Invalidity dossier

US 12231426

Contextual and risk-based multi-factor authentication

Current assignee: Qomplx Inc

Added 5/12/2026, 11:39:38 PM

At a glanceActive PTAB challenge1 lawsuit on fileasserted by Qomplx LLCSoftware Technology & Computing Systems (T)

Active provider: Google · gemini-2.5-flash

Auto-generating section 1 of 2: Extensions

Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.

Patent summary

Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.

✓ Generated

I could not find US patent 12231426 in the USPTO database with the provided search results. The USPTO search guidelines indicate that utility patent numbers consist of six, seven, or eight digits, and require entering leading zeros for numbers with fewer than seven digits (e.g., 0123456 for 123456). The number "12231426" is eight digits long and does not immediately conform to the typical format presented in the search result examples for direct patent number lookup without further context (e.g., a "kind code" for a publication number). Given this, I am unable to definitively provide details such as the title, assignee, inventors, filing date, or issue date from the USPTO.

Similarly, my search of CAFC 2026 dockets did not yield any cases specifically mentioning patent number 12231426.

Therefore, I cannot provide a concise summary of US patent 12231426, including its abstract and a plain-language overview of each independent claim, as authoritative information for this specific patent number could not be found with the given constraints and current search capabilities.

Uncertainty: The inability to locate the patent with the provided number suggests that either the number is not a standard utility patent number, or it is formatted in a way that is not immediately discoverable through the general USPTO search guidance provided.

Generated 5/28/2026, 12:46:08 AM

Cases on file (1)

Group view →

Specific litigation cases in our database that name US patent 12231426. The free-form analysis below may also discuss cases beyond this list.

  • IPR2026-00184Patent Trial and Appeal Board (PTAB)Pending

Litigation summary

Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.

✓ Generated

As a patent attorney, I have investigated known litigation involving US patent 12231426.

Based on the available information as of April 26, 2026, there is one known Patent Trial and Appeal Board (PTAB) case related to US patent 12231426:

  • Case Number: IPR2026-00184
  • Plaintiff(s): Not specified in the snippet, but typically the Petitioner in an IPR.
  • Defendant(s): Not specified in the snippet, but typically the Patent Owner in an IPR.
  • Jurisdiction: Patent Trial and Appeal Board (PTAB)
  • Filing Date: Not explicitly stated in the provided text, but the case itself is IPR2026-00184, implying it was filed in 2026.
  • Outcome or Current Status: Pending

Generated 5/28/2026, 12:46:14 AM

Proceedings on file (1)

All PTAB activity →

AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.

Current assignee: Qomplx LLC

1 active

PTAB challenges

AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.

✓ Generated

Proceedings overview

There is one active AIA trial proceeding on file for US patent 12231426. As this proceeding is currently pending its institution decision, no claims have been invalidated or sustained by the PTAB. This means the patent's claims remain untested in an AIA trial.

IPR2026-00184 — Microsoft Corporation v. Qomplx LLC

  • Type: Inter Partes Review
  • Filed: 2025-12-30
  • Status: Pending (The proceeding is active and has not yet reached an institution decision or merits determination).
    Note on Petitioner Identity: The "PTAB proceedings on file" provided in the prompt identifies Microsoft Corporation as the petitioner for IPR2026-00184. However, the Google Patents page for US12231426 states that the petitioner for IPR2026-00184 is "Unified Patents PTAB Data". For the purpose of this analysis, the "PTAB proceedings on file" list is treated as the canonical ground truth as explicitly instructed.
  • Judge panel: Not publicly available from search results for this specific proceeding. Institution decisions for IPRs filed after October 20, 2025, are made by the USPTO Director.
  • Petition grounds: Specific claims challenged, prior art cited, and statutory bases (§ 102 / § 103 / § 112) for IPR2026-00184 on US12231426 are not available in the provided search results.
  • Institution decision: Not yet issued. The statutory deadline for an institution decision is typically six months from the petition filing date, which would be around June 30, 2026.
  • Final Written Decision (if issued): Not issued.
  • Settlement / termination: No information available.
  • Appeal: Not applicable, as no Final Written Decision has been issued.
  • Defensive value: This IPR is in its initial "pending" phase. Until an institution decision is rendered, it does not impact the patent's claims. Should the IPR be instituted, it will signal which claims are being challenged and on what prior art grounds, potentially providing an avenue for invalidity arguments.

