to the request, selecting a set of previous user-initiated events of the user on the enterprise computing platform. Further, the method includes accessing user-specific event information related to the selected set of previous user-initiated events. In addition, the method includes generating, from at least a portion of the user-specific event information, a user-specific authentication sequence comprising a plurality of event-information requests. Additionally, the method includes administering the user-specific authentication sequence to the user, the administering comprising requiring the user to provide a valid response to each of the event-information requests as a precondition to successful authentication.

Claims (42)

1. A method of dynamic event-based authentication comprising, by a computer system:

receiving a request to authenticate a user of a user device currently accessing an enterprise computing system;

determining an authentication context of the request, the authentication context identifying at least the user device and a current physical location of the user device;

dynamically selecting an authentication template, from among a plurality of stored authentication templates, based, at least part, on a discrete level of security deemed warranted by the authentication context;

wherein the plurality of stored authentication templates each specify one or more user-initiated event types in combination with one or more corresponding user-initiated event requests;

responsive to the request, selecting a set of previous user-initiated events of the user on the enterprise computing platform based, at least part, on the specified one or more user-initiated event types of the dynamically selected authentication template, the previous user-initiated events each relating to a discrete user action with respect to a resource on the enterprise computing system;

accessing user-specific event information related to the selected set of previous user-initiated events, wherein the user-specific event information corresponds to a field of at least one of the one or more corresponding user-initiated event requests of the selected authentication template;

generating, from at least a portion of the user-specific event information, a user-specific authentication sequence comprising a plurality of event-information requests that conform to the one or more corresponding user-initiated event requests of the authentication template; and

administering the user-specific authentication sequence to the user, the administering comprising requiring the user to provide a valid response to each of the plurality of event-information requests as a precondition to successful authentication.

2. The method of claim 1 , wherein:

the authentication template specifies a form of the plurality of event-information requests; and

the generating comprises populating the authentication template with the at least a portion of the user-specific event information.

3. The method of claim 1 , wherein the authentication context comprises information related to a content-based classification of a network resource requested by the user.

4. The method of claim 1 , wherein the selecting comprises randomly selecting the set subject to one or more constraints.

5. The method of claim 4 , wherein the one or more constraints comprise event-timing information.

6. The method of claim 1 , wherein the user-specific authentication sequence is single-use.

7. The method of claim 1 , comprising, responsive to successful authentication, granting the user access to a requested network resource.

8. An information handling system comprising a processor and memory, wherein the processor and memory in combination are operable to implement a method comprising:

receiving a request to authenticate a user of a user device currently accessing an enterprise computing system;

determining an authentication context of the request, the authentication context identifying at least the user device and a current physical location of the user device;

dynamically selecting an authentication template, from among a plurality of stored authentication templates, based, at least part, on a discrete level of security deemed warranted by the authentication context;

wherein the plurality of stored authentication templates each specify one or more user-initiated event types in combination with one or more corresponding user-initiated event requests;

responsive to the request, selecting a set of previous user-initiated events of the user on the enterprise computing platform based, at least part, on the specified one or more user-initiated event types of the dynamically selected authentication template, the previous user-initiated events each relating to a discrete user action with respect to a resource on the enterprise computing system;

accessing user-specific event information related to the selected set of previous user-initiated events, wherein the user-specific event information corresponds to a field of at least one of the one or more corresponding user-initiated event requests of the selected authentication template;

generating, from at least a portion of the user-specific event information, a user-specific authentication sequence comprising a plurality of event-information requests that conform to the one or more corresponding user-initiated event requests of the authentication template; and

administering the user-specific authentication sequence to the user, the administering comprising requiring the user to provide a valid response to each of the plurality of event-information requests as a precondition to successful authentication.

9. The information handling system of claim 8 , wherein:

the authentication template specifies a form of the plurality of event-information requests; and

the generating comprises populating the authentication template with the at least a portion of the user-specific event information.

10. The information handling system of claim 8 , wherein the authentication context comprises information related to a content-based classification of a network resource requested by the user.

11. The information handling system of claim 8 , wherein the selecting comprises randomly selecting the set subject to one or more constraints.

