IP Library Granted Patent US 8,479,272
Granted Patent B2
US 8,479,272 · App. 11/961,783 · Granted Jul 2, 2013

Identity assertion

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,479,272
App. No.
11/961,783
Granted
Jul 2, 2013
Kind
B2
Abstract

The present invention relates to using authorization information provided by an asserting agent to control identity-related interactions between a receiving agent and an identity agent, which acts on behalf of the asserting agent. The authorization information may be provided to the identity agent directly or through the receiving agent. When the asserting agent is asserting the identity of an associated entity to the receiving agent, the asserting agent delivers assertion information, which may but need not include the authorization information, to the receiving agent. The assertion information includes claim information that includes actual claims or identifies available claims. Upon receiving the assertion information, the receiving agent may interact with the identity agent. The identity agent will use the authorization information to control claim-related interactions with the receiving agent.

Claims (62)

1. A method for operating a computer implemented identity agent comprising:

receiving, at the identity agent, identity information comprising one or more claims corresponding to a credential, wherein the identity information is received from a user;

receiving, at the identity agent through a computer controlled communication medium, authorization information originated from an asserting agent associated with the user,

wherein the authorization information is received in association with the asserting agent asserting an identity to a receiving agent, and

wherein the authorization information is configured to control an identity-related interaction between the identity agent and the receiving agent;

receiving, at the identity agent from the receiving agent, a request for information related to at least one claim among the one or more claims, the information related to the at least one claim among the one or more claims comprising at least one from the group consisting of: the at least one claim among the one or more claims and a verification of the at least one claim among the one or more claims;

determining, by the identity agent based on the authorization information, whether to transmit the information related to the at least one claim among the one or more claims to the receiving agent in response to the request.

2. The method of claim 1 wherein the authorization information is configured to authorize a single identity-related interaction between the identity agent and the receiving agent.

3. The method of claim 1 wherein the authorization information is configured to authorize at least one identity-related interaction between the identity agent and the receiving agent for a limited duration.

4. The method of claim 1 wherein the authorization information is configured to authorize identity-related interactions between the identity agent and only the receiving agent.

5. The method of claim 1 wherein the authorization information is configured to authorize at least one identity-related interaction for a defined purpose between the identity agent and the receiving agent.

6. The method of claim 1 wherein the asserting agent is asserting the identity to the receiving agent in association with a session established or to be established between the asserting agent and the receiving agent, the authorization information configured to authorize at least one identity-related interaction between the identity agent and the receiving agent if the session is of a certain type.

7. The method of claim 1 wherein the authorization information is configured to authorize at least one identity-related interaction for a defined purpose and for a limited duration.

8. The method of claim 1 wherein the authorization information is configured to authorize only a single identity-related interaction for a defined purpose and for a limited duration.

9. The method of claim 1 wherein obtaining the authorization information comprises receiving the authorization information from the asserting agent.

10. The method of claim 1 wherein the authorization information is provided to the receiving agent from the asserting agent, and obtaining the authorization information comprises receiving the authorization information from the receiving agent.

11. The method of claim 1 wherein receiving the request for information related to the at least one claim among the one or more claims comprises receiving a request to transmit at least one claim that is associated with the user among the one or more claims to the receiving agent, and

wherein determining, based on the authorization information, whether to transmit information related to the at least one claim among the one or more claims to the receiving agent comprises determining to transmit the at least one claim among the one or more claims to the receiving agent if the authorization information allows the at least one claim to be provided to the receiving agent.

12. The method of claim 1 wherein receiving the request for information related to the at least one claim among the one or more claims comprises receiving a request to verify at least one claim that is associated with the user among the one or more claims to the receiving agent, and

wherein determining, based on the authorization information, whether to transmit information related to the at least one claim among the one or more claims to the receiving agent comprises determining to verify the at least one claim among the one or more claims to the receiving agent if the authorization information allows the at least one claim to be verified to the receiving agent.

13. The method of claim 1 further comprising:

identifying only select ones of the one or more claims to use for responding to the request based on the authorization information; and

providing the select ones of the one or more claims to the receiving agent.

14. The method of claim 1 further comprising:

generating claim-related information based on at least one of the one or more claims based on the authorization information; and

providing the claim-related information to the receiving agent.

