发明名称 On-demand service security system and method for managing a risk of access as a condition of permitting access to the on-demand service
摘要 Provided are mechanisms and methods for managing a risk of access to an on-demand service as a condition of permitting access to the on-demand service. These mechanisms and methods for providing such management can help prohibit an unauthorized user from accessing an account of an authorized user when the authorized user inadvertently loses login information. The ability to provide such management may lead to an improved security feature for accessing on-demand services.
申请公布号 US8898753(B1) 申请公布日期 2014.11.25
申请号 US201213424285 申请日期 2012.03.19
申请人 salesforce.com, inc. 发明人 Junod Forrest A.;Fly Robert C.;Dapkus Peter;Yancey Scott W.;Lawrance Steven S.;Fell Simon Z.
分类号 G06F7/04;G06F9/00 主分类号 G06F7/04
代理机构 Zilka-Kotab, PC 代理人 Zilka-Kotab, PC
主权项 1. A method, comprising: receiving a request to access an on-demand service from a requestor at the on-demand service, the request including credentials for logging into the on-demand service; determining, utilizing a hardware processor, that the requestor from which the request to access the on-demand service is received is a potentially risky source, the determination being based at least on: information about the requestor, andinformation about one of a plurality of entities of the on-demand service to which the access is requested, wherein the information about the one of the plurality of entities is stored by the on-demand service; in response to the request to access the on-demand service and the determination that the requestor is the potentially risky source, managing access to the on-demand service by: identifying information previously stored in association with the credentials that were received in the request to access the on-demand service, the information previously stored in association with the credentials indicating a message destination,sending, by the on-demand service, a token to the message destination,after sending the token to the message destination, challenging the requestor to provide the token to the on-demand service,determining whether the token is provided by the requestor to the on-demand service in response to the challenge,identifying the requestor as authenticated in response to a determination that the token is provided by the requestor to the on-demand service, and permitting the requested access to the on-demand service by the authenticated requestor, andidentifying the requestor as non-authenticated in response to a determination that the token is not provided by the requestor to the on-demand service, and prohibiting the requested access to the on-demand service by the non-authenticated requestor.
地址 San Francisco CA US