US2017339125A1PendingUtilityA1

Method and system for transmitting authentication context information

Assignee: III HOLDINGS 1 LLCPriority: Dec 31, 2002Filed: Jun 12, 2017Published: Nov 23, 2017
Est. expiryDec 31, 2022(expired)· nominal 20-yr term from priority
Inventors:Michael Barrett
G06F 21/33H04L 63/205H04L 63/0815G06F 21/41G06F 21/31H04L 63/08
60
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A system of the present invention uses an identity provider to provide the authentication services for multiple service providers. An identity provider communicates with one or more service providers. A user that wishes to gain access to a service provider is authenticated through the use of the identity provider. A user desiring to access a service provider is first authenticated by the identity provider. The identity provider determines if the user meets the desired class level and provides various information related to the authentication. When the user attempts to access a second service provider that is associated with the same identity provider, the second service provider accesses the identity provider and determines that the user was recently authenticated. The identity provider then transmits the relevant information regarding the authentication process to the second service provider, which can then allow or deny the user access to the second service provider.

Claims

exact text as granted — not AI-modified
1 - 20 . (canceled) 
     
     
         21 . A method comprising:
 receiving, by a computer system, authentication information from a user;   based on the authentication information, the computer system determining that the authentication information meets a requirement for a first system associated with a first entity to authenticate the user;   subsequent to receiving the authentication information, the computer system detecting a request by the user to access a second system associated with a second entity; and   based on a requirement for the second system to authenticate the user and based on the determining, the computer system providing to the second system an indication of authentication of the user dependent upon at least a physical protection characteristic of the computer system.   
     
     
         22 . The method of  claim 21 , wherein the computer system providing the indication of authentication of the user to the second system occurs without providing the authentication information to the second system. 
     
     
         23 . The method of  claim 21 , wherein the physical protection characteristic is indicative of one or more physical controls of a facility housing the computer system. 
     
     
         24 . The method of  claim 21 , wherein the computer system providing to the second system the indication of authentication of the user is further dependent on one or more of: an operational protection characteristic, a technical protection characteristic, an authentication method, or any combination thereof. 
     
     
         25 . The method of  claim 21 , further comprising:
 receiving, by the computer system, one or more authentication requirements of the second system, wherein the one or more authentication requirements include a required level of the physical protection characteristic.   
     
     
         26 . The method of  claim 21 , wherein receiving the authentication information from the user occurs via a web-based interface. 
     
     
         27 . The method of  claim 21 , wherein receiving the authentication information from the user occurs subsequent to the user being redirected to the computer system from the first system. 
     
     
         28 . A computer system, comprising:
 a processor; and   a memory that stores instructions, wherein the instructions are executable by the processor to perform operations comprising:
 determining that authentication information meets a requirement for a first system associated with a first entity to authenticate a user; 
 subsequent to determining that the authentication information meets the requirement, detecting a request by the user to access a second system associated with a second entity; 
 dependent at least upon a physical protection characteristic of the computer system, determining that additional authentication information is needed to authenticate the user for access to the second system; and 
 dependent upon successfully receiving the additional authentication information, providing to the second system an indication of authentication of the user. 
   
     
     
         29 . The computer system of  claim 28 , wherein determining that additional authentication information is needed is further dependent upon a type of service provided by the second system. 
     
     
         30 . The computer system of  claim 28 , wherein determining that additional authentication information is needed is further dependent upon an amount of time elapsed since the determining that the authentication information meets the requirement for the first system. 
     
     
         31 . The computer system of  claim 28 , wherein providing the indication of authentication of the user includes identifying to the second system one or more criteria used to authenticate the user. 
     
     
         32 . The computer system of  claim 28 , wherein the operations further comprise:
 providing a list of authentication capabilities in a standardized format.   
     
     
         33 . The computer system of  claim 32 , wherein the standardized format is Web Service Definition Language (WSDL). 
     
     
         34 . The computer system of  claim 28 , wherein the physical protection characteristic is indicative of a level of physical security of the computer system. 
     
     
         35 . An article of manufacture including a non-transitory computer readable medium having instructions stored thereon that are executable by a computer system to cause the computer system to perform operations comprising:
 based on authentication information previously used to grant a user access to a first system associated with a first entity, determining that the authentication information meets a requirement of a second system associated with a second entity to authenticate the user, wherein the determining is dependent upon at least a physical protection characteristic of the computer system; and   based on the determining, providing to the second system an indication of authentication of the user.   
     
     
         36 . The article of manufacture of  claim 35 , wherein the determining is further dependent upon an amount of time elapsed since the authentication information was previously used to grant the user access to the first system. 
     
     
         37 . The article of manufacture of  claim 35 , wherein determining that the authentication information meets the requirement of the second system comprises:
 detecting that additional authentication information is required to authenticate the user for access to the second system; and   successfully receiving the additional authentication information.   
     
     
         38 . The article of manufacture of  claim 37 , wherein detecting that additional authentication information is required comprises detecting that the second system requires a higher level of authentication than the first system. 
     
     
         39 . The article of manufacture of  claim 35 , wherein the authentication information includes one or more of a personal identification number (PIN), a user ID, a password, a biometric identifier, or any combination thereof. 
     
     
         40 . The article of manufacture of  claim 35 , wherein the physical protection characteristic is indicative of a location of the computer system.

Join the waitlist — get patent alerts

Track US2017339125A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.