IP Library Patent Application 11742891
Patent Application
App. No. 11/742,891

Triggering of Authentication Rules for Service Provisioning

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
11/742,891
Abstract

Described are methods, systems, and apparatus, including computer program products for providing authentication for service provisioning. One or more executable authentication rules are provided for determining access by a user to one or more services. A request is received from the user. The request is for a first service from the one or more services at an enforcement point. It is determined, at the enforcement point, if at least a first executable authentication rule from the one or more executable authentication rules applies to the user. The first executable authentication rule is for determining access by the user to the first service, wherein determining if the first executable authentication rule applies includes determining if one or more triggers specified by the first executable authentication rule are triggered.

Claims (65)

1 . A computerized method for providing authentication for service provisioning, the method comprising:

providing one or more executable authentication rules for determining access by a user to one or more services;

receiving, from the user, a request for a first service from the one or more services at an enforcement point; and

determining, at the enforcement point, if at least a first executable authentication rule from the one or more executable authentication rules applies to the user, the first executable authentication rule for determining access by the user to the first service, wherein determining if the first executable authentication rule applies comprises determining if one or more triggers specified by the first executable authentication rule are triggered.

2 . The method of claim 1 , wherein providing the one or more executable authentication rules comprises providing a rules credential including the one or more executable authentication rules.

3 . The method of claim 1 , wherein the one or more triggers comprise: a user trigger, a request trigger, an enforcement point trigger, a policy trigger, or any combination thereof.

4 . The method of claim 3 , wherein the user trigger comprises an identification credential of the user, an identification credential of a group of users including the user, or any combination thereof.

5 . The method of claim 4 , wherein the group of users comprises: one or more employees of an organization, one or more customers of the organization, or any combination thereof.

6 . The method of claim 3 , wherein the request trigger comprises: an access-channel trigger, an access-point trigger, a device trigger, or any combination thereof.

7 . The method of claim 6 further comprising triggering the access-channel trigger when the user sends the request in: a web message, a universal resource locator (URL) message, electronic mail, text messaging, instant messaging, a session initiation protocol (SIP) message, a short message service (SMS) message, a multimedia messaging service (MMS) message, an enhanced messaging service (EMS) message, an IP multimedia system (IMS) message, a live voice call, an automated voice call, an interactive voice response (IVR) call, or any combination thereof.

8 . The method of claim 6 further comprising triggering the access-point trigger when the request originates from a specified network access-point, the specified network access-point comprising: an IP address, a network IP address, a telephone number, an area code, a country code, or any combination thereof.

9 . The method of claim 6 further comprising triggering the device trigger when the request originates from a specified device, the specified device characterized by a software characteristic or a hardware characteristic.

10 . The method of claim 3 , wherein the enforcement point trigger comprises: a time trigger, a service type trigger, a function trigger, an expiration-of-time trigger, or any combination thereof.

11 . The method of claim 10 further comprising triggering the time trigger when the request is received during: a specified time range, a specified day of the week, a specified set of dates, or any combination thereof.

12 . The method of claim 10 further comprising triggering the service type trigger when the first service is associated with: a retail services type, an employment services type, an insurance services type, or any combination thereof.

13 . The method of claim 10 further comprising triggering the function trigger when the first service is associated with: a financial service, an accounting service, a personnel service, an administrative service, a trade service, or any combination thereof.

14 . The method of claim 3 , wherein the policy trigger comprises a fraud trigger.

15 . The method of claim 1 further comprising determining by default, at the enforcement point, that the first executable authentication rule applies to the user if the first executable authentication rule does not specify at least a first trigger.

16 . The method of claim 1 further comprising determining, at the enforcement point, if at least a second executable authentication rule from the one or more executable authentication rules applies to the user, wherein determining if the second executable authentication rule applies comprises determining if one or more triggers specified by the second executable authentication rule are triggered.

17 . The method of claim 16 , wherein the steps of determining if the first and the second executable authentication rules apply to the user are processed in an order specified by one or more priority characteristics of at least one of the first or the second executable authentication rule, the one or more priority characteristics comprising: a priority code, a priority class, a priority type, a priority context, or any combination thereof.

18 . The method of claim 1 , when the first executable authentication rule applies, further comprising:

determining if the user satisfies the first executable authentication rule;

providing access by the user to the first service if the user satisfies the first executable authentication rule; and

executing an authentication action if the user does not satisfy the first executable authentication rule.

19 . The method of claim 18 , wherein determining if the user satisfies the first executable authentication rule comprises determining a satisfaction state of the first executable authentication rule.

