IP Library Granted Patent US 9,332,433
Granted Patent B1
US 9,332,433 · App. 14/041,125 · Granted May 3, 2016

Distributing access and identification tokens in a mobile environment

Inventors: Yedidya Dotan (Newton, MA); Lawrence N. Friedman (Arlington, MA); Riaz Zolfonoon (Concord, MA); Gareth Richards (Woodstock, GB); Guoying Luo (Lexington, MA)
Assignee: EMC Corporation
H04W12/06H04L63/08H04L63/0807H04L63/0815H04L63/0853H04L63/0876
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,332,433
App. No.
14/041,125
Filed
Sep 30, 2013
Granted
May 3, 2016
Kind
B1
Examiner
KIM, TAE K
Art Unit
2492
USPC
726/9
Abstract

A technique performs authentication before delivering a token to a client device. The technique involves receiving a first message from a first application on the client device, the first message including a token request and a first set of authentication factors. The technique further involves receiving a second message from a second application on the client device, the second message including an authentication request and a second set of authentication factors. The technique further involves generating a result message which (i) provides access to a token for use by the client device when the first set of authentication factors is consistent with the second set of authentication factors, and (ii) rejects the token request when the first set of authentication factors is inconsistent with the second set of authentication factors. The client device may be a mobile device, and the first and second messages may be received via wireless communications.

Claims (84)

1. A method of performing authentication, the method comprising:

receiving, by processing circuitry, a first message from a first application running on a client device, the first message including a token request and a first set of authentication factors;

receiving, by the processing circuitry, a second message from a second application running on the client device, the second message including an authentication request and a second set of authentication factors; and

generating, by the processing circuitry, an authentication result message which (i) provides access to a token for use by the client device when the first set of authentication factors is consistent with the second set of authentication factors, and (ii) rejects the token request when the first set of authentication factors is inconsistent with the second set of authentication factors;

wherein the client device is a mobile device; wherein the first message is received via wireless communications;

wherein the second message is received via wireless communications;

wherein receiving the first message from the first application running on the mobile device includes obtaining the first message from a browser application which is constructed and arranged to access a resource from a service provider (SP) server;

wherein receiving the second message from the second application running on the mobile device includes obtaining the second message from a security application which is constructed and arranged to (i) collect the second set of authentication factors on the mobile device and (ii) send the second set of authentication factors to the processing circuitry independently of the browser application running on the mobile device;

wherein the processing circuitry includes (i) an identity provider (IDP) server and (ii) an authentication server;

wherein obtaining the first message from the browser application includes acquiring the first set of authentication factors by the IDP server;

wherein obtaining the second message from the security application includes acquiring the second set of authentication factors by the authentication server in a manner which is out of band of the IDP server; and wherein the method further comprises:

receiving, by the IDP server, another message from the browser application running on the mobile device via wireless communications, the other message including a token identifier which identifies the token, and providing, by the IDP server, a response message to the mobile device in response to the other message from the browser application.

2. A method as in claim 1 wherein the other message from the browser application further includes a third set of authentication factors;

wherein the response message includes the token for use by the mobile device when the IDP server successfully matches the first set of authentication factors with the third set of authentication factors; and

wherein the response message includes a token rejection when the IDP server does not successfully match the first set of authentication factors with the third set of authentication factors.

3. A method as in claim 1 , further comprising:

selecting a particular token from multiple tokens stored in a token database of the IDP server based on the token identifier, the response message including the particular token selected from multiple tokens stored in the token database of the IDP server.

4. A method as in claim 3 , further comprising:

delivering the token from the authentication server to the IDP server for storage in the token database in a manner which is out of band with the mobile device.

5. A method as in claim 3 wherein the particular token is a bearer token that authenticates a user to the SP server in accordance with a bearer subject confirmation method.

6. A method as in claim 1 , further comprising:

providing, by the IDP server, an augmented universal resource locator (URL) string in response to the first message from the browser application, the augmented URL string directing the browser application to automatically launch the security application on the mobile device.

7. A method as in claim 1 wherein the first set of authentication factors of the first message includes a first set of mobile device fingerprints which distinguish the mobile device from other mobile devices;

wherein the second set of authentication factors of the second message includes a second set of mobile device fingerprints which distinguish the mobile device from other mobile devices; and

wherein the method further comprises comparing the first set of mobile device fingerprints to the second set of mobile device fingerprints to determine whether the first message and the second message were received from the same mobile device.

