IP Library Granted Patent US 7,441,263
Granted Patent B1
US 7,441,263 · App. 09/814,971 · Granted Oct 21, 2008

System, method and computer program product for providing unified authentication services for online applications

Assignee: Citibank, N.A.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,441,263
App. No.
09/814,971
Granted
Oct 21, 2008
Kind
B1
Abstract

A system, method and computer program product for providing unified authentication services in an Application Service Provider (ASP) setting to a registered end-user of one or more online (or web) applications. The system includes client side components, a user management component coupled to the client side components and server side components coupled to the user management component. The client side components include an authentication control component that manages the process of capturing a user-determined policy for a first account and user credentials. This allows the user to define the level of protection to access the first account. This includes, but is not limited to, accounts/applications that have been configured specifically for used with the system and particular user credentials and accounts that have been subsequently set up but configured to use the same user credentials. The client side components then communicate the result of capturing the user-determined policy and user credentials to the user management component. The user management component stores the user-determined policy and user credentials in a centralized location. In addition, the user management component organizes the user-determined policy and user credentials such that the user credentials can be reused for user authentication to a second account. Finally, the server side components include an authentication server. The user management component indicates to the authentication server to use the user-determined policy for user authentication to the first account.

Claims (30)

1. A system for providing user authentication to a first account provided by a first server via a communication medium, comprising:

client side components;

a user management component coupled to said client side components via the communication medium; and

server side components coupled to said user management component via the communication medium,

wherein said client side components include an authentication control component that manages a process of capturing a user-determined policy for the first account and user credentials, thereby allowing a user to define a level of protection by selecting one or more identification devices from a list of at least two identification devices that are used to execute the policy for accessing the first account and wherein said client side components communicate the result of capturing said user-determined policy and said user credentials to said user management component,

wherein said user management component stores said user-determined policy and said user credentials in a centralized location and organizes said user-determined policy and said user credentials such that said user credentials can be reused for user authentication to a second account provided by a second server;

wherein said user-determined policy for the first account and a second user-determined policy for said second account utilize different sets of devices; and

wherein said server side components include an authentication server, and wherein said user management component indicates to said authentication server to use said user-determined policy for user authentication to the first account.

2. The system of claim 1 , wherein the communication medium is the Internet.

3. The system of claim 1 , wherein the communication medium is a local network.

4. The system of claim 1 , wherein the communication medium is a wireless network.

5. The system of claim 1 , wherein the first server and said second server are web servers.

6. The system of claim 1 , wherein the first server and said second server are application servers.

7. The system of claim 1 , wherein said authentication control component is checked for integrity each time it is invoked.

8. The system of claim 1 , wherein the first server and said second server are unrelated.

9. The system of claim 1 , wherein the first server and said second server are related.

10. A method for providing user authentication to a first account provided by a first server via a communication medium, comprising the steps of:

managing, via an authentication control component, the process of capturing a user-determined policy for the first account and user credentials, thereby allowing a user to define a level of protection by selecting one or more identification devices from a list of at least two identification devices that are used to execute the policy for accessing the first account;

communicating, from said authentication control component to a user management component, the result of capturing said user-determined policy and said user credentials;

organizing, by said user management component, said user-determined policy and said user credentials in a centralized location such that said user credentials can be reused for user authentication to a second account provided by a second server;

wherein said user-determined policy for the first account and a second user-determined policy for said second account utilize different sets of devices; and

indicating, by said user management component to said authentication server, to use said user-determined policy for user authentication to the first account.

11. The method of claim 10 , wherein the communication medium is the Internet.

12. The method of claim 10 , wherein the communication medium is a local network.

13. The method of claim 10 , wherein the communication medium is a wireless network.

14. The method of claim 10 , wherein the first server and said second server are web servers.

15. The method of claim 10 wherein the first server and said second server are application servers.

16. The method of claim 10 wherein said authentication control component is checked for integrity each time it is invoked.