20 . The method of claim 18 , wherein the authentication action comprises: a hard token action, a soft token action, a personal identification number (PIN) action, a password (PW) action, a knowledge action, a biometric action, a modify-user information action, or any combination thereof.

21 . The method of claim 18 , wherein executing the authentication action comprises directing the user to a site different from the enforcement point.

22 . The method of claim 21 , wherein executing the authentication action further comprises blocking the user from accessing the first service.

23 . The method of claim 1 , when the first executable authentication rule applies, further comprising:

providing access by the user to the first service; and

executing an authentication action when the user accesses the first service.

24 . The method of claim 23 , wherein the authentication action comprises a monitoring action.

25 . The method of claim 23 , when the first executable authentication rule does not apply, further comprising providing access by the user to the first service.

26 . The method of claim 1 further comprising:

providing, when the first executable authentication rule applies, access by the user to the first service; and

directing, when the first executable authentication rule does not apply, the user to a redirect service different from the first service.

27 . The method of claim 26 , wherein the first service comprises a fraud service.

28 . The method of claim 18 , wherein the authentication action is specified by at least one of:

the first executable authentication rule or the enforcement point.

29 . The method of claim 18 further comprising modifying a satisfaction state of the first executable authentication rule based on a result of the authentication action.

30 . The method of claim 18 further comprising determining, at the enforcement point and before the user is provided access to the first service, if at least a second executable authentication rule from the one or more executable authentication rules applies to the user, wherein determining if the second executable authentication rule applies comprises determining if one or more triggers specified by the second executable authentication rule are triggered.

31 . The method of claim 1 further comprising:

determining if the user satisfies the first executable authentication rule; and

providing access by the user to the first service if the user does not satisfy the first executable authentication rule.

32 . The method of claim 31 , wherein the first service comprises an authentication service for satisfying the first executable authentication rule.

33 . The method of claim 31 , wherein providing the one or more executable authentication rules comprises providing a rules credential including the one or more executable authentication rules.

34 . The method of claim 33 further comprising bypassing processing of at least a second executable authentication rule from the one or more executable authentication rules if the user does not satisfy the first executable authentication rule.

35 . The method of claim 1 , wherein the one or more executable authentication rules comprise: a mandatory configurable rule, an optional configurable rule, a mandatory non-configurable rule, an optional non-configurable rule, or any combination thereof.

36 . The method of claim 1 further comprising:

determining if a second executable authentication rule from the one or more executable authentication rules applies to the user at the enforcement point;

determining if the second executable authentication rule is grouped with the first executable authentication rule;

executing an authentication action specified by the first executable authentication rule; and

modifying a satisfaction state of the second executable authentication rule based on a result of the authentication action if the second executable authentication rule is grouped with the first executable authentication rule.

37 . The method of claim 1 , wherein the first service comprises: a financial service, an accounting service, a personnel service, an administrative service, a trade service, or any combination thereof.

38 . The method of claim 1 , wherein a type of the first service comprises: a retail service type, an employment service type, an insurance services type, or any combination thereof.

39 . A computer program product, tangibly embodied in an information carrier, the computer program product including instructions being operable to cause a data processing apparatus to:

provide one or more executable authentication rules for determining access by a user to one or more services;

receive, from the user, a request for a first service from the one or more services at an enforcement point;

determine if at least a first executable authentication rule from the one or more executable authentication rules applies to the user at the enforcement point, the first executable authentication rule for determining access by the user to the first service, wherein determining if the first executable authentication rule applies comprises determining if one or more triggers specified by the first executable authentication rule is triggered; and

execute an authentication action specified by the first executable authentication rule when the first executable authentication rule applies.

40 . A system for providing authentication for service provisioning, the system comprising an authentication system adapted to:

provide one or more executable authentication rules for determining access by a user to one or more services;

receive, from the user, a request for a first service from the one or more services at an enforcement point;

determine if at least a first executable authentication rule from the one or more executable authentication rules applies to the user at the enforcement point, the first executable authentication rule for determining access by the user to the first service, wherein determining if the first executable authentication rule applies comprises determining if one or more triggers specified by the first executable authentication rule is triggered; and

execute an authentication action specified by the first executable authentication rule when the first executable authentication rule applies.

Assignments (2)
MERGER Recorded Dec 2, 2007
From: FMR CORP.
To: FMR LLC
Reel/Frame 020184/0151 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 25, 2007
From: KULKARNI, RAJANDRA LAXMAN; GREENBERG, ADAM; MAROTTO, ANTHONY M.; LOPIANO, MICHAEL FRANCIS; POPOWYCZ, ALEXANDER L.
To: FMR CORP.
Reel/Frame 019344/0672 →