IP Library Granted Patent US 10,776,464
Granted Patent B2
US 10,776,464 · App. 14/218,646 · Granted Sep 15, 2020

System and method for adaptive application of authentication policies

Inventor: Brendon Wilson (San Jose, CA)
Assignee: Nok Nok Labs, Inc.
G06F21/32G06F21/577G06Q20/204G06Q20/3224G06Q20/3274G06Q20/3278G06Q20/4012G06Q20/40145G06Q20/42G06Q20/425G07F19/20H04L9/0819H04L9/0822H04L9/0841H04L9/3231H04L9/3247H04L9/3297H04L63/0492H04L63/08H04L63/083H04L63/0861H04L63/20G06F2221/2115H04L2209/805H04L2463/102H04W12/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,776,464
App. No.
14/218,646
Granted
Sep 15, 2020
Kind
B2
Abstract

A system, apparatus, method, and machine readable medium are described for adaptively implementing an authentication policy. For example, one embodiment of a method comprises: detecting a user of a client attempting to perform a current interaction with a relying party; and responsively identifying a first interaction class for the current interaction based on variables associated with the current interaction and implementing a set of one or more authentication rules associated with the first interaction class.

Claims (44)

1. A method for user authentication comprising:

initially defining a plurality of authentication device classes based on characteristics of client authentication devices, the characteristics comprising a type of authentication device and a level of security assurance of the client device's hardware and/or software;

initially defining a plurality of interaction classes for a relying party, the interaction classes defined based on variables associated with interactions between a client and the relying party, the variables including an amount of money or a level of sensitivity of information involved in the interactions;

initially defining one or more authentication rule sets specifying authentication devices or classes of authentication devices to be used for different interaction classes, the one or more authentication rule sets comprising a first rule set;

detecting, by a secure transaction services engine, a user of a client attempting to perform a current interaction with a relying party over a network; and

responsively identifying a first interaction class for the current interaction, by an adaptive authentication policy hardware engine, based on variables associated with the current interaction and

implementing a first rule set of one or more authentication rules associated with the first interaction class to authenticate the user of the client, wherein implementing the first rule set of one or more authentication rules comprises the adaptive authentication policy hardware engine implementing a first rule specifying a particular authentication device class required to authenticate the user for the current interaction, wherein the first rule comprises a prioritized list of acceptable authentication device classes for the current interaction.

2. The method as in claim 1 further comprising:

initially classifying a plurality of authentication device models into the plurality of authentication device classes based on characteristics of the authentication device models.

3. The method as in claim 1 wherein the client selects a first authentication device to be used for authentication based on the prioritized list of acceptable authentication device classes.

4. The method as in claim 1 wherein the variables associated with the current interaction comprises an amount of money or sensitivity of data involved in the current interaction.

5. The method as in claim 1 wherein the type of authentication device includes fingerprint authentication, PIN or password entry, face recognition authentication, voice recognition authentication, authentication using a trusted platform module (TPM) device, and/or retinal scanning authentication.

6. The method as in claim 2 wherein at least one authentication device class is defined to have a particular authentication factor with a false acceptance rate below a specified threshold.

7. The method as in claim 2 wherein at least one authentication device class is defined based on where and/or how a matching algorithm is implemented to match biometric data extracted from an authentication device with biometric template data stored in a secure storage.

8. The method as in claim 7 wherein the authentication device class is defined based on the matching algorithm being, or not being implemented within a secure execution environment.

9. The method as in claim 6 wherein the one authentication device class is further defined to store sensitive data in cryptographically secure hardware and/or software.

10. The method as in claim 3 further comprising:

generating an assurance level based, at least in part, on a user authentication with the first authentication device.

11. The method as in claim 10 wherein the interaction is permitted if the assurance level is above a specified threshold.

12. The method as in claim 11 wherein the assurance level is generated, at least in part, based on current sensor data read from client sensors, wherein at least one of the sensors comprises a location sensor providing a current location of the client.

13. An authentication system comprising:

an authentication policy database to store authentication policies for a relying party;

a secure transaction services engine of the relying party to detect a user of a client attempting to perform a current interaction with the relying party over a network;

an adaptive authentication policy hardware engine of the relying party to perform operations of:

initially define a plurality of interaction classes in the authentication policy database, the interaction classes defined based on variables associated with interactions between the client and the relying party, the variables including an amount of money or a level of sensitivity of information involved in the interactions;

initially define one or more authentication rule sets in the authentication policy database specifying authentication devices or classes of authentication devices to be used for different interaction classes, the one or more authentication rule sets comprising a first rule set; and

query the authentication policy database to identify a first interaction class for the current interaction based on variables associated with the current interaction and to implement the first rule set of one or more authentication rules associated with the first interaction class to authenticate the user of the client, wherein implementing a first rule set of one or more authentication rules comprises the adaptive authentication policy hardware engine implementing a first rule specifying a particular authentication device class required to authenticate the user for the current interaction, the first rule comprising a prioritized list of acceptable authentication device classes for the current interaction, and wherein the adaptive authentication policy hardware engine is to perform additional operations of initially defining a plurality of authentication device classes in the authentication policy database based on characteristics of client authentication devices, the characteristics comprising a type of authentication device and a level of security assurance of the client device's hardware and/or software.