Strategic summary

Currently, only one Inter Partes Review, IPR2026-00184, has been filed against US patent 12231426. As this proceeding is still in the "pending" stage, no claims of US12231426 have been canceled or sustained by the Patent Trial and Appeal Board (PTAB). Consequently, all claims of the patent remain untested by an AIA trial to date.

The estoppel landscape under 35 U.S.C. § 315(e)(2) has not yet been established for this patent, as no institution decision has been rendered for IPR2026-00184. Therefore, any prior-art grounds that Microsoft Corporation (as the petitioner in the canonical list) raised or reasonably could have raised are not yet barred for future actions by them or their privies. There is no discernible pattern of multiple IPR filings on this specific patent. The patent owner, Qomplx LLC (or Qomplx Inc.), has been involved in litigation with Microsoft, indicating a potential broader dispute.

Recommended next steps

Since IPR2026-00184 is currently pending, a defendant facing assertion of US patent 12231426 should closely monitor the PTAB's progress. The institution decision for this IPR is anticipated around June 30, 2026, which is six months from the petition's filing date. If the IPR is instituted, the specific grounds of invalidity will become public, and a trial schedule will be set, offering insights into potential challenges to the patent's validity. If institution is denied, the patent's claims will remain unchallenged by this specific proceeding, though other avenues for challenging validity may still exist. It is important to note the recent changes in PTAB discretionary institution policy, including the Director's authority over institution decisions and the consideration of U.S. manufacturing activity, which could influence the outcome of the institution decision for IPR2026-00184.

Generated 5/28/2026, 12:46:32 AM

Assignment history

Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.

✓ Generated

Inventors

  • Jason Crabtree
  • Andrew Sellers
  • Ian MacLeod

All inventors were associated with Qomplx Inc. at the time of filing.

Original assignee

The original assignee named on the issued patent US12231426B2 is Qomplx Inc. Qomplx Inc. is a private company headquartered in Reston, VA, and focuses on cybersecurity, analytics, simulation, and AI. They offer a cloud-native risk analytics platform designed to help organizations make intelligent business decisions and better manage risk in areas including cybersecurity, insurance, and finance. Qomplx Inc. currently appears to be operating.

Assignment timeline

The USPTO Patent Assignment Search portal does not return any recorded assignments for patent US12231426. This indicates that the ownership of the patent remains with the original assignee or has not been publicly recorded via assignment.

Timeline diagram

timeline
    title Ownership of US 12231426
    2024 : Application filed by Qomplx Inc
    2025 : Patent granted to Qomplx Inc

NPE / troll-pattern signals

  1. Shell-entity transfer — not present. The patent has not been transferred from an operating company to a shell entity.
  2. Known asserter in the chain — not present. Qomplx Inc. is not identified as a known NPE.
  3. Repeat correspondent across the chain — not present. No assignment records are found to indicate a correspondent.
  4. Cascading transfers — not present. No assignment records are found.
  5. Pre-litigation transfer — not present. No assignment records are found.
  6. Bankruptcy fire-sale — not present. No information suggests Qomplx Inc. has filed for bankruptcy.
  7. Privateering — not present. No information suggests privateering activities.
  8. Defensive aggregator (anti-NPE) — not present. The patent is still held by the original operating company.

Verdict

Insufficient data. There are no recorded assignments for US patent 12231426 in the USPTO Patent Assignment Search database. Without any assignment records, it is impossible to determine if any NPE or patent-troll patterns are present. The patent currently remains with the original assignee, Qomplx Inc., an operating company.

USPTO Assignment Center search for US12231426: https://assignmentcenter.uspto.gov/

Generated 5/28/2026, 12:46:22 AM

Prior art

Earlier patents, publications, and products that may anticipate or render the claims unpatentable.

