IP Library Granted Patent US 8,413,221
Granted Patent B2
US 8,413,221 · App. 11/930,738 · Granted Apr 2, 2013

Methods and apparatus for delegated authentication

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,413,221
App. No.
11/930,738
Granted
Apr 2, 2013
Kind
B2
Abstract

An authentication-delegating service implemented in an authentication server or other processing device is configured to receive a request from a relying party for delegated authentication information associated with a particular user, to determine a level of trust associated with the relying party, and to provide the delegated authentication information to the relying party if the relying party has a sufficient level of trust, so as to permit the relying party to authenticate the user based on the delegated authentication information. The delegated authentication information has the property that the user can be presently authenticated based on such information. The delegated authentication information may comprise, for example, at least one value derived from a one-time password or other authentication credential of the particular user. The authentication-delegating service may be graded to provide different types of delegated authentication information based on respective levels of trust that may be associated with relying parties.

Claims (51)

1. A user authentication method comprising the steps of:

receiving a request from a relying party for delegated authentication information associated with a particular user, the delegated authentication information having the property that the user can be presently authenticated based on such information;

determining a level of trust associated with the relying party; and

providing the delegated authentication information to the relying party responsive to the request only if the relying party has a sufficient level of trust, so as to permit the relying party to authenticate the user based on the delegated authentication information;

wherein each of the steps is performed at least in part by one or more processing devices; and

wherein the step of determining a level of trust associated with the relying party further comprises determining which of a plurality of trust levels is associated with the relying party, the plurality of trust levels corresponding to respective ones of a plurality of different types of delegated authentication information, and the step of providing the delegated authentication information to the relying party further comprises providing delegated authentication information of a particular one of the plurality of different types to the relying party based on the particular one of the plurality of trust levels determined to be associated with the relying party.

2. The method of claim 1 wherein the delegated authentication information comprises at least one value derived from an authentication credential of the particular user.

3. The method of claim 2 wherein the at least one value comprises a protected one-time password derived from a one-time password of the particular user.

4. The method of claim 2 wherein the at least one value comprises a doubly protected one-time password derived from a protected one-time password of the particular user.

5. The method of claim 2 wherein the authentication credential comprises at least a portion of at least one password.

6. The method of claim 5 wherein the password comprises a one-time password.

7. A user authentication method comprising the steps of:

receiving a request from a relying party for delegated authentication information associated with a particular user, the delegated authentication information having the property that the user can be presently authenticated based on such information;

determining a level of trust associated with the relying party; and

providing the delegated authentication information to the relying party responsive to the request only if the relying party has a sufficient level of trust, so as to permit the relying party to authenticate the user based on the delegated authentication information;

wherein each of the steps is performed at least in part by one or more processing devices; and

wherein the relying party is not in possession of an authentication credential of the user but is in possession of information derived from the authentication credential of the user.

8. The method of claim 7 wherein the delegated authentication information permits the relying party to authenticate the information derived from the authentication credential of the user.

9. The method of claim 8 wherein the information derived from the authentication credential of the user comprises a message authentication code generated based on at least the authentication credential.

10. The method of claim 8 wherein the information derived from the authentication credential of the user comprises an encryption performed utilizing at least a function of the authentication credential.

11. The method of claim 1 wherein the delegated authentication information comprises one or more seeds utilized to generate an authentication credential of the user.

12. The method of claim 1 further comprising the step of receiving feedback information from the relying party indicative of status of the authentication of the user.

13. A non-transitory machine-readable storage medium having encoded therein executable instructions, wherein the executable instructions when executed by the one or more processing devices implement the steps of the user authentication method of claim 1 .

14. The method of claim 1 wherein the level of trust associated with the relying party is determined at least in part by a time-related parameter of the request for delegated authentication information received from the relying party.

15. The method of claim 1 wherein the level of trust associated with the relying party is determined at least in part by an identity of the particular user.

16. A user authentication method comprising the steps of:

receiving a request from a relying party for delegated authentication information associated with a particular user, the delegated authentication information having the property that the user can be presently authenticated based on such information;

determining a level of trust associated with the relying party;

providing the delegated authentication information to the relying party responsive to the request only if the relying party has a sufficient level of trust, so as to permit the relying party to authenticate the user based on the delegated authentication information;

receiving feedback information from the relying party indicative of status of the authentication of the user; and

updating high watermark information based on the feedback information;

wherein each of the steps is performed at least in part by one or more processing devices.

17. An apparatus comprising:

at least one processing device comprising a processor coupled to a memory, said processing device implementing an authentication-delegating service which is configured to receive a request from a relying party for delegated authentication information associated with a particular user, the delegated authentication information having the property that the user can be presently authenticated based on such information; to determine a level of trust associated with the relying party; and to provide the delegated authentication information to the relying party responsive to the request only if the relying party has a sufficient level of trust, so as to permit the relying party to authenticate the user based on the delegated authentication information;

wherein the authentication-delegating service comprises a graded authentication-delegating service configured to determine which of a plurality of trust levels is associated with the relying party, the plurality of trust levels corresponding to respective ones of a plurality of different types of delegated authentication information, and to provide delegated authentication information of a particular one of the plurality of different types to the relying party based on the particular one of the plurality of trust levels determined to be associated with the relying party.