8. A method as in claim 1 wherein the first set of authentication factors of the first message includes a first set of biometric data;

wherein the second set of authentication factors of the second message includes a second set of biometric data; and

wherein the method further comprises comparing the first set of biometric data to the second set of biometric data to determine whether the first message and the second message were received from the same user.

9. A method of obtaining access to a token from a mobile device, the method comprising:

providing, by the mobile device, a first message from a first application running on the mobile device to remote processing circuitry via wireless communications, the first message including a token request and a first set of authentication factors;

providing, by the mobile device, a second message from a second application running on the mobile device to the remote processing circuitry via wireless communications, the second message including an authentication request and a second set of authentication factors; and

receiving, by the mobile device, an authentication result message from the remote processing circuitry, the authentication result message (i) providing access to a token for use by the mobile device when the first set of authentication factors is consistent with the second set of authentication factors, and (ii) rejecting the token request when the first set of authentication factors is inconsistent with the second set of authentication factors;

wherein providing the first message from the first application running on the mobile device includes sending the first message using a browser application which is constructed and arranged to access a resource from a service provider (SP) server;

wherein providing the second message from the second application running on the mobile device includes sending the second message using a security application which is constructed and arranged to (i) collect the second set of authentication factors on the mobile device and (ii) send the second set of authentication factors to the remote processing circuitry independently of the browser application running on the mobile device;

wherein the remote processing circuitry includes (i) an identity provider (IDP) server and (ii) an authentication server;

wherein sending the first message using the browser application includes transmitting the first set of authentication factors to the IDP server;

wherein sending the second message from the security application includes transmitting the second set of authentication factors to the authentication server in a manner which is out of band of the IDP server; and

wherein the method further comprises:

providing, by the mobile device, another message to the IDP server from the browser application running on the mobile device via wireless communications, the other message including a token identifier which identifies the token, and

receiving, by the mobile device, a response message from the IDP server in response to the other message from the browser application.

10. A method as in claim 9 further comprising:

receiving an augmented universal resource locator (URL) string from the IDP server in response to the first message, and

in response to the URL string, automatically launching the security application on the mobile device.

11. A method as in claim 9 , further comprising:

collecting a first set of user biometric data for inclusion in the first set of authentication factors of the first message; and

collecting a second set of user biometric data for inclusion in the second set of authentication factors of the second message.

12. A method as in claim 9 wherein the other message from the browser application further includes a third set of authentication factors;

wherein the response message includes the token for use by the mobile device when the IDP server successfully matches the first set of authentication factors with the third set of authentication factors; and

wherein the response message includes a token rejection when the IDP server does not successfully match the first set of authentication factors with the third set of authentication factors.

13. A method as in claim 9 wherein the IDP server selects a particular token from multiple tokens stored in a token database of the IDP server based on the token identifier, the response message including the particular token selected from multiple tokens stored in the token database of the IDP server.

14. A method as in claim 13 wherein the token is delivered from the authentication server to the IDP server for storage in the token database in a manner which is out of band with the mobile device.

15. A method as in claim 13 wherein the particular token is a bearer token that authenticates a user to the SP server in accordance with a bearer subject confirmation method.

16. A computer program product having a non-transitory computer readable medium which stores a set of instructions to perform authentication, the set of instructions, when carried out by computerized circuitry, causing the computerized circuitry to perform a method of:

receiving, by the computerized circuitry, a first message from a first application running on the mobile device via wireless communications, the first message including a token request and a first set of authentication factors;

receiving, by the computerized circuitry, a second message from a second application running on the mobile device via wireless communications, the second message including an authentication request and a second set of authentication factors; and

generating, by the computerized circuitry, an authentication result message which (i) provides access to a token for use by the mobile device when the first set of authentication factors is consistent with the second set of authentication factors, and (ii) rejects the token request when the first set of authentication factors is inconsistent with the second set of authentication factors;

wherein receiving the first message from the first application running on the mobile device includes obtaining the first message from a browser application which is constructed and arranged to access a resource from a service provider (SP) server;

wherein receiving the second message from the second application running on the mobile device includes obtaining the second message from a security application which is constructed and arranged to (i) collect the second set of authentication factors on the mobile device and (ii) send the second set of authentication factors to the processing circuitry independently of the browser application running on the mobile device;

wherein the computerized circuitry includes (i) an identity provider (IDP) server and (ii) an authentication server;

wherein obtaining the first message from the browser application includes acquiring the first set of authentication factors by the IDP server;

wherein obtaining the second message from the security application includes acquiring the second set of authentication factors by the authentication server in a manner which is out of band of the IDP server; and wherein the method further comprises:

receiving, by the IDP server, another message from the browser application running on the mobile device via wireless communications, the other message including a token identifier which identifies the token, and

providing, by the IDP server, a response message to the mobile device in response to the other message from the browser application.

