IP Library Granted Patent US 8,756,664
Granted Patent B2
US 8,756,664 · App. 12/238,676 · Granted Jun 17, 2014

Management of user authentication

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,756,664
App. No.
12/238,676
Granted
Jun 17, 2014
Kind
B2
Abstract

A method and system for managing user authentication. First authentication data associated with a user is received from a first authentication mechanism. The first authentication data is generated in response to the first authentication mechanism successfully authenticating the user. In response to receipt of the first authentication data, a first identifier associated with the user is registered. The first authentication data is associated with the first identifier. In response to associating the first authentication data with the first identifier, second authentication data associated with the user is received from a second authentication mechanism. The second authentication data is generated in response to the second authentication mechanism successfully authenticating the user. The second authentication data is associated with the first authentication data and the first identifier.

Claims (39)

1. A method for managing user authentication, said method comprising:

in a first session, receiving, by a processor at a user website from a first authentication mechanism at a first web site, first authentication data comprising both a first username entered by a user and a first authentication key specific to the first website, said first authentication key configured to be used to display data associated with the first website, wherein the first authentication data is received from the first website in response to the first authentication mechanism having successfully authenticated the user using the first username;

after said receiving the first authentication data, said processor generating an account associated with the user website, said account uniquely identifying the user;

in response to said generating the account, said processor storing in the user website first data comprising the first username, the first authentication key, and data associated with the first website;

after said storing the first data, said processor ending the first session;

after said ending the first session, in a second session, said processor receiving from a second authentication mechanism at a second website distinct from the first website, second authentication data comprising both a second username entered by the user and a second authentication key specific to the second website and configured to be used to display data associated with the second website, wherein the second authentication data is received from the second website in response to the second authentication mechanism having successfully authenticated the user using the second username;

after said receiving the second authentication data, said processor storing in the user website second data comprising the second username, the second authentication key, and data associated with the second website against both the account and the first data;

said processor generating an association of the first and second authentication data with the generated account;

said processor storing the association in the user website;

said processor using the first authentication key to display, at the user website, said data associated with the first website;

said processor using the second authentication key to display, at the user website, said data associated with the second website; and

said processor ending the second session.

2. The method of claim 1 , wherein said generating the account is performed without credentials being input by the user.

3. A computer system comprising a processor and a computer readable hardware storage device, said computer readable hardware storage device containing program code configured to be executed by the processor to implement a method for managing user authentication, said processor being at a user website of the computer system, said method comprising:

in a first session, receiving, by said processor from a first authentication mechanism at a first website, first authentication data comprising both a first username entered by a user and a first authentication key specific to the first website, said first authentication key configured to be used to display data associated with the first website, wherein the first authentication data is received from the first website in response to the first authentication mechanism having successfully authenticated the user using the first username;

after said receiving the first authentication data, said processor generating an account associated with the user website, said account uniquely identifying the user;

in response to said generating the account, said processor storing in the user website first data comprising the first username, the first authentication key, and data associated with the first website;

after said storing the first data, said processor ending the first session;

after said ending the first session, in a second session, said processor receiving from a second authentication mechanism at a second website distinct from the first website, second authentication data comprising both a second username entered by the user and a second authentication key specific to the second website and configured to be used to display data associated with the second website, wherein the second authentication data is received from the second website in response to the second authentication mechanism having successfully authenticated the user using the second username;

after said receiving the second authentication data, said processor storing in the user website second data comprising the second username, the second authentication key, and data associated with the second website against both the account and the first data;

said processor generating an association of the first and second authentication data with the generated account;

said processor storing the association in the user website;

said processor using the first authentication key to display, at the user website, said data associated with the first website;

said processor using the second authentication key to display, at the user website, said data associated with the second website; and

said processor ending the second session.

4. The computer system of claim 3 , wherein said generating the account is performed without credentials being input by the user.

5. A computer program product, comprising a computer readable hardware storage device having a computer readable program code therein, said computer readable program code configured to be executed by a processor at a user website to implement a method for managing user authentication, said method comprising:

in a first session, receiving, by said processor from a first authentication mechanism at a first website, first authentication data comprising both a first username entered by a user and a first authentication key specific to the first website, said first authentication key configured to be used to display data associated with the first website, wherein the first authentication data is received from the first website in response to the first authentication mechanism having successfully authenticated the user using the first username;

after said receiving the first authentication data, said processor generating an account associated with the user website, said account uniquely identifying the user;

in response to said generating the account, said processor storing in the user website first data comprising the first username, the first authentication key, and data associated with the first website;

after said storing the first data, said processor ending the first session;

after said ending the first session, in a second session, said processor receiving from a second authentication mechanism at a second website distinct from the first website, second authentication data comprising both a second username entered by the user and a second authentication key specific to the second website and configured to be used to display data associated with the second website, wherein the second authentication data is received from the second website in response to the second authentication mechanism having successfully authenticated the user using the second username;

after said receiving the second authentication data, said processor storing in the user website second data comprising the second username, the second authentication key, and data associated with the second website against both the account and the first data;

said processor generating an association of the first and second authentication data with the generated account;

said processor storing the association in the user website;

said processor using the first authentication key to display, at the user website, said data associated with the first website;

said processor using the second authentication key to display, at the user website, said data associated with the second website; and

said processor ending the second session.

6. The computer program product of claim 5 , wherein said generating the account is performed without credentials being input by the user.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 13, 2021
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: KYNDRYL, INC.
Reel/Frame 057885/0644 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 3, 2008
From: JONES, GARETH EDWARD
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 021775/0180 →