18. The apparatus of claim 17 wherein said processing device comprises an authentication server.

19. A method comprising the steps of:

sending a request from a relying party to an authentication-delegating service for delegated authentication information associated with a particular user;

receiving the delegated authentication information from the authentication-delegating service responsive to the request only if the relying party is determined by that service to have a sufficient level of trust associated therewith; and

utilizing the delegated authentication information to establish a key to be shared between the relying party and the user;

wherein the steps are performed at least in part by one or more processing devices; and

wherein the authentication-delegating service determines which of a plurality of trust levels is associated with the relying party, the plurality of trust levels corresponding to respective ones of a plurality of different types of delegated authentication information, and the step of receiving the delegated authentication information from the authentication-delegating service further comprises receiving delegated authentication information of a particular one of the plurality of different types from the authentication-delegating service based on the particular one of the plurality of trust levels determined to be associated with the relying party.

20. The method of claim 19 wherein the user is implicitly authenticated by the relying party based on subsequent correct use of the shared key by the user.

21. A system for authenticating a user, comprising:

a plurality of processing devices;

a first one of the processing devices implementing a relying party and configured for communication with a second one of the processing devices implementing an authentication-delegating service;

wherein the authentication-delegating service is configured to receive a request from a relying party for delegated authentication information associated with a particular user, the delegated authentication information having the property that the user can be presently authenticated based on such information; to determine a level of trust associated with the relying party; and to provide the delegated authentication information to the relying party responsive to the request only if the relying party has a sufficient level of trust, so as to permit the relying party to authenticate the user based on the delegated authentication information; and

wherein the authentication-delegating service comprises a graded authentication-delegating service configured to determine which of a plurality of trust levels is associated with the relying party, the plurality of trust levels corresponding to respective ones of a plurality of different types of delegated authentication information, and to provide delegated authentication information of a particular one of the plurality of different types to the relying party based on the particular one of the plurality of trust levels determined to be associated with the relying party.

22. An apparatus comprising:

at least one processing device comprising a processor coupled to a memory, said processing device implementing a relying party configured to send a request to an authentication-delegating service for delegated authentication information associated with a particular user, the delegated authentication information having the property that the user can be presently authenticated based on such information; to receive the delegated authentication information from the authentication-delegating service responsive to the request only if the relying party is determined by that service to have a sufficient level of trust associated therewith; and to authenticate the user based on the delegated authentication information;

wherein the authentication-delegating service determines which of a plurality of trust levels is associated with the relying party, the plurality of trust levels corresponding to respective ones of a plurality of different types of delegated authentication information, and the received delegated authentication information from the authentication-delegating service further comprises delegated authentication information of a particular one of the plurality of different types based on the particular one of the plurality of trust levels determined to be associated with the relying party.

Assignments (24)
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56096/0525 Recorded Mar 5, 2026
From: JPMORGAN CHASE BANK, N.A.
To: RSA SECURITY LLC; RSA SECURITY USA LLC
Reel/Frame 075030/0744 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56098/0534 Recorded Mar 5, 2026
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: RSA SECURITY LLC
Reel/Frame 075041/0175 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 053666, FRAME 0767 Recorded Apr 29, 2021
From: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056095/0574 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 056098/0534 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 056096/0525 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 054155, FRAME 0815 Recorded Apr 29, 2021
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056104/0841 →
PARTIAL RELEASE OF SECURITY INTEREST Recorded Nov 24, 2020
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXRESS, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054511/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 7, 2020
From: EMC IP HOLDING COMPANY LLC
To: RSA SECURITY LLC
Reel/Frame 053717/0020 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: ASAP SOFTWARE EXPRESS; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054163/0416 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054191/0287 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (049452/0223) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054250/0372 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 054155/0815 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: JEFFERIES FINANCE LLC
Reel/Frame 053666/0767 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040203/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 23, 2010
From: RSA SECURITY HOLDING, INC.
To: EMC CORPORATION
Reel/Frame 023975/0151 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 23, 2010
From: RSA SECURITY LLC
To: RSA SECURITY HOLDING, INC.
Reel/Frame 023975/0453 →
MERGER Recorded Jan 27, 2010
From: RSA SECURITY INC
To: RSA SECURITY LLC
Reel/Frame 023852/0644 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 21, 2010
From: RSA SECURITY LLC
To: RSA SECURITY HOLDING, INC.
Reel/Frame 023824/0729 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 21, 2010
From: RSA SECURITY HOLDING, INC.
To: EMC CORPORATION
Reel/Frame 023825/0109 →