IP Library Granted Patent US 12,621,311
Granted Patent B2
US 12,621,311 · App. 18/184,548 · Granted May 5, 2026

Authentication attack detection and mitigation with embedded authentication and delegation

Inventors: Jason Crabtree (Vienna, VA); Richard Kelley (Woodbridge, VA)
Assignee: QOMPLX LLC
H04L63/1416H04L63/0876H04L63/1425H04L63/1466
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,621,311
App. No.
18/184,548
Granted
May 5, 2026
Kind
B2
Abstract

A system and methods for authentication attack detection with embedded authentication and delegation is provided, comprising an authentication object inspector configured to observe a new authentication object generated by an identity provider, and retrieve the new authentication object, wherein subsequent access requests accompanied by authentication objects are validated by comparing identifiers for each authentication object to previous identifiers.

Claims (36)

1 . A system for mitigating an authentication attack, comprising:

a memory storing instructions to be executed by one or more hardware processors; and

one or more hardware processors configured to execute the instructions stored in the memory, wherein the instructions, when executed by the one or more hardware processors, cause the system to:

maintain an authentication ledger comprising metadata associated with a plurality of authentication objects;

receive network traffic associated with a first authentication object;

update one or more portions of metadata in the authentication leger based on the received network traffic associated with the first authentication object;

receive a request for access to a network resource accompanied by the first authentication object;

upon a determination that the first authentication object is invalid, update the authentication ledger to reflect that the first authentication object is invalid, wherein the determination that the first authentication object is invalid is based on the received network traffic associated with the first authentication object; and

revoke access to other network resources based on the determination that the first authentication object is invalid, wherein the revocation of access to the other network resources is performed based on one or more rules executed by a distributed computational graph.

2 . The system of claim 1 , wherein the instructions instructions, when executed by the one or more hardware processors, cause the system to:

calculate an identifier comprising a cryptographic hash for the first authentication object by performing a plurality of calculations and transformations on the first authentication object; and

update one or more portions of metadata associated with first authentication object in the authentication ledger to include the identifier.

3 . The system of claim 1 , wherein the metadata associated with the first authentication object comprises a randomly-generated unique identifier for the first authentication object.

4 . The system of claim 1 , wherein the metadata associated with the first authentication object comprises a numerical counter for the first authentication object.

5 . The system of claim 1 , wherein the authentication ledger comprises a second authentication object derived from the first authentication object.

6 . The system of claim 1 , wherein the first authentication object is embedded within a web request.

7 . The system of claim 1 , wherein the first authentication object is known to be generated by an identity provider associated with an authentication domain based on tracking of legitimate authentication events associated with the identity provider.

8 . The system of claim 1 , wherein the authentication attack is a golden ticket attack.

9 . The system of claim 1 , wherein the authentication attack is a silver ticket attack.

10 . A method for mitigating an authentication attack, comprising the steps of:

maintaining an authentication ledger comprising metadata associated with a plurality of authentication objects;

receiving network traffic associated with a first authentication object;

updating one or more portions of metadata in the authentication leger based on the received network traffic associated with the first authentication object;

receiving a request for access to a network resource accompanied by the first authentication object;

upon a determination that the first authentication object is invalid, updating the authentication ledger to reflect that the first authentication object is invalid, wherein the determination that the first authentication object is invalid is based on the received network traffic associated with the first authentication object; and

revoking access to other network resources based on the determination that the first authentication object is invalid, wherein the revocation of access to the other network resources is performed based on one or more rules executed by a distributed computational graph.

11 . The method of claim 10 , further comprising the steps of:

calculating an identifier comprising a cryptographic hash for the first authentication object by performing a plurality of calculations and transformations on the first authentication object; and

updating one or more portions of metadata associated with first authentication object in the authentication ledger to include the identifier.

12 . The method of claim 10 , wherein the metadata associated with the first authentication object comprises a randomly-generated unique identifier for the first authentication object.

13 . The method of claim 10 , wherein the metadata associated with the first authentication object comprises a numerical counter for the first authentication object.

14 . The method of claim 10 , wherein the authentication ledger comprises a second authentication object derived from the first authentication object.

15 . The method of claim 10 , wherein the first authentication object is embedded within a web request.

16 . The method of claim 10 , wherein the first authentication object is known to be generated by an identity provider associated with an authentication domain based on tracking of legitimate authentication events associated with the identity provider.

17 . The method of claim 10 , wherein the authentication attack is a golden ticket attack.

18 . The method of claim 10 , wherein the authentication attack is a silver ticket attack.