17. The method of claim 10 , wherein the first server and said second server are unrelated.

18. The method of claim 10 , wherein the first server and said second server are related.

Assignments (8)
RELEASE OF SECURITY INTEREST Recorded Jan 30, 2007
From: COMERICA BANK
To: BIONETRIX SYSTEMS CORPORATION
Reel/Frame 018816/0930 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2006
From: BNX SYSTEMS CORPORATION
To: CITIBANK, N.A.
Reel/Frame 017823/0036 →
TERMINATION OF SECURITY INTEREST Recorded Sep 2, 2004
From: BNX SYSTEMS CORPORATION
To: CARLYLE VENTURE PARTNERS, L.P.; CARYLE U.S. VENTURE PARTNERS, L.P.; C/S VENTURE INVESTORS, L.P.; CARYLE VENTURE COINVESTMENT, L.L.C.; COLUMBIA CAPITAL EQUITY PARTNERS II (QP), L.P.; COLUMBIA BIONETRIX PARTNERS, LLC; COLUMBIA CAPITAL EQUITY PARTNERS III (QP), L.P.; COLUMBIA BIONEXTRIX PARTNERS III, L.L.C.; COLUMBIA CAPITAL EQUITY PARTNERS III (AI), L.P.; WALKER INVESTMENT FUND II SBIC, LP; DINER CLUB I, LLC, THE; MELTON, WILLIAM
Reel/Frame 015098/0512 →
SECURITY INTEREST Recorded Mar 11, 2004
From: BNX SYSTEMS CORPORATION
To: CARLYLE VENTURE PARTNERS, L.P.; CARYLE U.S. VENTURE PARTNERS, L.P.; C/S VENTURE INVESTORS, LP.; CARYLE VENTURE COINVESTMENT, L.L.C.; COLUMBIA CAPITAL EQUITY PARTNERS II (QP), L.P.; COLUMBIA BIONETRIX PARTNERS, LLC; COLUMBIA CAPITAL EQUITY PARTNERS III (QP), L.P.; COLUMBIA BLONEXTRIX PARTNERS III, L.L.C.; COLUMBIA CAPITAL EQUITY PARTNER III (AL), L.P.; WALKER INVESTMENT FUND II SBIC, LP; THE DINER CLUB I, LLC; MELTON, WILLIAM
Reel/Frame 014420/0154 →
SECURITY INTEREST Recorded Mar 11, 2004
From: BNX SYSTEMS CORPORATION
To: CARLYLE VENTURE PARTNERS, L.P.; CARYLE U.S. VENTURE PARTNERS, L.P.; C/S VENTURE INVESTORS, L.P.; CARYLE VENTURE COINVESTMENT, L.L.C.; COLUMBIA CAPITAL EQUITY PARTNERS II (QP), L.P.; COLUMBIA BIONETRIX PARTNERS, LLC; COLUMBIA CAPITAL EQUITY PARTNERS III (QP), L.P.; COLUMBIA BIONEXTRIX PARTNERS III, L.L.C.; COLUMBIA CAPITAL EQUITY PARTNERS III (AI), L.P.; WALKER INVESTMENT FUND II SBIC, LP; DINER CLUB I, THE LLC; MELTON, WILLIAM
Reel/Frame 014420/0123 →
SECURITY AGREEMENT Recorded Dec 18, 2002
From: BIONETRIX SYSTEMS CORPORATION
To: CARLYLE VENTURE PARTNERS, L.P.; CARYLE U.S. VENTURE PARTNERS, L.P.; C/S VENTURE INVESTORS, L.P.; CARYLE VENTURE COINVESTMENT, L.L.C.; COLUMBIA CAPITAL EQUITY PARTNERS II (QP), L.P.; COLUMBIA BIONETRIX PARTNERS, LLC; COLUMBIA CAPITAL EQUITY PARTNERS III (QP), L.P.; COLUMBIA BIONEXTRIX PARTNERS III, L.L.C.; COLUMBIA CAPITAL EQUITY PARTNERS III (AI), L.P.; WALKER INVESTMENT FUND II SBIC, LP; ADVANTA GROWTH CAPITAL FUND, LP; DINER CLUB I, LLC, THE; NEXTLEVEL VENTURE PARTNERS, LLC; MELTON, WILLIAM; GARRETT VENTURE PARTNERS LLC; CANDELORI, ERIC; MARTIN JR., EDWIN M.; SPANGLER, NANCY A.
Reel/Frame 013599/0467 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 6, 2002
From: BAKSHI, BIKRAM S.; HELMS, DAVID W.; ROCHON, ANTHONY C.; WALKER, TREVOR J.
To: BIONETRIX SYSTEMS CORPORATION
Reel/Frame 012565/0128 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 29, 2001
From: BIONETRIX SYSTEMS CORPORATION
To: IMPERIAL BANK
Reel/Frame 012122/0666 →
Continuity (1)
Provisional Application 6019147100 · Mar 23, 2000