US2008115192A1PendingUtilityA1
Customizable authentication for service provisioning
Est. expiryNov 7, 2026(~0.3 yrs left)· nominal 20-yr term from priority
Inventors:Rajandra Laxman KulkarniAdam Phillip Takla GreenbergAnthony M. MarottoAlexander L. PopowyczMichael Francis Lopiano
G06F 21/33H04L 9/3226H04L 2209/56H04L 63/104H04L 63/20H04L 63/205H04L 63/08H04L 9/3234G06F 21/31H04L 63/0263H04L 2209/80
46
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
Described are methods, systems, and apparatus, including computer program products for providing customizable authentication for service provisioning. A first user is enabled to customize an authentication system associated with a service type. Customizing the authentication system includes defining one or more authentication rules for determining access for a second user to a service for the service type.
Claims
exact text as granted — not AI-modified1 - 35 . (canceled)
36 . A computerized method for providing customizable authentication for service provisioning, the method comprising:
enabling a client of a service provider to customize an authentication system of the service provider, wherein customizing the authentication system comprises defining one or more executable authentication rules for determining access by a consumer to a service provided by the service provider.
37 . The method of claim 36 , wherein the client is the consumer.
38 . The method of claim 36 , wherein the client comprises a client organization or one or more subgroups of the client organization.
39 . The method of claim 36 , wherein the consumer comprises one or more individuals associated with the client, the one or more individuals comprising: one or more employees of the client, one or more customers of the client, or any combination thereof.
40 . The method of claim 36 further comprising enabling the consumer to customize the authentication system associated with the service.
41 . The method of claim 40 , wherein enabling the consumer to customize the authentication system comprises enabling the consumer to edit one or more of the one or more executable authentication rules.
42 . The method of claim 40 , wherein enabling the consumer to customize the authentication system comprises enabling the consumer to define one or more consumer executable authentication rules for determining access by the consumer to the service, wherein the one or more consumer executable authentication rules are different from the one or more executable authentication rules.
43 . The method of claim 36 , wherein the one or more executable authentication rules comprise: a configurable rule, a non-configurable rule, or any combination thereof.
44 . The method of claim 36 , wherein the one or more executable authentication rules comprise: a mandatory rule, an optional rule, or any combination thereof.
45 . The method of claim 44 further comprising enabling the consumer to select enrollment in at least one of the one or more executable authentication rules when the at least one of the one or more executable authentication rules is optional.
46 . The method of claim 36 further comprising:
selecting at least a first executable authentication rule from the one or more executable authentication rules, wherein selecting the first executable authentication rule is based on: a characteristic of the consumer, a characteristic of a request, a characteristic of an acquisition point, or any combination thereof; and generating a rules credential, the rules credential including the first executable authentication rule.
47 . The method of claim 46 , wherein the characteristic of the consumer comprises an identification credential of the consumer, an identification credential of a group of consumers including the consumer, or any combination thereof.
48 . The method of claim 46 , wherein the characteristic of the request comprises: an access-channel characteristic, an access-point characteristic, a device characteristic, or any combination thereof.
49 . The method of claim 46 , wherein the characteristic of the acquisition point comprises: a time characteristic, a policy characteristic, a service type characteristic, a function type characteristic, or any combination thereof.
50 . The method of claim 49 , wherein the rules credential is generated at an acquisition point.
51 . The method of claim 36 further comprising:
receiving, from the consumer, a request for the service at an enforcement point; and determining, at the enforcement point, if at least a first executable authentication rule from the one or more executable authentication rules applies to the consumer, wherein determining if the first executable authentication rule applies comprises determining if one or more triggers specified by the first executable authentication rule are triggered.
52 . The method of claim 51 , wherein the one or more triggers comprise: a user trigger, a request trigger, an enforcement point trigger, a policy trigger, or any combination thereof.
53 . The method of claim 52 , wherein the user trigger comprises an identification credential of the consumer, an identification credential of a group of consumers including the consumer, or any combination thereof.
54 . The method of claim 52 , wherein the request trigger comprises: an access-channel trigger, an access-point trigger, a device trigger, or any combination thereof.
55 . The method of claim 52 , wherein the enforcement point trigger comprises: a time trigger, a service type trigger, a function trigger, an expiration-of-time trigger, or any combination thereof.
56 . The method of claim 36 further comprising:
receiving, from the consumer, a request for the service at an enforcement point; determining if the consumer satisfies at least a first executable authentication rule from the one or more executable authentication rules; providing access by the consumer to the service if the consumer satisfies the first executable authentication rule; and executing an authentication action if the consumer does not satisfy the first executable authentication rule.
57 . The method of claim 56 , wherein determining if the consumer satisfies the first executable authentication rule comprises determining a satisfaction state of the first executable authentication rule.
58 . The method of claim 56 , wherein the authentication action comprises: a hard token action, a soft token action, a personal identification number (PIN) action, a password (PW) action, a knowledge action, a biometric action, a modify-user information action, or any combination thereof.
59 . The method of claim 56 , wherein executing the authentication action comprises directing the consumer to a site different from the enforcement point.
60 . The method of claim 56 , wherein the authentication action is specified by at least one of: the first executable authentication rule or the enforcement point.
61 . The method of claim 56 further comprising modifying a satisfaction state of the first executable authentication rule based on a result of the authentication action.
62 . The method of claim 36 , wherein the service comprises: a financial service, an accounting service, a personnel service, an administrative service, a trade service, or any combination thereof.
63 . The method of claim 36 , wherein a type of the service comprises: a retail service type, an employment service type, an insurance services type, or any combination thereof.
64 . A computer program product, tangibly embodied in an information carrier, the computer program product including instructions being operable to cause a data processing apparatus to:
enable a client of a service provider to customize an authentication system of the service provider, wherein customizing the authentication system comprises defining one or more executable authentication rules for determining access by a consumer to a service provided by the service provider.
65 . A system for providing customizable authentication for service provisioning, the system comprising an authentication system adapted to:
enable a client of a service provider to customize the authentication system of the service provider, wherein customizing the authentication system comprises defining one or more executable authentication rules for determining access by a consumer to a service provided by the service provider.Join the waitlist — get patent alerts
Track US2008115192A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.