IP Library Patent Application 11742923
Patent Application
App. No. 11/742,923

GRANULAR CUSTOMIZABLE AUTHENTICATION FOR SERVICE PROVISIONING

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
11/742,923
Abstract

Described are methods, systems, and apparatus, including computer program products for providing customizable authentication for service provisioning. A first user is enabled to customize an authentication system associated with a service. Customizing the authentication system includes defining a first executable authentication rule for a second user and a second executable authentication rule for a third user. The second executable authentication rule is different from the first executable authentication rule. The second user is different from the third user. The first executable authentication rule is employed for determining access by the second user to the service. The second executable authentication rule is employed for determining access by the third user to the service.

Claims (41)

1 . A computerized method for providing customizable authentication for service provisioning, the method comprising:

enabling a first user to customize an authentication system associated with a service, wherein customizing the authentication system comprises defining a first executable authentication rule for a second user and a second executable authentication rule for a third user, the second executable authentication rule being different from the first executable authentication rule, the second user being different from the third user, the first executable authentication rule being employed for determining access by the second user to the service, the second executable authentication rule being employed for determining access by the third user to the service.

2 . The method of claim 1 , wherein the first user comprises a service provider, a client organization of the service provider, or one or more subgroups of the client organization.

3 . The method of claim 1 , wherein the second and third users comprise: one or more client organizations of the service provider, one or more subgroups of the one or more client organizations, one or more individuals, or any combination thereof.

4 . The method of claim 3 , wherein the one or more individuals comprise: one or more employees of the one or more client organizations, one or more customers of the one or more client organizations, one or more customers of the service provider, or any combination thereof.

5 . The method of claim 1 further comprising enabling the second user to customize the authentication system associated with the service.

6 . The method of claim 5 , wherein enabling the second user to customize the authentication system comprises enabling the second user to edit the first executable authentication rule.

7 . The method of claim 5 , wherein enabling the second user to customize the authentication system comprises enabling the second user to define one or more second user executable authentication rules for determining access by the second user to the service, wherein the one or more second user executable authentication rules are different from the first executable authentication rule.

8 . The method of claim 1 , wherein the first and second executable authentication rules comprise: a configurable rule, a non-configurable rule, or any combination thereof.

9 . The method of claim 1 , wherein the first and second executable authentication rules comprise: a mandatory rule, an optional rule, or any combination thereof.

10 . The method of claim 9 further comprising enabling the second user to select enrollment in the first executable authentication rule when the first executable authentication rule is optional.

11 . The method of claim 1 further comprising:

selecting the first executable authentication rule, wherein selecting the first executable authentication rule is based on: a characteristic of the second user, a characteristic of a request, a characteristic of an acquisition point, or any combination thereof; and

generating a rules credential, the rules credential including the first executable authentication rule.

12 . The method of claim 11 , wherein the characteristic of the second user comprises an identification credential of the second user, an identification credential of a group of users including the second user, or any combination thereof.

13 . The method of claim 11 , wherein the characteristic of the request comprises: an access-channel characteristic, an access-point characteristic, a device characteristic, or any combination thereof.

14 . The method of claim 11 , wherein the characteristic of the acquisition point comprises: a time characteristic, a policy characteristic, a service type characteristic, a function type characteristic, or any combination thereof.

15 . The method of claim 14 , wherein the rules credential is generated at an acquisition point.

16 . The method of claim 1 further comprising:

receiving, from the second user, a request for the service at an enforcement point; and

determining, at the enforcement point, if at least the first executable authentication rule applies to the second user, wherein determining if the first executable authentication rule applies comprises determining if one or more triggers specified by the first executable authentication rule are triggered.

17 . The method of claim 16 , wherein the one or more triggers comprise: a user trigger, a request trigger, an enforcement point trigger, a policy trigger, or any combination thereof.

18 . The method of claim 17 , wherein the user trigger comprises an identification credential of the second user, an identification credential of a group of users including the second user, or any combination thereof.

19 . The method of claim 17 , wherein the request trigger comprises: an access-channel trigger, an access-point trigger, a device trigger, or any combination thereof.

20 . The method of claim 17 , wherein the enforcement point trigger comprises: a time trigger, a service type trigger, a function trigger, an expiration-of-time trigger, or any combination thereof.

21 . The method of claim 1 further comprising:

receiving, from the second user, a request for the service at an enforcement point;

determining if the second user satisfies the first executable authentication rule;

providing access by the second user to the service if the second user satisfies the first executable authentication rule; and

executing an authentication action if the second user does not satisfy the first executable authentication rule.

22 . The method of claim 21 , wherein determining if the second user satisfies the first executable authentication rule comprises determining a satisfaction state of the first executable authentication rule.

23 . The method of claim 21 , wherein the authentication action comprises: a hard token action, a soft token action, a personal identification number (PIN) action, a password (PW) action, a knowledge action, a biometric action, a modify-user information action, or any combination thereof.

24 . The method of claim 21 , wherein executing the authentication action comprises directing the second user to a site different from the enforcement point.

25 . The method of claim 21 , wherein the authentication action is specified by at least one of: the first executable authentication rule or the enforcement point.

26 . The method of claim 21 further comprising modifying a satisfaction state of the first executable authentication rule based on a result of the authentication action.

27 . The method of claim 1 , wherein the service comprises: a financial service, an accounting service, a personnel service, an administrative service, a trade service, or any combination thereof.

28 . The method of claim 1 , wherein a type of the service comprises: a retail service type, an employment service type, an insurance services type, or any combination thereof.

29 . A computer program product, tangibly embodied in an information carrier, the computer program product including instructions being operable to cause a data processing apparatus to:

enable a first user to customize an authentication system associated with a service, wherein customizing the authentication system comprises defining a first executable authentication rule for a second user and a second executable authentication rule for a third user, the second executable authentication rule being different from the first executable authentication rule, the second user being different from the third user, the first executable authentication rule being employed for determining access by the second user to the service, the second executable authentication rule being employed for determining access by the third user to the service.

30 . A system for providing customizable authentication for service provisioning, the system comprising an authentication system adapted to:

enable a first user to customize an authentication system associated with a service, wherein customizing the authentication system comprises defining a first executable authentication rule for a second user and a second executable authentication rule for a third user, the second executable authentication rule being different from the first executable authentication rule, the second user being different from the third user, the first executable authentication rule being employed for determining access by the second user to the service, the second executable authentication rule being employed for determining access by the third user to the service.

Assignments (2)
MERGER Recorded Dec 2, 2007
From: FMR CORP.
To: FMR LLC
Reel/Frame 020184/0151 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 25, 2007
From: KULKARNI, RAJANDRA LAXMAN; GREENBERG, ADAM; MAROTTO, ANTHONY M.; LOPIANO, MICHAEL FRANCIS; POPOWYCZ, ALEXANDER L.
To: FMR CORP.
Reel/Frame 019344/0672 →