US2023385098A1PendingUtilityA1
Enforce changes in session behavior based on updated machine learning model with detected risk behavior during session
Assignee: MICROSOFT TECHNOLOGY LICENSING LLCPriority: Oct 5, 2019Filed: Aug 8, 2023Published: Nov 30, 2023
Est. expiryOct 5, 2039(~13.2 yrs left)· nominal 20-yr term from priority
G06F 9/468G06N 20/00G06F 9/5011G06F 21/32G06F 21/564G06F 2209/5013G06F 2221/2141H04L 67/306H04L 67/14G06F 21/33H04L 63/101H04L 63/068H04L 63/0846H04L 67/535
67
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
Systems and methods are provided for managing dynamic controls over access to computer resources and, even more particularly, for evaluating and re-evaluating dynamic conditions and changes associated with user sessions. The systems and methods are configured to automatically make a determination as to whether new or additional authentication credentials are required for a user that is already authorized for accessing resources in a user session, in response to triggering events such as the identification of a new or changed condition associated with the user session.
Claims
exact text as granted — not AI-modified1 . (canceled)
2 . A system that controls access to resources, said system comprising:
a conditional access engine; a tenant session manager; one or more processors; and one or more hardware storage devices that store instructions that are executable by the one or more processors to cause the system to:
access a policy associated with a resource of a tenant, said access being performed using the conditional access engine, wherein the policy enforces access permissions for the resource based on a triggering event, wherein the triggering event relates to a modified condition that is identified during a user session for an identity, and wherein the identity has current access to the resource via the user session;
monitor events occurring during the user session, said monitoring being performed using one of the conditional access engine or the tenant session manager;
in response to the triggering event being detected from among the monitored events, re-evaluate the user session based on the policy, said re-evaluating being performed using the conditional access engine;
determine, based on said re-evaluation, that a new credential is required to continue to provide the identity the current access to the resource, said determining being performed using the conditional access engine;
suspend the current access to the resource while maintaining session state for the user session, said suspending being performed using the tenant session manager; and
after the new credential is obtained, unsuspend the user session, said unsuspending being performed using the tenant session manager.
3 . The system of claim 2 , wherein the identity is selected from a group consisting of a user identity or an application identity.
4 . The system of claim 2 , wherein the identity is a user identity.
5 . The system of claim 2 , wherein the identity is an application identity.
6 . The system of claim 2 , wherein the triggering event is further based on information from a comparison between a first behavior of the identity detected during the user session and a second behavior of the identity detected during a previous user session.
7 . The system of claim 6 , wherein information describing at least one of the first behavior or the second behavior is obtained from an additional information source.
8 . The system of claim 2 , wherein the policy omits at least one of a predefined static conditional access policy or a session timeout policy.
9 . The system of claim 2 , wherein, prior to monitoring the events occurring during the user session, the user session is established.
10 . The system of claim 9 , wherein, prior to the user session being established, the user session is authorized to be established.
11 . The system of claim 2 , wherein the user session was previously authorized.
12 . A method for controlling access to resources, said method being implemented by a system comprising a conditional access engine and a tenant session manager, said method comprising:
accessing a policy associated with a resource, said accessing being performed using the conditional access engine, wherein the policy enforces access permissions for the resource based on a triggering event, wherein the triggering event relates to a modified condition that is identified during a user session for an identity, and wherein the identity has current access to the resource via the user session; monitoring events occurring during the user session, said monitoring being performed using one of the conditional access engine or the tenant session manager; in response to the triggering event being detected from among the monitored events, re-evaluating the user session based on the policy, said re-evaluating being performed using the conditional access engine; determining, based on said re-evaluation, that a new credential is required to continue to provide the identity the current access to the resource, said determining being performed using the conditional access engine; suspending the current access to the resource by causing the user session to transition from an un-paused state to a paused state, said suspending being performed using the tenant session manager; and after the new credential is obtained, unsuspending the current access to the resource by causing the user session to transition from the paused state to the un-paused state, said unsuspending being performed using the tenant session manager.
13 . The method of claim 12 , wherein the method further includes:
prior to monitoring the events, receiving an original credential that is usable to access the resource; and in response to the credential being verified based on the policy, authorizing the user session.
14 . The method of claim 12 , wherein the method further includes:
prior to monitoring the events, receiving an original credential that is usable to access the resource; and in response to the credential being verified based on the policy, establishing the user session.
15 . The method of claim 12 , wherein the policy is different than a predefined static conditional access policy.
16 . The method of claim 12 , wherein the policy is different than a session timeout policy.
17 . The method of claim 12 , wherein the user session was previously authorized and established.
18 . The method of claim 12 , wherein dynamically determining that the new credential is required is not a predetermined static decision.
19 . The method of claim 12 , wherein the new credential is a same credential that was used to originally authorize the user session.
20 . The method of claim 12 , wherein the new credential is a different credential than an original credential that was used to originally authorize the user session.
21 . A system that controls access to resources, said system comprising:
a conditional access engine; a tenant session manager; one or more processors; and one or more hardware storage devices that store instructions that are executable by the one or more processors to cause the system to:
access a policy associated with a resource, said accessing being performed using the conditional access engine, wherein the policy enforces access permissions for the resource based on a triggering event, wherein the triggering event relates to a modified condition that is identified during a user session for an identity, and wherein the identity has current access to the resource via the user session;
monitor events occurring during the user session, said monitoring being performed using one of the conditional access engine or the tenant session manager;
in response to the triggering event being detected from among the monitored events, re-evaluate the user session based on the policy, said re-evaluating being performed using the conditional access engine;
determine, based on said re-evaluation, that a new credential is required to continue to provide the identity the current access to the resource, said determining being performed using the conditional access engine;
suspend the current access to the resource by causing the user session to transition from an un-paused state to a paused state, said suspending being performed using the tenant session manager; and
after the new credential is obtained, unsuspend the current access to the resource by causing the user session to transition from the paused state to the un-paused state, said unsuspending being performed using the tenant session manager.Join the waitlist — get patent alerts
Track US2023385098A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.