12. The information handling system of claim 11 , wherein the one or more constraints comprise event-timing information.

13. The information handling system of claim 8 , wherein the user-specific authentication sequence is single-use.

14. A computer-program product comprising a non-transitory computer-usable medium having computer-readable program code embodied therein, the computer-readable program code adapted to be executed to implement a method comprising:

receiving a request to authenticate a user of a user device currently accessing an enterprise computing system;

determining an authentication context of the request, the authentication context identifying at least the user device and a current physical location of the user device;

dynamically selecting an authentication template, from among a plurality of stored authentication templates, based, at least part, on a discrete level of security deemed warranted by the authentication context;

wherein the plurality of stored authentication templates each specify one or more user-initiated event types in combination with one or more corresponding user-initiated event requests;

responsive to the request, selecting a set of previous user-initiated events of the user on the enterprise computing platform based, at least part, on the specified one or more user-initiated event types of the dynamically selected authentication template, the previous user-initiated events each relating to a discrete user action with respect to a resource on the enterprise computing system;

accessing user-specific event information related to the selected set of previous user-initiated events, wherein the user-specific event information corresponds to a field of at least one of the one or more corresponding user-initiated event requests of the selected authentication template;

generating, from at least a portion of the user-specific event information, a user-specific authentication sequence comprising a plurality of event-information requests that conform to the one or more corresponding user-initiated event requests of the authentication template; and

administering the user-specific authentication sequence to the user, the administering comprising requiring the user to provide a valid response to each of the plurality of event-information requests as a precondition to successful authentication.

Assignments (26)
RELEASE OF SECURITY INTEREST Recorded Nov 19, 2025
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073606/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 18, 2025
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073613/0326 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0649 →
SECURITY INTEREST Recorded Jun 8, 2025
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; ERWIN, INC.
To: ALTER DOMUS (US) LLC
Reel/Frame 071527/0001 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059105/0479 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: GOLDMAN SACHS BANK USA
Reel/Frame 058945/0778 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 058952/0279 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS Recorded Feb 2, 2022
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.
Reel/Frame 059096/0683 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0347 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jun 7, 2018
From: QUEST SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 046327/0486 →
RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT R/F 040581/0850 Recorded May 22, 2018
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 046211/0735 →
CHANGE OF NAME Recorded Dec 6, 2017
From: DELL SOFTWARE INC.
To: QUEST SOFTWARE INC.
Reel/Frame 044719/0565 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE PREVIOUSLY RECORDED AT REEL: 040587 FRAME: 0624. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Nov 28, 2017
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: QUEST SOFTWARE INC. (F/K/A DELL SOFTWARE INC.); AVENTAIL LLC
Reel/Frame 044811/0598 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Nov 10, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040587/0624 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Nov 9, 2016
From: DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040581/0850 →
RELEASE OF SECURITY INTEREST Recorded Oct 31, 2016
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0467 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040039/0642) Recorded Oct 31, 2016
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
Reel/Frame 040521/0016 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS, L.P.; DELL SOFTWARE INC.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040030/0187 →
RELEASE OF REEL 035860 FRAME 0878 (NOTE) Recorded Sep 14, 2016
From: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.; STATSOFT, INC.
Reel/Frame 040027/0158 →
RELEASE OF REEL 035860 FRAME 0797 (TL) Recorded Sep 14, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.; STATSOFT, INC.
Reel/Frame 040028/0551 →
SECURITY AGREEMENT Recorded Sep 14, 2016
From: AVENTAIL LLC; DELL PRODUCTS L.P.; DELL SOFTWARE INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040039/0642 →
RELEASE OF REEL 035858 FRAME 0612 (ABL) Recorded Sep 13, 2016
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: DELL SOFTWARE INC.; DELL PRODUCTS L.P.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.; STATSOFT, INC.
Reel/Frame 040017/0067 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (NOTES) Recorded Jun 9, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; COMPELLENT TECHNOLOGIES, INC; SECUREWORKS, INC.; STATSOFT, INC.
To: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 035860/0878 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (TERM LOAN) Recorded Jun 9, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.; STATSOFT, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 035860/0797 →
SUPPLEMENT TO PATENT SECURITY AGREEMENT (ABL) Recorded Jun 9, 2015
From: DELL PRODUCTS L.P.; DELL SOFTWARE INC.; COMPELLENT TECHNOLOGIES, INC.; SECUREWORKS, INC.; STATSOFT, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 035858/0612 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 27, 2015
From: BRISEBOIS, MICHEL ALBERT; JOHNSTONE, CURTIS T.
To: DELL SOFTWARE INC.
Reel/Frame 035049/0337 →
Cited By (6)
US 12,250,228 US 12,271,970 US 12,299,155 US 12,355,843 US 12,437,042 US 12,682,096