IP Library Granted Patent US 9,195,834
Granted Patent B1
US 9,195,834 · App. 13/370,078 · Granted Nov 24, 2015

Cloud authentication

Inventor: Bjorn Markus Jakobsson (Mountain View, CA)
Assignee: RavenWhite Inc.
G06F21/60
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,195,834
App. No.
13/370,078
Granted
Nov 24, 2015
Kind
B1
Abstract

An authentication system is disclosed. A first user's response(s) to an authentication challenge for the first user is received. The first user is associated with a first service provider. A score is determined based on the user response(s). The first service provider is sent an assessment based on the determined score.

Claims (40)

1. An authentication system, comprising:

a processor configured to:

receive a first user's response(s) to a first authentication challenge for the first user, wherein the first user is associated with a first service provider, wherein the authentication system is configured to provide authentication services on behalf of the first service provider, and wherein the first authentication challenge is generated based at least in part on previously captured enrollment information provided by the first user during an enrollment phase;

receive a second user's response(s) to a second authentication challenge for the second user, wherein the second user is associated with a second service provider that is different from the first service provider, and wherein the authentication system is configured to provide authentication services on behalf of the second service provider in addition to the first service provider;

determine, on behalf of the first service provider, a first score based at least in part on the first user's response(s), and send to the first service provider a first assessment based at least in part on the determined first score, wherein the first assessment is configured according to a first set of configuration rules corresponding to the first service provider; and

determine, on behalf of the second service provider, a second score based at least in part on the second user's response(s), and send to the second service provider a second assessment based at least in part on the determined second score, wherein the second assessment is configured according to a second set of configuration rules corresponding to the second service provider; and

a memory coupled to the processor and configured to the processor to provide the processor with instructions.

2. The system of claim 1 wherein the processor is configured to determine the first score based at least in part on a comparison of the first score to a threshold specified by the first service provider.

3. The system of claim 1 wherein the processor is further configured to receive a user identity associated with the first service provider.

4. The system of claim 1 wherein the processor is further configured to receive a pseudonym associated with a user identity associated with the first service provider.

5. The system of claim 1 wherein the first authentication challenge is generated based at least in part on a profile of the first user.

6. The system of claim 1 wherein the first authentication challenge is generated based at least in part on a stimulus for which the first user has provided a classification and based at least in part on a stimulus for which the first user has not provided a classification.

7. The system of claim 1 wherein the first user's response is received via an iframe element included in a webpage hosted by the first service provider.

8. The system of claim 1 wherein the first assessment comprises the first score.

9. The system of claim 1 wherein the processor is further configured to receive a key from the first service provider and wherein the processor is further configured to decrypt at least a portion of a profile associated with the first user.

10. The system of claim 1 wherein the processor is further configured to store a score history in a profile of the first user.

11. The system of claim 1 wherein the processor is further configured to store a device identifier associated with the first user in a profile.

12. A method, comprising:

receiving a first user's response(s) to a first authentication challenge for the first user, wherein the first user is associated with a first service provider, wherein the authentication system is configured to provide authentication services on behalf of the first service provider, and wherein the first authentication challenge is generated based at least in part on previously captured enrollment information provided by the first user during an enrollment phase;

receiving a second user's response(s) to a second authentication challenge for the second user, wherein the second user is associated with a second service provider that is different from the first service provider, and wherein the authentication system is configured to provide authentication services on behalf of the second service provider in addition to the first service provider;

determining, using a processor and on behalf of the first service provider, a first score based at least in part on the first user's response(s), and sending to the first service provider a first assessment based at least in part on the determined first score, wherein the first assessment is configured according to a first set of configuration rules corresponding to the first service provider; and

determining, on behalf of the second service provider, a second score based at least in part on the second user's response(s), and sending to the second service provider a second assessment based at least in part on the determined second score, wherein the second assessment is configured according to a second set of configuration rules corresponding to the second service provider.

13. The system of claim 1 , wherein the first user is associated with a third service provider, and wherein the processor is further configured to receive the first user's response(s) to a third authentication challenge that is different from the first authentication challenge.

14. The system of claim 1 , wherein the first authentication challenge and the second authentication challenge are different.

15. The system of claim 1 , wherein the first authentication challenge is provided as part of a secondary form of authentication on behalf of the first service provider.

16. The system of claim 1 , wherein the first score is a binary value.

17. The method of claim 12 wherein the first score is determined based at least in part on a comparison of the first score to a threshold specified by the first service provider.

18. The method of claim 12 further comprising receiving a user identity associated with the first service provider.

19. The method of claim 12 further comprising receiving a pseudonym associated with a user identity associated with the first service provider.

20. The method of claim 12 wherein the first authentication challenge is generated based at least in part on a profile of the first user.

21. The method of claim 12 wherein the first authentication challenge is generated based at least in part on a stimulus for which the first user has provided a classification and based at least in part on a stimulus for which the first user has not provided a classification.

22. The method of claim 12 wherein the first user's response is received via an iframe element included in a webpage hosted by the first service provider.

23. The method of method 12 wherein the first assessment comprises the first score.

24. The method of claim 12 further comprising receiving a key from the first service provider and decrypting at least a portion of a profile associated with the first user.

25. The method of claim 12 further comprising storing a score history in a profile of the first user.

26. The method of claim 12 further comprising storing a device identifier associated with the first user in a profile.

27. The method of claim 12 further comprising receiving the first user's response(s) to a third authentication challenge that is different from the first authentication challenge, wherein the first user is associated with a third service provider.

28. The method of claim 12 , wherein the first authentication challenge and the second authentication challenge are different.

29. The method of claim 12 , wherein the first authentication challenge is provided as part of a secondary form of authentication on behalf of the first service provider.

30. The method of claim 12 , wherein the first score is a binary value.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 21, 2026
From: JAKOBSSON, BJORN MARKUS
To: RAVENWHITE SECURITY, INC.
Reel/Frame 075334/0716 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 21, 2026
From: RAVENWHITE SECURITY, INC.
To: NUECES BLOCKCHAIN LLC
Reel/Frame 075334/0752 →
CHANGE OF NAME Recorded May 24, 2019
From: RAVENWHITE INC.
To: RAVENWHITE SECURITY, INC.
Reel/Frame 049287/0025 →
CHANGE OF NAME Recorded May 3, 2019
From: RAVENWHITE INC.
To: RAVENWHITE SECURITY, INC.
Reel/Frame 050260/0821 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 19, 2012
From: JAKOBSSON, BJORN MARKUS
To: RAVENWHITE INC.
Reel/Frame 027889/0169 →
Continuity (9)
Continuation In Part 12215048 · Jun 23, 2008
Continuation In Part 13161184 · Jun 15, 2011
Continuation In Part 11890408 · Aug 6, 2007
Provisional Application 61441562 · Feb 10, 2011
Provisional Application 60836641 · Aug 9, 2006
Provisional Application 60967675 · Sep 6, 2007
Provisional Application 60836641 · Aug 9, 2006
Provisional Application 60918781 · Mar 19, 2007
Provisional Application 61355149 · Jun 16, 2010