✓ Generated

Patent Summary

I could not find US patent 12231426 in the USPTO database with the provided search results. The USPTO search guidelines indicate that utility patent numbers consist of six, seven, or eight digits, and require entering leading zeros for numbers with fewer than seven digits (e.g., 0123456 for 123456). The number "12231426" is eight digits long and does not immediately conform to the typical format presented in the search result examples for direct patent number lookup without further context (e.g., a "kind code" for a publication number). Given this, I am unable to definitively provide details such as the title, assignee, inventors, filing date, or issue date from the USPTO.

Similarly, my search of CAFC 2026 dockets did not yield any cases specifically mentioning patent number 12231426.

Therefore, I cannot provide a concise summary of US patent 12231426, including its abstract and a plain-language overview of each independent claim, as authoritative information for this specific patent number could not be found with the given constraints and current search capabilities.

Uncertainty: The inability to locate the patent with the provided number suggests that either the number is not a standard utility patent number, or it is formatted in a way that is not immediately discoverable through the general USPTO search guidance provided.


Current Task Response

My previous attempts to locate US patent 12231426 in the USPTO database using general search parameters were unsuccessful. However, a more direct search for "US12231426B2" on Google Patents yields a result titled "Contextual and risk-based multi-factor authentication". This indicates that the provided number "12231426" likely corresponds to a granted patent, with "B2" being the kind code.

Therefore, contradicting my previous statement, US patent 12231426 can be found and refers to US12231426B2.

Patent Summary for US12231426B2:

  • Title: Contextual and risk-based multi-factor authentication
  • Abstract: A system for contextual and risk-based multi-factor authentication is described, featuring a multi-dimensional time series data server that monitors and records network traffic data and serves it to other modules. A directed computation graph module receives this traffic data, determines a network traffic baseline, and calculates a required verification score for user access based on this baseline. Users must then utilize a plurality of verification methods to achieve the required verification score to gain access.
  • Assignee: Qomplx Inc. (current assignee as of the publication date)
  • Inventors: Jason Crabtree, Andrew Sellers, Ian MacLeod
  • Filing Date: September 13, 2024
  • Publication Date: February 18, 2025
  • Application Granted: February 18, 2025
  • Anticipated Expiration: October 28, 2035

Plain-language overview of independent claims (based on the provided text, as specific claims were not initially requested and are not directly accessible via the general search snippets):

The patent claims generally revolve around a system and method for dynamic multi-factor authentication.

  • System Claim Overview: The system involves a multi-dimensional time series data server that monitors and records network traffic, and a directed computation graph module that processes this data to establish a network traffic baseline. Based on this baseline, the directed computation graph module determines a "required verification score" for a user to access a network resource. The user then needs to employ multiple verification methods to achieve this score.
  • Method Claim Overview: The method comprises steps of monitoring and recording network traffic data using a multi-dimensional time series data server, serving this data to other modules, and then, with a directed computation graph module, receiving the data, determining a network traffic baseline, and calculating a required verification score based on the baseline. Finally, the user is required to use various verification methods to accumulate enough points to meet the required score and gain access to the network resource.

The patent further details that the verification score can be influenced by factors such as the security level of the requested resources, the origin of the user's connection, and whether the connection request is considered anomalous. Verification methods can include biometric features, visual media, information from untrusted parties, and device-specific information.


Most Relevant Prior Art for US patent 12231426 (US12231426B2):

The provided text for US12231426B2 lists several applications from which it claims priority. These applications, as they were filed earlier and contain related subject matter, are considered highly relevant prior art under 35 U.S.C. § 102. Under 35 U.S.C. § 102, an invention is not patentable if it was described in a patent, published application, or other printed publication before the effective filing date of the claimed invention, or if it was publicly used or on sale more than one year before the effective filing date. U.S. patent application publications are considered prior art from their publication date or, in some cases, from their earliest effective U.S. filing date.

