IP Library Granted Patent US 8,631,486
Granted Patent B1
US 8,631,486 · App. 12/414,845 · Granted Jan 14, 2014

Adaptive identity classification

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,631,486
App. No.
12/414,845
Granted
Jan 14, 2014
Kind
B1
Abstract

A method is used in identity assurance. A process is executed that is used to verify a user identity. A description of the executed process is stored and is used to determine a level of trust.

Claims (58)

1. A method for use in identity assurance, comprising:

receiving at a determinator a user credential of a verification of a user identity; wherein the credential includes a stored description of an executed process of the verification method performed by a verifier to verify the user identity;

using the credential by the determinator to determine a granular identity level of trust and a granular verification level of trust, wherein the granular identity level of trust describes an amount of risk associated with what was provided to verify the user identity by associating a granular identity trust level with the description of what was provided to verify the user identity and wherein the granular verification level of trust describes an amount of risk associated with what method was performed to verify the identity and by associating a verification trust level with the verification method performed to verify the identity,

calculating, at the determinator, a granular level of trust based on the granular identity level and the granular verification level;

determining, at the determinator, a trust threshold necessary for a user to perform an operation; and

determining, at the determinator, whether to allow the user to perform the operation; wherein if the granular level of trust exceeds the trust threshold the operation is allowed; and

storing, in a computer memory, a plurality of user transactions using the user identity associated with the credential; and

based on the plurality of user transactions, enabling the determinator to modify the granular level of trust; wherein modification is based on modifying the granular level of trust of the user identification with levels of trust associated with each of the plurality of user transactions.

2. The method of claim 1 further comprising:

encrypting the user credential.

3. The method of claim 2 , further comprising:

presenting the description and associated user credential to an authenticator; and

using the description and the associated user credential to allow the authenticator to determine whether to allow the user to perform an operation.

4. The method of claim 1 further comprising:

basing the determination of the granular trust threshold on adaptive criteria.

5. The method of claim 4 wherein the adaptive criteria is based on at least one member of the group comprising time, patterns of behavior, type of authentication requested, and location.

6. The method of claim 1 wherein the trust threshold is based on environmental factors.

7. The method of claim 1 wherein the operation is of a plurality of operations and each operation of the plurality of operations has a different trust threshold.

8. A method for use in identity assurance, comprising:

receiving at a determinator a credential of a verification of a user identity; wherein the credential includes a stored description of an executed process of the verification method performed by a verifier to verify the user identity;

using the credential by the determinator to determine a granular identity level of trust and a granular verification level of trust, wherein the granular identity level of trust describes an amount of risk associated with what was provided to verify the user by associating a granular identity trust level with the description of what was provided to verify the user identity and wherein the granular verification level of trust describes an amount of risk associated with what method was performed to verify the identity and by associating a verification trust level with the verification method performed to verify the identity,

calculating, at the determinator, a granular level of trust based on the granular identity level of trust and the granular verification level of trust;

determining, at the determinator, a trust threshold necessary for a user to perform an operation; and

determining, at the determinator, whether to allow the user to perform the operation; wherein if the granular level of trust exceeds the trust threshold the operation is allowed; and

storing, in a computer memory, a plurality of user transactions using the user identity and the credential; and wherein the determining by the determinator is also based on the plurality of user transactions; wherein the determining is further based on modifying the granular level of trust of the user identification with levels of trust associated with each of the plurality of user transactions.

9. The method of claim 8 further comprising encrypting the user credential.

10. The method of claim 8 wherein the operation is of a plurality of operations and each operation of the plurality of operations has a different trust threshold.