15. The method of claim 1 wherein the asserting agent is provided by a first user terminal.

16. The method of claim 1 wherein the receiving agent is provided by a first user terminal.

17. The method of claim 1 wherein an entity is associated with a plurality of identity-related claims, and a first group of the plurality of identity-related claims are stored on the asserting agent and a second group of the plurality of identity-related claims are stored on the identity agent and not the asserting agent, wherein the identity-related interaction involves the second group of the plurality of identity-related claims.

18. The method of claim 17 wherein the first group of the plurality of identity-related claims are provided to the receiving agent by the asserting agent.

19. The method of claim 1 wherein the authorization information is configured to control an identity-related interaction between the identity agent and the receiving agent by authorizing on behalf of the user whether the information related to the at least one claim among the one or more claims may be transmitted from the identity agent to the receiving agent.

20. The method of claim 1 further comprising transmitting the information related to the at least one claim among the one or more claims from the identity agent to the receiving agent if the authorization information allows the information related to the at least one claim among the one or more claims to be provided to the receiving agent.

21. The method of claim 1 wherein the authorization information is distinct from the one or more claims.

22. The method of claim 1 wherein the authorization information initially originated from the asserting agent associated with the user.

23. An identity agent comprising:

a communication interface; and

a control system associated with the communication interface and adapted to:

receive identity information comprising one or more claims corresponding to a credential, wherein the identity information is received from a user;

receive authorization information originated from an asserting agent associated with the user,

wherein the authorization information is received in association with the asserting agent asserting an identity to a receiving agent, and

wherein the authorization information is configured to control an identity-related interaction between the identity agent and the receiving agent;

receive, from the receiving agent, a request for information related to at least one claim among the one or more claims, the information related to the at least one claim among the one or more claims comprising at least one from the group consisting of: the at least one claim among the one or more claims and a verification of the at least one claim among the one or more claims; and

determine, based on the authorization information, whether to transmit the information related to the at least one claim among the one or more claims to the receiving agent in response to the request.

24. A computer implemented method comprising:

receiving, at a computer implemented identity agent, identity information comprising one or more claims corresponding to a credential, wherein the identity information is received from a user;

receiving, at the computer implemented identity agent, over a communication network, authorization information originated from an asserting agent associated with the user,

wherein the authorization information is received in association with the asserting agent asserting an identity to the receiving agent, and

wherein the authorization information is configured to control an identity-related interaction between the computer implemented identity agent and a receiving agent;

receiving, at the computer implemented identity agent from the receiving agent, a request for information related to at least one claim among the one or more claims, the information related to the at least one claim among the one or more claims comprising at least one from the group consisting of: the at least one claim among the one or more claims and a verification of the at least one claim among the one or more claims;

determining, by the computer implemented identity agent based on the authorization information, whether to transmit the information related to the at least one claim among the one or more claims to the receiving agent in response to the request.

25. The method of claim 24 wherein receiving the request for information related to the at least one claim among the one or more claims comprises receiving a request to transmit at least one claim that is associated with the user among the one or more claims to the receiving agent, and

wherein determining, based on the authorization information, whether to transmit information related to the at least one claim among the one or more claims to the receiving agent comprises determining to transmit the at least one claim among the one or more claims to the receiving agent if the authorization information allows the at least one claim to be provided to the receiving agent.

26. The method of claim 24 wherein receiving the request for information related to the at least one claim among the one or more claims comprises receiving a request to verify at least one claim that is associated with the user among the one or more claims to the receiving agent, and

wherein determining, based on the authorization information, whether to transmit information related to the at least one claim among the one or more claims to the receiving agent comprises determining to verify the at least one claim among the one or more claims to the receiving agent if the authorization information allows the at least one claim to be verified to the receiving agent.

27. The method of claim 24 wherein receiving the authorization information originated from the asserting agent comprises receiving the authorization information from the asserting agent.

28. The method of claim 24 wherein the authorization information is provided to the receiving agent from the asserting agent, and receiving the authorization information originated from the asserting agent comprises receiving the authorization information from the receiving agent.