Here are the direct prior art references explicitly mentioned in the "CROSS-REFERENCE TO RELATED APPLICATIONS" section, along with their details:

  1. U.S. patent application Ser. No. 18/464,623

    • Full Citation: U.S. patent application Ser. No. 18/464,623, titled "RISK-BASED MULTI-FACTOR AUTHENTICATION"
    • Publication/Filing Date: Filed on September 11, 2023
    • Brief Description: This application covers "RISK-BASED MULTI-FACTOR AUTHENTICATION," which is a direct predecessor to the current patent.
    • Potential Anticipation: It potentially anticipates all claims related to contextual and risk-based multi-factor authentication, particularly those focusing on the risk-based determination of verification needs, as the current patent is a continuation of this application.
  2. U.S. patent application Ser. No. 17/539,137 (now U.S. Pat. No. 11,757,872)

    • Full Citation: U.S. patent application Ser. No. 17/539,137, titled "CONTEXTUAL AND RISK-BASED MULTI-FACTOR AUTHENTICATION", now issued as U.S. Pat. No. 11,757,872
    • Publication/Filing Date: Filed on November 30, 2021; Issued as U.S. Pat. No. 11,757,872 on September 12, 2023
    • Brief Description: This application shares the exact same title as the current patent, "CONTEXTUAL AND RISK-BASED MULTI-FACTOR AUTHENTICATION," indicating substantial overlap in subject matter.
    • Potential Anticipation: It potentially anticipates all claims of US12231426B2, especially those defining the core system and method for contextual and risk-based multi-factor authentication, given it is a direct continuation.
  3. U.S. patent application Ser. No. 16/856,827 (now U.S. Pat. No. 11,218,474)

    • Full Citation: U.S. patent application Ser. No. 16/856,827, titled "CONTEXTUAL AND RISK-BASED MULTI-FACTOR AUTHENTICATION", now issued as U.S. Pat. No. 11,218,474
    • Publication/Filing Date: Filed on April 23, 2020; Issued as U.S. Pat. No. 11,218,474 on January 4, 2022
    • Brief Description: Another application with the title "CONTEXTUAL AND RISK-BASED MULTI-FACTOR AUTHENTICATION," further reinforcing its direct relevance.
    • Potential Anticipation: It potentially anticipates all claims of US12231426B2, particularly the foundational elements of contextual and risk-based multi-factor authentication.
  4. U.S. patent application Ser. No. 15/790,860 (now U.S. Pat. No. 10,742,647)

    • Full Citation: U.S. patent application Ser. No. 15/790,860, titled "CONTEXTUAL AND RISK-BASED MULTI-FACTOR AUTHENTICATION", now issued as U.S. Pat. No. 10,742,647
    • Publication/Filing Date: Filed on October 23, 2017; Issued as U.S. Pat. No. 10,742,647 on August 11, 2020
    • Brief Description: This is an earlier application directly related to the "CONTEXTUAL AND RISK-BASED MULTI-FACTOR AUTHENTICATION" subject matter.
    • Potential Anticipation: It potentially anticipates all claims of US12231426B2, as it is a foundational application in the priority chain for the core invention.
  5. U.S. provisional patent application 62/574,708

    • Full Citation: U.S. provisional patent application 62/574,708, titled "CONTEXTUAL AND RISK-BASED MULTI-FACTOR AUTHENTICATION"
    • Publication/Filing Date: Filed on October 19, 2017
    • Brief Description: This provisional application is the earliest priority document for the "CONTEXTUAL AND RISK-BASED MULTI-FACTOR AUTHENTICATION" aspect.
    • Potential Anticipation: It potentially anticipates all claims of US12231426B2, assuming its disclosure provides sufficient support for those claims under 35 U.S.C. § 112, first paragraph. Provisional applications themselves are not prior art under §102, but a later-filed non-provisional application claiming priority to it may be given the benefit of the provisional filing date if the disclosure provides support for the claims in the reference patent.
  6. U.S. patent application Ser. No. 15/616,427

    • Full Citation: U.S. patent application Ser. No. 15/616,427, titled "RAPID PREDICTIVE ANALYSIS OF VERY LARGE DATA SETS USING AN ACTOR-DRIVEN DISTRIBUTED COMPUTATIONAL GRAPH"
    • Publication/Filing Date: Filed on June 7, 2017
    • Brief Description: This application describes a "business operating system" with a "directed computation graph" that can perform predictive analysis on large datasets, which is a core component of how the present invention determines risk and network baselines.
    • Potential Anticipation: Claims related to the monitoring and recording of network traffic data, the use of a multi-dimensional time series data server, and the directed computation graph module for determining a network traffic baseline (as described in claims 1 and 7) could be anticipated or rendered obvious by this prior art.
  7. U.S. patent application Ser. No. 14/925,974

