IP Library Granted Patent US 8,612,747
Granted Patent B2
US 8,612,747 · App. 13/467,901 · Granted Dec 17, 2013

System and method for establishing historical usage-based hardware trust

Inventor: James A. Roskind (Redwood City, CA)
Assignee: Microsoft Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,612,747
App. No.
13/467,901
Granted
Dec 17, 2013
Kind
B2
Abstract

Establishing trust according to historical usage of selected hardware involves providing a usage history for a selected client device; and extending trust to a selected user based on the user's usage history of the client device. The usage history is embodied as signed statements issued by a third party or an authentication server. The issued statement is stored either on the client device, or on an authentication server. The usage history is updated every time a user is authenticated from the selected client device. By combining the usage history with conventional user authentication, an enhanced trust level is readily established. The enhanced, hardware-based trust provided by logging on from a trusted client may eliminate the necessity of requiring secondary authentication for e-commerce and financial services transactions, and may also be used to facilitate password recovery and conflict resolution in the case of stolen passwords.

Claims (45)

1. A method for establishing trust in relation to a service provider across a network, comprising:

writing a token into any of a memory or a disk that is associated with a selected client device of one or more client devices;

confirming that the token exists on the selected client device during each log in of the selected client device through one or more access points across the network; and

extending an increase in trust to the selected client device at a level that is at least partially based on any of frequency of the confirmed log ins or number of the confirmed log ins.

2. The method of claim 1 , wherein the token comprises any of a cookie and a tag.

3. The method of claim 1 , further comprising:

performing an authentication of a selected user of the selected client device, wherein the authentication is based on a combination of the extended trust and at least one other form of authentication.

4. The method of claim 1 , wherein the token comprises a statement that is created by an issuer, wherein the statement corresponds with one or more of the log ins for a selected user of the selected client device.

5. The method of claim 4 , further comprising:

providing the statement by the selected client device with a request for any of service and access.

6. The method of claim 1 , wherein extending an increase in trust further comprises:

determining a level of trust according to a selected user's frequency of use of the selected client device that corresponds with one or more of the log ins for the selected user, wherein a frequent user is granted enhanced trust over an infrequent user.

7. The method of claim 1 , further comprising:

establishing a pattern of use based at least on tracked information for any of a selected user or the selected client device, wherein the tracked information corresponds with one or more of the log ins for the selected user,

wherein extending trust is at least partially based on a level of conformance to the established pattern of use.

8. The method of claim 7 , wherein the tracked information comprises at least one of:

information indicating where the selected user dials in from;

information indicating a device type;

information indicating a device operating system;

information indicating an Internet Protocol (IP) address;

information indicating a subnet; or

information indicating the token on the selected client device.

9. A system for establishing trust across a network, comprising:

a service provider; and

one or more servers associated with the service provider;

wherein at least one of the servers is configured to write a token into any of a memory or a disk that is associated with a selected client device of one or more client devices;

wherein at least one of the servers is configured to confirm that the token exists on the selected client device during each log in of the selected client device through one or more access points across the network; and

wherein at least one of the servers is configured to extend an increase in trust to the selected client device at a level at least partially based on any of frequency of the log ins and number of the log ins through the access points for the selected client device.

10. The system of claim 9 , wherein the token comprises any of a cookie and a tag.

11. The system of claim 9 , wherein at least one of the servers is configured to authenticate a selected user, wherein the authentication is based on a combination of the extended trust and at least one other form of authentication.

12. The system of claim 9 , wherein the token comprises a statement that is created by an issuer, wherein the statement corresponds with one or more of the log ins for a selected user of the selected client device.

13. The system of claim 12 , wherein the selected client device is configured to provide the statement with a request for any of service and access.

14. The system of claim 9 , wherein at least one of the servers is configured to determine a level of trust according to a selected user's frequency of use of the selected client device that corresponds with one or more of the log ins for the selected user, wherein a frequent user is granted enhanced trust over an infrequent user.

15. A system for establishing trust with a service provider across a network, comprising:

one or more access points; and

one or more servers associated with the service provider;

wherein at least one of the servers is configured to write a token into any of a memory or a disk that is associated with a selected client device of one or more client devices;

wherein at least one of the servers is configured to confirm that the token exists on the selected client device during each log in of the selected client device through one or more of the access points across the network; and

wherein at least one of the servers is configured to extend an increase in trust to the selected client device at a level at least partially based on any of frequency of the log ins and number of the log ins through the access points for the selected client device.

16. The system of claim 15 , wherein the token comprises any of a cookie and a tag.

17. The system of claim 15 , wherein at least one of the servers is configured to authenticate a selected user, wherein the authentication is based on a combination of the extended trust and at least one other form of authentication.

18. The system of claim 15 , wherein at least one of the servers is configured to determine a level of trust according to a selected user's frequency of use of the selected client device that corresponds with one or more of the log ins for the selected user, wherein a frequent user is granted enhanced trust over an infrequent user.

19. The system of claim 15 , wherein at least one of the servers is configured to establish or update a pattern of use based at least on tracked information for any of a selected user or the selected client device, wherein the tracked information corresponds with one or more of the log ins for the selected user;

wherein the extended trust is at least partially based on a level of conformance to the pattern of use.

20. The system of claim 19 , wherein the tracked information comprises any of where the selected user dials in from, device type, device operating system, IP address, subnet, or the token on the selected client device.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2014
From: MICROSOFT CORPORATION
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 034544/0541 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 23, 2013
From: AOL, INC.
To: MICROSOFT CORPORATION
Reel/Frame 030855/0562 →
CHANGE OF NAME Recorded May 16, 2012
From: ROSKIND, JAMES A.
To: AMERICA ONLINE, INC.
Reel/Frame 028219/0347 →
CHANGE OF NAME Recorded May 16, 2012
From: AOL LLC
To: AOL INC.
Reel/Frame 028219/0560 →
CHANGE OF NAME Recorded May 16, 2012
From: AMERICA ONLINE, INC.
To: AOL LLC
Reel/Frame 028222/0354 →
Continuity (5)
Continuation 12960326 · Dec 3, 2010
Continuation 11615858 · Dec 22, 2006
Continuation 10465163 · Jun 18, 2003
Continuation In Part 10276842
Related Publication 20120222105A1 · Aug 30, 2012