29. A method comprising:

at a computer implemented identity agent, receiving, from a user, identity information comprising one or more claims capable of being verified from a credential;

storing the identity information for subsequent use;

receiving authorization information distinct from the one or more claims that controls when and how the computer implemented identity agent may interact with a receiving agent, wherein the authorization information originated from an asserting agent associated with the user and wherein the authorization information was generated in conjunction with the asserting agent asserting an identity to the receiving agent;

at the computer implemented identity agent, receiving a request from the receiving agent, wherein the request comprises a request selected from the group consisting of: a request for at least one claim and a request for verification of at least one claim; and

determining, by the computer implemented identity agent, based on the authorization information, whether to respond to the request by transmitting one of a response to the request for at least one claim or a response to the request for verification of at least one claim to the receiving agent.

Assignments (22)
(SECURITY INTEREST) GRANTOR'S NAME CHANGE Recorded Sep 21, 2023
From: AVAYA INC.
To: AVAYA LLC
Reel/Frame 065019/0231 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 53955/0436) Recorded May 18, 2023
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063705/0023 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 045034/0001) Recorded May 18, 2023
From: GOLDMAN SACHS BANK USA., AS COLLATERAL AGENT
To: ZANG, INC. (FORMER NAME OF AVAYA CLOUD INC.); AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; HYPERQUALITY, INC.; HYPERQUALITY II, LLC; CAAS TECHNOLOGIES, LLC; AVAYA MANAGEMENT L.P.
Reel/Frame 063779/0622 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 61087/0386) Recorded May 18, 2023
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063690/0359 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 4, 2023
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 063542/0662 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 3, 2023
From: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; KNOAHSOFT INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB [COLLATERAL AGENT]
Reel/Frame 063742/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS AT REEL 45124/FRAME 0026 Recorded Apr 26, 2023
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: AVAYA HOLDINGS CORP.; AVAYA INC.; AVAYA MANAGEMENT L.P.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063457/0001 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 5, 2022
From: AVAYA INC.; INTELLISIST, INC.; AVAYA MANAGEMENT L.P.; AVAYA CABINET SOLUTIONS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 061087/0386 →
SECURITY INTEREST Recorded Sep 25, 2020
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 053955/0436 →
SECURITY INTEREST Recorded Jan 23, 2018
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 045124/0026 →
RELEASE OF SECURITY INTEREST Recorded Jan 11, 2018
From: CITICORP USA, INC.
To: AVAYA, INC.; SIERRA HOLDINGS CORP.
Reel/Frame 045045/0564 →
SECURITY INTEREST Recorded Jan 10, 2018
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 045034/0001 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 041576/0001 Recorded Dec 15, 2017
From: CITIBANK, N.A.
To: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS LLC (FORMERLY KNOWN AS OCTEL COMMUNICATIONS CORPORATION); VPNET TECHNOLOGIES, INC.
Reel/Frame 044893/0531 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 029608/0256 Recorded Dec 15, 2017
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVAYA INC.
Reel/Frame 044891/0801 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 025863/0535 Recorded Dec 15, 2017
From: THE BANK OF NEW YORK MELLON TRUST, NA
To: AVAYA INC.
Reel/Frame 044892/0001 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 030083/0639 Recorded Dec 15, 2017
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVAYA INC.
Reel/Frame 045012/0666 →
SECURITY INTEREST Recorded Jan 27, 2017
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS CORPORATION; VPNET TECHNOLOGIES, INC.
To: CITIBANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 041576/0001 →
SECURITY AGREEMENT Recorded Mar 13, 2013
From: AVAYA, INC.
To: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., THE
Reel/Frame 030083/0639 →
SECURITY AGREEMENT Recorded Jan 10, 2013
From: AVAYA, INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 029608/0256 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 26, 2010
From: NORTEL NETWORKS LIMITED
To: AVAYA INC.
Reel/Frame 023998/0878 →
SECURITY AGREEMENT Recorded Feb 5, 2010
From: AVAYA INC.
To: CITICORP USA, INC., AS ADMINISTRATIVE AGENT
Reel/Frame 023905/0001 →
SECURITY AGREEMENT Recorded Feb 4, 2010
From: AVAYA INC.
To: CITIBANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 023892/0500 →