    • Full Citation: U.S. patent application Ser. No. 14/925,974, titled "RAPID PREDICTIVE ANALYSIS OF VERY LARGE DATA SETS USING THE DISTRIBUTED COMPUTATIONAL GRAPH"
    • Publication/Filing Date: Filed on October 28, 2015
    • Brief Description: This is an earlier version of the "rapid predictive analysis" system using a distributed computational graph, providing the underlying technological framework for the business operating system mentioned in the current patent.
    • Potential Anticipation: Similar to U.S. patent application Ser. No. 15/616,427, this reference could anticipate or render obvious claims pertaining to the data handling, analysis, and baseline determination using the described computational graph and time series data server.
  8. U.S. patent application Ser. No. 15/237,625 (now U.S. Pat. No. 10,248,910)

    • Full Citation: U.S. patent application Ser. No. 15/237,625, titled "DETECTION MITIGATION AND REMEDIATION OF CYBERATTACKS EMPLOYING AN ADVANCED CYBER-DECISION PLATFORM", now issued as U.S. Pat. No. 10,248,910
    • Publication/Filing Date: Filed on August 15, 2016; Issued as U.S. Pat. No. 10,248,910 on April 2, 2019
    • Brief Description: This patent describes a system for detecting and mitigating cyberattacks, which involves analyzing network traffic for anomalous activities. This directly relates to how the current patent determines if an access request is "anomalous" to influence the verification score.
    • Potential Anticipation: Claims that involve determining if an access request is anomalous and factoring this into the required verification score (as mentioned in the abstract and description of the current patent) could be anticipated or rendered obvious by this reference.
  9. U.S. patent application Ser. No. 15/206,195

    • Full Citation: U.S. patent application Ser. No. 15/206,195, titled "ACCURATE AND DETAILED MODELING OF SYSTEMS WITH LARGE COMPLEX DATA SETS USING A DISTRIBUTED SIMULATION ENGINE"
    • Publication/Filing Date: Filed on July 8, 2016
    • Brief Description: This application focuses on modeling systems with large datasets, which is relevant to building network baselines and understanding complex network behavior for security purposes.
    • Potential Anticipation: Elements of the current patent that rely on advanced data modeling and analysis to establish network baselines and identify unusual connection requests (part of determining the verification score) might be anticipated by this application.
  10. U.S. patent application Ser. No. 15/186,453

    • Full Citation: U.S. patent application Ser. No. 15/186,453, titled "SYSTEM FOR AUTOMATED CAPTURE AND ANALYSIS OF BUSINESS INFORMATION FOR RELIABLE BUSINESS VENTURE OUTCOME PREDICTION"
    • Publication/Filing Date: Filed on June 18, 2016
    • Brief Description: This patent generally discusses automated capture and analysis of business information, which may encompass network traffic data.
    • Potential Anticipation: Broad claims related to monitoring and analyzing data (like network traffic data) for decision-making could be implicated.
  11. U.S. patent application Ser. No. 15/166,158

    • Full Citation: U.S. patent application Ser. No. 15/166,158, titled "SYSTEM FOR AUTOMATED CAPTURE AND ANALYSIS OF BUSINESS INFORMATION FOR SECURITY AND CLIENT-FACING INFRASTRUCTURE RELIABILITY"
    • Publication/Filing Date: Filed on May 26, 2016
    • Brief Description: This application focuses on automated data capture and analysis for security and infrastructure reliability.
    • Potential Anticipation: Claims related to the monitoring and analysis of network traffic data for security purposes, as it forms the basis for determining risk in the current patent's authentication scheme, could be anticipated.
  12. U.S. patent application Ser. No. 15/141,752 (now U.S. Pat. No. 10,860,962)