Assignments (6)
CHANGE OF ADDRESS Recorded Oct 1, 2024
From: QOMPLX LLC
To: QOMPLX LLC
Reel/Frame 069083/0279 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYING PARTY DATA PREVIOUSLY RECORDED ON REEL 064412 FRAME 0425. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 17, 2024
From: CRABTREE, JASON; KELLEY, RICHARD
To: QOMPLX, INC.
Reel/Frame 066342/0763 →
CHANGE OF NAME Recorded Sep 27, 2023
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 065036/0449 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY PREVIOUSLY RECORDED AT REEL: 064674 FRAME: 0408. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 20, 2023
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 064966/0863 →
PATENT ASSIGNMENT AGREEMENT TO ASSET PURCHASE AGREEMENT Recorded Aug 23, 2023
From: QOMPLX, INC.
To: QPX, LLC.
Reel/Frame 064674/0407 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 28, 2023
From: CRABTREE, JASON; KELLY, RICHARD
To: QOMPLX, INC.
Reel/Frame 064412/0425 →
Continuity (21)
Continuation In Part 18152142 · Jan 9, 2023
Continuation 17163073 · Jan 29, 2021
Continuation In Part 15837845 · Dec 11, 2017
Continuation In Part 15825350 · Nov 29, 2017
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 15655113 · Jul 20, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 14925974 · Oct 28, 2015
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15206195 · Jul 8, 2016
Continuation In Part 15186453 · Jun 18, 2016
Continuation In Part 15166158 · May 26, 2016
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 15091563 · Apr 5, 2016
Continuation In Part 14986536 · Dec 31, 2015
Continuation In Part 14925974 · Oct 28, 2015
Continuation In Part 17170288 · Feb 8, 2021
Continuation In Part 17169924 · Feb 8, 2021
Continuation In Part 15837845 · Dec 11, 2017
Provisional Application 62596105 · Dec 7, 2017
Related Publication 20230308459A1 · Sep 28, 2023
References Cited (54)
US 6256544B1 · Weissinger · 2001 [cited by applicant]
US 7281125B2 · Challener et al. · 2007 [cited by applicant]
US 7702821B2 · Feinberg et al. · 2010 [cited by applicant]
US 8015412B2 · Lapstun · 2011 [cited by examiner]
US 8204945B2 · Milliken · 2012 [cited by examiner]
US 8228861B1 · Nix · 2012 [cited by examiner]
US 8601554B2 · Gordon et al. · 2013 [cited by applicant]
US 9253643B2 · Pattar et al. · 2016 [cited by applicant]
US 9292692B2 · Wallrabenstein · 2016 [cited by applicant]
US 9602530B2 · Ellis et al. · 2017 [cited by applicant]
US 9652604B1 · Johansson et al. · 2017 [cited by applicant]
US 10038559B2 · Burrows et al. · 2018 [cited by applicant]
US 10061635B2 · Ellwein · 2018 [cited by applicant]
US 10193695B1 · Endress · 2019 [cited by examiner]
US 10248910B2 · Crabtree et al. · 2019 [cited by applicant]
US 10367829B2 · Huang et al. · 2019 [cited by applicant]
US 10410214B2 · Doyle · 2019 [cited by applicant]
US 10628578B2 · Eksten et al. · 2020 [cited by applicant]
US 10645086B1 · Hadler · 2020 [cited by applicant]
US 11005824B2 · Crabtree et al. · 2021 [cited by applicant]
US 11057366B2 · Avetisov et al. · 2021 [cited by applicant]
US 11570209B2 · Crabtree · 2023 [cited by examiner]
US 11799900B2 · Crabtree · 2023 [cited by examiner]
US 11818169B2 · Crabtree · 2023 [cited by examiner]
US 12003534B2 · Crabtree · 2024 [cited by examiner]
US 20030005290A1 · Fishman · 2003 [cited by examiner]
US 20030041254A1 · Challener et al. · 2003 [cited by applicant]
US 20030145225A1 · Bruton, III et al. · 2003 [cited by applicant]
US 20050210255A1 · Kirovski · 2005 [cited by applicant]
US 20070036314A1 · Kloberdans et al. · 2007 [cited by applicant]
US 20070136821A1 · Hershaft et al. · 2007 [cited by applicant]
US 20070150744A1 · Cheng et al. · 2007 [cited by applicant]
US 20080021866A1 · Hinton et al. · 2008 [cited by applicant]
US 20090182672A1 · Doyle · 2009 [cited by applicant]
US 20100092048A1 · Pan · 2010 [cited by examiner]
US 20110087888A1 · Rennie · 2011 [cited by applicant]
US 20120096271A1 · Ramarathinam · 2012 [cited by examiner]
US 20120110334A1 · Rossi · 2012 [cited by examiner]
US 20130117831A1 · Hook · 2013 [cited by applicant]
US 20150128258A1 · Novozhenets · 2015 [cited by applicant]
US 20150186962A1 · Krell · 2015 [cited by examiner]
US 20150281225A1 · Schoen · 2015 [cited by examiner]
US 20150317481A1 · Gardner et al. · 2015 [cited by applicant]
US 20160072845A1 · Chiviendacz et al. · 2016 [cited by applicant]
US 20160275123A1 · Lin et al. · 2016 [cited by applicant]
US 20160330233A1 · Hart · 2016 [cited by examiner]
US 20180248701A1 · Johnson et al. · 2018 [cited by applicant]
US 20210099868A1 · Damlaj et al. · 2021 [cited by applicant]
US 20210105285A1 · Simakov et al. · 2021 [cited by applicant]
US 20210185531A1 · Avetisov et al. · 2021 [cited by applicant]
US 20210297443A1 · Crabtree et al. · 2021 [cited by applicant]
US 20240314162A1 · Crabtree · 2024 [cited by examiner]
WO 2014159150A1 · 2014 [cited by applicant]
WO 2017075543A1 · 2017 [cited by applicant]