US2023385098A1PendingUtilityA1

Enforce changes in session behavior based on updated machine learning model with detected risk behavior during session

Assignee: MICROSOFT TECHNOLOGY LICENSING LLCPriority: Oct 5, 2019Filed: Aug 8, 2023Published: Nov 30, 2023
Est. expiryOct 5, 2039(~13.2 yrs left)· nominal 20-yr term from priority
G06F 9/468G06N 20/00G06F 9/5011G06F 21/32G06F 21/564G06F 2209/5013G06F 2221/2141H04L 67/306H04L 67/14G06F 21/33H04L 63/101H04L 63/068H04L 63/0846H04L 67/535
67
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Systems and methods are provided for managing dynamic controls over access to computer resources and, even more particularly, for evaluating and re-evaluating dynamic conditions and changes associated with user sessions. The systems and methods are configured to automatically make a determination as to whether new or additional authentication credentials are required for a user that is already authorized for accessing resources in a user session, in response to triggering events such as the identification of a new or changed condition associated with the user session.

Claims

exact text as granted — not AI-modified
1 . (canceled) 
     
     
         2 . A system that controls access to resources, said system comprising:
 a conditional access engine;   a tenant session manager;   one or more processors; and   one or more hardware storage devices that store instructions that are executable by the one or more processors to cause the system to:
 access a policy associated with a resource of a tenant, said access being performed using the conditional access engine, wherein the policy enforces access permissions for the resource based on a triggering event, wherein the triggering event relates to a modified condition that is identified during a user session for an identity, and wherein the identity has current access to the resource via the user session; 
 monitor events occurring during the user session, said monitoring being performed using one of the conditional access engine or the tenant session manager; 
 in response to the triggering event being detected from among the monitored events, re-evaluate the user session based on the policy, said re-evaluating being performed using the conditional access engine; 
 determine, based on said re-evaluation, that a new credential is required to continue to provide the identity the current access to the resource, said determining being performed using the conditional access engine; 
 suspend the current access to the resource while maintaining session state for the user session, said suspending being performed using the tenant session manager; and 
 after the new credential is obtained, unsuspend the user session, said unsuspending being performed using the tenant session manager. 
   
     
     
         3 . The system of  claim 2 , wherein the identity is selected from a group consisting of a user identity or an application identity. 
     
     
         4 . The system of  claim 2 , wherein the identity is a user identity. 
     
     
         5 . The system of  claim 2 , wherein the identity is an application identity. 
     
     
         6 . The system of  claim 2 , wherein the triggering event is further based on information from a comparison between a first behavior of the identity detected during the user session and a second behavior of the identity detected during a previous user session. 
     
     
         7 . The system of  claim 6 , wherein information describing at least one of the first behavior or the second behavior is obtained from an additional information source. 
     
     
         8 . The system of  claim 2 , wherein the policy omits at least one of a predefined static conditional access policy or a session timeout policy. 
     
     
         9 . The system of  claim 2 , wherein, prior to monitoring the events occurring during the user session, the user session is established. 
     
     
         10 . The system of  claim 9 , wherein, prior to the user session being established, the user session is authorized to be established. 
     
     
         11 . The system of  claim 2 , wherein the user session was previously authorized. 
     
     
         12 . A method for controlling access to resources, said method being implemented by a system comprising a conditional access engine and a tenant session manager, said method comprising:
 accessing a policy associated with a resource, said accessing being performed using the conditional access engine, wherein the policy enforces access permissions for the resource based on a triggering event, wherein the triggering event relates to a modified condition that is identified during a user session for an identity, and wherein the identity has current access to the resource via the user session;   monitoring events occurring during the user session, said monitoring being performed using one of the conditional access engine or the tenant session manager;   in response to the triggering event being detected from among the monitored events, re-evaluating the user session based on the policy, said re-evaluating being performed using the conditional access engine;   determining, based on said re-evaluation, that a new credential is required to continue to provide the identity the current access to the resource, said determining being performed using the conditional access engine;   suspending the current access to the resource by causing the user session to transition from an un-paused state to a paused state, said suspending being performed using the tenant session manager; and   after the new credential is obtained, unsuspending the current access to the resource by causing the user session to transition from the paused state to the un-paused state, said unsuspending being performed using the tenant session manager.   
     
     
         13 . The method of  claim 12 , wherein the method further includes:
 prior to monitoring the events, receiving an original credential that is usable to access the resource; and   in response to the credential being verified based on the policy, authorizing the user session.   
     
     
         14 . The method of  claim 12 , wherein the method further includes:
 prior to monitoring the events, receiving an original credential that is usable to access the resource; and   in response to the credential being verified based on the policy, establishing the user session.   
     
     
         15 . The method of  claim 12 , wherein the policy is different than a predefined static conditional access policy. 
     
     
         16 . The method of  claim 12 , wherein the policy is different than a session timeout policy. 
     
     
         17 . The method of  claim 12 , wherein the user session was previously authorized and established. 
     
     
         18 . The method of  claim 12 , wherein dynamically determining that the new credential is required is not a predetermined static decision. 
     
     
         19 . The method of  claim 12 , wherein the new credential is a same credential that was used to originally authorize the user session. 
     
     
         20 . The method of  claim 12 , wherein the new credential is a different credential than an original credential that was used to originally authorize the user session. 
     
     
         21 . A system that controls access to resources, said system comprising:
 a conditional access engine;   a tenant session manager;   one or more processors; and   one or more hardware storage devices that store instructions that are executable by the one or more processors to cause the system to:
 access a policy associated with a resource, said accessing being performed using the conditional access engine, wherein the policy enforces access permissions for the resource based on a triggering event, wherein the triggering event relates to a modified condition that is identified during a user session for an identity, and wherein the identity has current access to the resource via the user session; 
 monitor events occurring during the user session, said monitoring being performed using one of the conditional access engine or the tenant session manager; 
 in response to the triggering event being detected from among the monitored events, re-evaluate the user session based on the policy, said re-evaluating being performed using the conditional access engine; 
 determine, based on said re-evaluation, that a new credential is required to continue to provide the identity the current access to the resource, said determining being performed using the conditional access engine; 
 suspend the current access to the resource by causing the user session to transition from an un-paused state to a paused state, said suspending being performed using the tenant session manager; and 
 after the new credential is obtained, unsuspend the current access to the resource by causing the user session to transition from the paused state to the un-paused state, said unsuspending being performed using the tenant session manager.

Join the waitlist — get patent alerts

Track US2023385098A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.