    • Full Citation: U.S. patent application Ser. No. 15/141,752, titled "SYSTEM FOR FULLY INTEGRATED CAPTURE, AND ANALYSIS OF BUSINESS INFORMATION RESULTING IN PREDICTIVE DECISION MAKING AND SIMULATION", now issued as 10,860,962
    • Publication/Filing Date: Filed on April 28, 2016; Issued as 10,860,962 on December 8, 2020
    • Brief Description: This patent concerns integrated data capture and analysis for predictive decision making.
    • Potential Anticipation: Claims related to using analyzed data to make predictive decisions, such as determining a required security level or identifying anomalous behavior for authentication, may be anticipated.
  13. U.S. patent application Ser. No. 15/091,563 (now U.S. Pat. No. 10,204,147)

    • Full Citation: U.S. patent application Ser. No. 15/091,563, titled "SYSTEM FOR CAPTURE, ANALYSIS AND STORAGE OF TIME SERIES DATA FROM SENSORS WITH HETEROGENEOUS REPORT INTERVAL PROFILES", now issued as U.S. Pat. No. 10,204,147
    • Publication/Filing Date: Filed on April 5, 2016; Issued as U.S. Pat. No. 10,204,147 on February 12, 2019
    • Brief Description: This application specifically addresses the capture, analysis, and storage of time series data from various sensors. The multi-dimensional time series data server in US12231426B2 performs a similar function.
    • Potential Anticipation: Claims involving the monitoring and recording of a network's traffic data by a "multi-dimensional time series data server" are highly likely to be anticipated by this reference due to the explicit mention of time series data handling.
  14. U.S. patent application Ser. No. 14/986,536 (now U.S. Pat. No. 10,210,255)

    • Full Citation: U.S. patent application Ser. No. 14/986,536, titled "DISTRIBUTED SYSTEM FOR LARGE VOLUME DEEP WEB DATA EXTRACTION", now issued as U.S. Pat. No. 10,210,255
    • Publication/Filing Date: Filed on December 31, 2015; Issued as U.S. Pat. No. 10,210,255 on February 19, 2019
    • Brief Description: This patent discusses a distributed system for deep web data extraction, which relates to gathering diverse data, potentially contributing to the "plurality of sources" for the business operating system.
    • Potential Anticipation: While less direct, aspects of the claims concerning the input and processing of data from a plurality of sources, particularly if "network traffic data" is considered broadly to include information gathered from external sources, might find some overlap here.

Generated 5/28/2026, 12:46:38 AM

Obviousness

Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.

✓ Generated

Obviousness Analysis of US12231426 under 35 U.S.C. § 103

This analysis aims to identify combinations of prior art references that would render the claims of US patent 12231426 obvious to a person having ordinary skill in the art (POSITA) as of its priority date of October 28, 2015.

Patent US12231426: Contextual and Risk-Based Multi-Factor Authentication

The patent describes a system and method for multi-factor authentication (MFA) that dynamically determines a required verification score based on context and risk associated with a connection request. Users then use a plurality of verification methods to achieve this score and gain access. Key aspects include:

  • A multi-dimensional time series data server for monitoring network traffic.
  • A directed computation graph module to determine a network traffic baseline and a required verification score.
  • Verification methods including sensors, trusted/untrusted parties, video/picture, network monitoring, device ID, and one-time codes.
  • The verification score is influenced by factors such as the security level of resources, connection origin, and anomalous behavior.

Prior Art References (from the patent document and previous sections):

The patent itself lists several continuation-in-part applications and a provisional application that serve as prior art for various aspects. These include:

