IP Library Patent Application 11742912
Patent Application
App. No. 11/742,912

Authentication Rule Overrides For Service Provisioning

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
11/742,912
Abstract

Described are methods, systems, and apparatus, including computer program products for providing authentication for service provisioning. An executable authentication rule is provided for determining access by a user to a service. A request for the service is received at an enforcement point from the user. It is determined if the user satisfies the executable authentication rule. Access is provided by the user to the service if the user does not satisfy the executable authentication rule.

Claims (33)

1 . A computerized method for providing authentication for service provisioning, the method comprising:

providing an executable authentication rule for determining access by a user to a service;

receiving, from the user, a request for the service at a first enforcement point;

determining if the user satisfies the executable authentication rule; and

providing access by the user to the service if the user does not satisfy the executable authentication rule.

2 . The method of claim 1 further comprising providing access by the user to the service if the user satisfies the executable authentication rule.

3 . The method of claim 1 further comprising directing the user to a site different from the first enforcement point if the user satisfies the executable authentication rule.

4 . The method of claim 1 , wherein the service comprises an authentication service for satisfying the executable authentication rule.

5 . The method of claim 4 further comprising modifying a satisfaction state of the executable authentication rule based on a result of the user accessing the service.

6 . The method of claim 1 , wherein providing the executable authentication rule comprises providing a rules credential including the executable authentication rule and one or more other executable authentication rules.

7 . The method of claim 6 further comprising bypassing processing of the one or more other executable authentication rules if the user does not satisfy the executable authentication rule.

8 . The method of claim 1 , wherein determining if the user satisfies the executable authentication rule comprises determining a satisfaction state of the executable authentication rule.

9 . The method of claim 1 further comprising executing an authentication action if the user does not satisfy the executable authentication rule.

10 . The method of claim 9 , wherein the authentication action is specified by at least one of:

the first executable authentication rule or the first enforcement point.

11 . The method of claim 1 further comprising:

receiving, from the user, a second request for a second service from the one or more services at a second enforcement point;

determining if the user satisfies the first executable authentication rule;

providing access by the user to the second service if the user satisfies the first executable authentication rule; and

executing an authentication action if the user does not satisfy the first executable authentication rule.

12 . The method of claim 11 , wherein the authentication action comprises: a hard token action, a soft token action, a personal identification number (PIN) action, a password (PW) action, a knowledge action, a biometric action, a modify-user information action, or any combination thereof.

13 . The method of claim 11 , wherein executing the authentication action comprises directing the user to the first enforcement point.

14 . The method of claim 11 , wherein executing the authentication action further comprises blocking the user from accessing the second service.

15 . A computer program product, tangibly embodied in an information carrier, the computer program product including instructions being operable to cause a data processing apparatus to:

provide an executable authentication rule for determining access by a user to a service;

receive, from the user, a request for the service at an enforcement point;

determine if the user satisfies the executable authentication rule; and

provide access by the user to the service if the user does not satisfy the executable authentication rule.

16 . A system for providing authentication for service provisioning, the system comprising an authentication system adapted to:

provide an executable authentication rule for determining access by a user to a service;

receive, from the user, a request for the service at an enforcement point;

determine if the user satisfies the executable authentication rule; and

provide access by the user to the service if the user does not satisfy the executable authentication rule.

Assignments (2)
MERGER Recorded Dec 2, 2007
From: FMR CORP.
To: FMR LLC
Reel/Frame 020184/0151 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 25, 2007
From: KULKARNI, RAJANDRA LAXMAN; GREENBERG, ADAM; MAROTTO, ANTHONY M.; LOPIANO, MICHAEL FRANCIS; POPOWYCZ, ALEXANDER L.
To: FMR CORP.
Reel/Frame 019344/0672 →