17. A computer program product as in claim 16 wherein the other message from the browser application further includes a third set of authentication factors;

wherein the response message includes the token for use by the mobile device when the IDP server successfully matches the first set of authentication factors with the third set of authentication factors; and

wherein the response message includes a token rejection when the IDP server does not successfully match the first set of authentication factors with the third set of authentication factors.

18. A computer program product as in claim 16 , further comprising:

selecting a particular token from multiple tokens stored in a token database of the IDP server based on the token identifier, the response message including the particular token selected from multiple tokens stored in the token database of the IDP server.

19. A computer program product as in claim 18 , further comprising:

delivering the token from the authentication server to the IDP server for storage in the token database in a manner which is out of band with the mobile device.

20. A computer program product as in claim 18 wherein the particular token is a bearer token that authenticates a user to the SP server in accordance with a bearer subject confirmation method.

21. A method of performing authentication, the method comprising:

receiving, by processing circuitry, a first message from a first application running on a client device, the first message including a token request and a first set of authentication factors;

receiving, by the processing circuitry, a second message from a second application running on the client device, the second message including an authentication request and a second set of authentication factors; and

generating, by the processing circuitry, an authentication result message which (i) provides access to a token for use by the client device when the first set of authentication factors is consistent with the second set of authentication factors, and (ii) rejects the token request when the first set of authentication factors is inconsistent with the second set of authentication factors;

wherein the client device is a mobile device; wherein the first message is received via wireless communications;

wherein the second message is received via wireless communications;

wherein receiving the first message from the first application running on the mobile device includes obtaining the first message from a browser application which is constructed and arranged to access a resource from a service provider (SP) server;

wherein receiving the second message from the second application running on the mobile device includes obtaining the second message from a security application which is constructed and arranged to (i) collect the second set of authentication factors on the mobile device and (ii) send the second set of authentication factors to the processing circuitry independently of the browser application running on the mobile device;

wherein the processing circuitry includes (i) an identity provider (IDP) server and (ii) an authentication server;

wherein obtaining the first message from the browser application includes acquiring the first set of authentication factors by the IDP server;

wherein obtaining the second message from the security application includes acquiring the second set of authentication factors by the authentication server in a manner which is out of band of the IDP server;

wherein the method further comprises providing, by the IDP server, an augmented universal resource locator (URL) string in response to the first message from the browser application, the augmented URL string directing the browser application to automatically launch the security application on the mobile device; and

wherein, when the authentication result message provides access to the token for use by the mobile device, the authentication result message includes a token identifier and directs the security application running on the mobile device to point the browser application to the IDP server to retrieve the token from the IDP server using the token identifier.

Assignments (23)
RELEASE OF SECURITY INTEREST FILED JANUARY 21, 2026 Recorded Mar 9, 2026
From: ALTER DOMUS (US) LLC
To: RSA SECURITY LLC; RSA SECURITY USA LLC
Reel/Frame 075089/0201 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56096/0525 Recorded Mar 5, 2026
From: JPMORGAN CHASE BANK, N.A.
To: RSA SECURITY LLC; RSA SECURITY USA LLC
Reel/Frame 075030/0744 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56098/0534 Recorded Mar 5, 2026
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: RSA SECURITY LLC
Reel/Frame 075041/0175 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY LLC
Reel/Frame 069762/0401 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY USA, LLC
Reel/Frame 069762/0529 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 056096/0525 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 053666, FRAME 0767 Recorded Apr 29, 2021
From: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056095/0574 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 056098/0534 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 054155, FRAME 0815 Recorded Apr 29, 2021
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056104/0841 →
PARTIAL RELEASE OF SECURITY INTEREST Recorded Nov 24, 2020
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXRESS, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054511/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 7, 2020
From: EMC IP HOLDING COMPANY LLC
To: RSA SECURITY LLC
Reel/Frame 053717/0020 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054191/0287 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (049452/0223) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054250/0372 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: ASAP SOFTWARE EXPRESS; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054163/0416 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: JEFFERIES FINANCE LLC
Reel/Frame 053666/0767 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 054155/0815 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040203/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 30, 2015
From: DOTAN, YEDIDYA; FRIEDMAN, LAWRENCE N.; ZOLFONOON, RIAZ; RICHARDS, GARETH; LUO, GOUYING
To: EMC CORPORATION
Reel/Frame 035534/0437 →