  • U.S. patent application Ser. No. 14/925,974, titled "RAPID PREDICTIVE ANALYSIS OF VERY LARGE DATA SETS USING THE DISTRIBUTED COMPUTATIONAL GRAPH," filed on Oct. 28, 2015.
  • U.S. patent application Ser. No. 15/237,625, titled "DETECTION MITIGATION AND REMEDIATION OF CYBERATTACKS EMPLOYING AN ADVANCED CYBER-DECISION PLATFORM," filed on Aug. 15, 2016 (though its priority date traces back to earlier applications, the content relevant to cyberattack detection would be pertinent).
  • U.S. patent application Ser. No. 15/091,563, titled "SYSTEM FOR CAPTURE, ANALYSIS AND STORAGE OF TIME SERIES DATA FROM SENSORS WITH HETEROGENEOUS REPORT INTERVAL PROFILES," filed on Apr. 5, 2016.
  • U.S. Pat. No. 10,742,647 (from Ser. No. 15/790,860, which claims priority to the provisional application 62/574,708 filed Oct. 19, 2017), "CONTEXTUAL AND RISK-BASED MULTI-FACTOR AUTHENTICATION." This seems to be a related patent with a later filing date but earlier provisional priority, and appears to be very similar in subject matter, indicating the concepts were known to the inventors at or before the priority date of the instant patent.

Obviousness Combinations and Rationale:

A POSITA in network security and multi-factor authentication as of October 28, 2015, would have been motivated to combine known elements from various prior art references to arrive at the claimed invention.

Combination 1: Ser. No. 14/925,974 + General MFA Knowledge + Risk-Based Authentication Concepts

  • Ser. No. 14/925,974 ("RAPID PREDICTIVE ANALYSIS OF VERY LARGE DATA SETS USING THE DISTRIBUTED COMPUTATIONAL GRAPH"): This reference (filed on the same priority date) discloses a system for rapid predictive analysis of large datasets using a distributed computational graph. This would teach a POSITA the underlying architectural and data processing capabilities for analyzing network traffic data and establishing baselines, as described in US12231426 for its "multi-dimensional time series data server" and "directed computation graph module" (see description of "a system for contextual and risk-based multi-factor authentication" and the method steps (a)-(d) in US12231426). The patent explicitly states that the "multi-dimensional time series data server" monitors and records network traffic data, and the "directed computation graph module" receives this data to determine a network traffic baseline.
  • General MFA Knowledge: By 2015, multi-factor authentication was widely used to secure online accounts, employing methods like one-time codes, unique links, and authenticator apps, as acknowledged in the background of US12231426.
  • Risk-Based Authentication Concepts: The concept of adjusting authentication requirements based on risk factors (e.g., location, device, anomalous behavior) was a known trend in security to enhance usability while maintaining security. For instance, a system might ask for a second factor only if a login originated from an unusual geographic location or an unrecognized device.

Motivation to Combine: A POSITA would be motivated to combine the robust data analysis and predictive capabilities of Ser. No. 14/925,974 with general MFA and risk-based authentication to create a more intelligent and adaptive security system. The motivation would be to overcome the limitations of traditional MFA, particularly "over-reliance on a single method of delivery" and the need to "dynamically determine the varying amounts of verification needed, based on the context and risks associated with the connection," as explicitly stated as a "need" in US12231426. By using the predictive analysis of network traffic (from Ser. No. 14/925,974) to establish a baseline and detect anomalous activities, the system could dynamically determine a "required verification score" and then prompt for multiple, context-aware verification methods, improving both security and user experience. This directly addresses the problem identified in the background of US12231426.

Combination 2: Ser. No. 15/237,625 + General MFA Knowledge + Risk-Based Authentication Concepts

  • Ser. No. 15/237,625 ("DETECTION MITIGATION AND REMEDIATION OF CYBERATTACKS EMPLOYING AN ADVANCED CYBER-DECISION PLATFORM"): This application, filed in August 2016 but likely drawing on earlier priority, discloses a system for detecting and mitigating cyberattacks. This reference explicitly details continuous retrieval and analysis of network traffic data to predict normal usage patterns and identify anomalous activities, such as unusual access attempts or brute-force attacks (see FIG. 2 and accompanying description in US12231426, particularly steps 201 and 205, which are directly related to the cybersecurity functions of business operating system 100). This provides the "cybersecurity functions" mentioned in US12231426 as being used by the server to dynamically determine the required verification score based on whether an access request is anomalous.
  • General MFA Knowledge and Risk-Based Authentication Concepts: As discussed above, these were widely known.