11. A system for use in identity assurance, the system comprising:

a computer having a memory;

computer-executable program code operating in memory, wherein the computer-executable program code is configured for execution of the following steps:

executing a provisioning process used to verify a user identity at a verifier;

storing, by the verifier, a description of said executed process in a computer memory in conjunction with a credential; wherein the description includes information about what verification method was performed and what was provided to identify the user identity; and

using the credential by a determinator to determine a granular identity level of trust and a granular verification level of trust, wherein the granular identity level of trust describes an amount of risk associated with what was provided to verify the user by associating a granular identity trust level with the description of what was provided to verify the user identity and wherein the granular verification level of trust describes an amount of risk associated with what method was performed to verify the identity and by associating a verification trust level with the verification method performed to verify the identity,

calculating, at the determinator, a granular level of trust based on the granular identity level of trust and the granular verification level of trust;

determining, at the determinator, a trust threshold necessary for a user to perform an operation; and

determining, at the determinator, whether to allow the user to perform the operation; wherein if the granular level of trust exceeds the trust threshold the operation is allowed; and

storing a plurality of user transactions using the credential;

based on the plurality of user transactions, modifying by the determinator the granular level of trust; wherein modification is based on modifying the granular level of trust of the user identification with levels of trust associated with each of the plurality of user transactions and

creating a user credential associated with the granular level of trust.

12. The system of claim 11 , further comprising:

encrypting the user credential.

13. The system of claim 11 , further comprising:

basing the determination of the granular trust threshold on adaptive criteria.

14. The system of claim 13 wherein the adaptive criteria is based on at least one member of the group comprising time, patterns of behavior, type of authentication requested, and location.

15. The system of claim 11 wherein the operation is of a plurality of operations and each operation of the plurality of operations has a different trust threshold.

16. A system for use in identity assurance, the system comprising:

a computer having a memory;

computer-executable program code operating in memory, wherein the computer-executable program code is configured for execution of the following:

executing a process used by a first party to verify a user identity;

associating, with an output of the executed process by the first party in conjunction with a credential, a description of the executed process stored in a computer memory; wherein the description includes information about what verification method was performed and what was provided to identify the user identity; and

using the credential by a determinator to determine a granular identity level of trust and a granular verification level of trust, wherein the granular identity level of trust describes an amount of risk associated with what was provided to verify the user by associating a granular identity trust level with the description of what was provided to verify the user identity and wherein the granular verification level of trust describes an amount of risk associated with what method was performed to verify the identity and by associating a verification trust level with the verification method performed to verify the identity,

calculating, at the determinator, a granular level of trust based on the granular identity level of trust and the granular verification level of trust;

determining, at the determinator, a trust threshold necessary for a user to perform an operation; and

determining, at the determinator, whether to allow the user to perform the operation; wherein if the granular level of trust exceeds the trust threshold the operation is allowed; and

storing a plurality of user transactions associated with the credential; and wherein the determining by the determinator is further based on the plurality of user transactions; wherein the determining is further based on modifying the granular level of trust of the user identification with levels of trust associated with each of the plurality of user transactions.

17. The system of claim 16 , wherein the trust threshold is based on an adaptive criteria.

18. The system of claim 17 wherein the adaptive criteria is based on at least one member of the group comprising time, patterns of behavior, type of authentication requested, and location.

19. The system of claim 16 wherein the operation is of a plurality of operations and each operation of the plurality of operations has a different trust threshold.

Assignments (14)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040203/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 23, 2010
From: RSA SECURITY HOLDING, INC.
To: EMC CORPORATION
Reel/Frame 023975/0151 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 23, 2010
From: RSA SECURITY LLC
To: RSA SECURITY HOLDING, INC.
Reel/Frame 023975/0453 →
MERGER Recorded Jan 27, 2010
From: RSA SECURITY INC
To: RSA SECURITY LLC
Reel/Frame 023852/0644 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 21, 2010
From: RSA SECURITY LLC
To: RSA SECURITY HOLDING, INC.
Reel/Frame 023824/0729 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 21, 2010
From: RSA SECURITY HOLDING, INC.
To: EMC CORPORATION
Reel/Frame 023825/0109 →