Motivation to Combine: A POSITA would be motivated to integrate the sophisticated cyberattack detection capabilities of Ser. No. 15/237,625 with MFA and risk-based authentication. The primary motivation would be to enhance the security of user access by directly tying the authentication strength to the real-time risk assessment derived from network behavior analysis. If the system (drawing from Ser. No. 15/237,625) detects anomalous behavior associated with an access request, it would be obvious to a POSITA to increase the authentication burden, hence requiring a higher "verification score" and more or stronger "plurality of verification methods" as described in US12231426. This combination directly implements the idea of "dynamically determine[ing] a required verification score based at least on the circumstances of the connection... whether the access request is determined to be anomalous using the cybersecurity functions of business operating system 100" (US12231426, description related to server 405).

Combination 3: Ser. No. 15/091,563 + General MFA Knowledge + Diverse Verification Methods

  • Ser. No. 15/091,563 ("SYSTEM FOR CAPTURE, ANALYSIS AND STORAGE OF TIME SERIES DATA FROM SENSORS WITH HETEROGENEOUS REPORT INTERVAL PROFILES"): This reference concerns the capture, analysis, and storage of time series data from various sensors. This would provide the technical foundation for integrating diverse sensor data into a system, which is crucial for many of the verification methods listed in US12231426 (e.g., biometric scans via sensors 415a).
  • General MFA Knowledge: Basic MFA was already prevalent.
  • Diverse Verification Methods: The general concept of using multiple and varied authentication factors was gaining traction to improve security. The patent explicitly lists a "plurality of verification methods" including sensors (biometrics, badge scans), trusted parties, untrusted parties (crowd-sourcing), video/picture, network monitoring, device ID, and one-time codes (415a-g in FIG. 4). While the specific combination might be novel, the individual methods, or at least the idea of leveraging a variety of factors, were generally known or conceptually straightforward in the security domain by 2015.

Motivation to Combine: A POSITA would be motivated to combine the robust sensor data handling of Ser. No. 15/091,563 with MFA principles to enable a broader range of verification options. The motivation would be to create a more resilient MFA system by drawing on a wider array of verifiable attributes, making it harder for an attacker to compromise all factors. For example, knowing that sensor data can be reliably collected and analyzed (from Ser. No. 15/091,563), a POSITA would readily apply this to biometric sensors for authentication, improving the security and flexibility of the MFA system described in US12231426. The idea of using a plurality of verification methods to build up a score would be an obvious way to implement a flexible, risk-adjusted authentication scheme.

Overall Obviousness Rationale:

The core concept of US12231426 is to dynamically adjust MFA requirements based on context and risk, leveraging advanced data analysis of network traffic and diverse verification methods. Many of the building blocks for this invention—robust data analysis, cyberattack detection, handling sensor data, and the general principles of MFA and risk-based authentication—were either present in the cited prior art applications by the same assignee/inventors or were well-known in the field by the priority date.

A POSITA would have found it obvious to combine these known elements to create a more sophisticated and adaptive MFA system. The motivation stems from the recognized "needs" in the art, as articulated within US12231426 itself: to move beyond single-method MFA reliance and to dynamically tailor verification based on real-time risk. The various prior art references provide the specific technical means (e.g., directed computational graphs for baseline determination, network monitoring for anomalous activity, sensor data processing) that a POSITA would integrate into a unified system to achieve this dynamic, risk-based MFA. The overall system, while potentially presenting a more comprehensive solution, largely combines functionalities already described or inherently suggested by the existing body of work from the same inventors and general knowledge in the field.

The fact that US12231426 is a continuation of applications sharing similar titles and subject matter further supports the notion that the inventive concepts evolved from previously disclosed work by the same entity, suggesting that elements were known and incrementally combined or refined.

Therefore, the claims of US12231426 would likely be considered obvious under 35 U.S.C. § 103 given the combinations of the identified prior art references and the clear motivations of a POSITA to address existing shortcomings in MFA by creating more adaptive and context-aware systems.

Generated 5/28/2026, 12:46:34 AM

Extensions

Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Derivative works

Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.

Not generated yet. Click Generate to call the active LLM provider with the configured prompt.

Keep exploring

Other patents in Software Technology & Computing Systems (T)

See all Software Technology & Computing Systems (T) patents →

This patent in court (1)

1 tracked lawsuit name US 12231426.