14. The authentication system as in claim 13 further comprising:

initially classifying a plurality of authentication device models into the plurality of authentication device classes in the authentication policy database based on characteristics of the authentication device models.

15. The authentication system as in claim 13 wherein the client selects a first authentication device to be used for authentication based on the prioritized list of acceptable authentication device classes.

16. The authentication system as in claim 13 wherein the variables associated with the current interaction comprises an amount of money or sensitivity of data involved in the current interaction.

17. The authentication system as in claim 13 wherein the type of authentication device includes fingerprint authentication, PIN or password entry, face recognition authentication, voice recognition authentication, authentication using a trusted platform module (TPM) device, and/or retinal scanning authentication.

18. The authentication system as in claim 14 wherein at least one authentication device class is defined to have a particular authentication factor with a false acceptance rate below a specified threshold.

19. The authentication system as in claim 14 wherein at least one authentication device class is defined based on where and/or how a matching algorithm is implemented to match biometric data extracted from an authentication device with biometric template data stored in a secure storage.

20. The authentication system as in claim 19 wherein the authentication device class is defined based on the matching algorithm being, or not being implemented within a secure execution environment.

21. The authentication system as in claim 18 wherein the one authentication device class is further defined to store sensitive data in cryptographically secure hardware and/or software.

22. The authentication system as in claim 15 further comprising:

the client generating an assurance level based, at least in part, on a user authentication with the first authentication device.

23. The authentication system as in claim 22 wherein the interaction is permitted if the assurance level is above a specified threshold.

24. The authentication system as in claim 23 wherein the assurance level is generated, at least in part, based on current sensor data read from client sensors, wherein at least one of the sensors comprises a location sensor providing a current location of the client.

25. The method as in claim 1 , wherein the characteristics of client authentication devices further comprises a type of location in which secrets are stored.

26. The method as in claim 1 , wherein the characteristics of client authentication devices further comprises a type of location where cryptographic operations are performed by the authentication devices.

27. The authentication system as in claim 13 , wherein the characteristics of client authentication devices further comprises a type of location in which secrets are stored.

28. The authentication system as in claim 13 , wherein the characteristics of client authentication devices further comprises a type of location where cryptographic operations are performed by the authentication devices.

Assignments (8)
CORRECTIVE ASSIGNMENT TO CORRECT THE APPLICATION NUMBER PREVIOUSLY RECORDED AT REEL: 71257 FRAME: 566. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST. Recorded Aug 26, 2025
From: VENTURE LENDING & LEASING VII, INC.; VENTURE LENDING & LEASING VIII, INC.
To: NOK NOK LABS, INC.
Reel/Frame 073057/0274 →
SECURITY INTEREST Recorded Jul 1, 2025
From: NOK NOK LABS, INC.
To: MUFG BANK, LTD.
Reel/Frame 071773/0493 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ERRONEOUSLY RECORDED PATENT APPLICATION NUMBER 14488747 PREVIOUSLY RECORDED ON REEL 71273 FRAME 25. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Jun 18, 2025
From: VENTURE LENDING & LEASING IX, INC.; VENTURE LENDING & LEASING VIII, INC.
To: NOK NOK LABS, INC.
Reel/Frame 071773/0352 →
RELEASE OF SECURITY INTEREST Recorded May 30, 2025
From: VENTURE LENDING & LEASING VIII, INC.; VENTURE LENDING & LEASING IX, INC.
To: NOK NOK LABS, INC.
Reel/Frame 071273/0025 →
RELEASE OF SECURITY INTEREST Recorded May 29, 2025
From: VENTURE LENDING & LEASING VII, INC.; VENTURE LENDING & LEASING VIII, INC.
To: NOK NOK LABS, INC.
Reel/Frame 071257/0566 →
SECURITY INTEREST Recorded Jul 5, 2018
From: NOK NOK LABS, INC.
To: VENTURE LENDING & LEASING IX, INC.; VENTURE LENDING & LEASING VIII, INC.
Reel/Frame 046492/0870 →
SECURITY INTEREST Recorded Jan 12, 2017
From: NOK NOK LABS, INC.
To: VENTURE LENDING & LEASING VII, INC.; VENTURE LENDING & LEASING VIII, INC.
Reel/Frame 041352/0867 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 7, 2015
From: WILSON, BRENDON
To: NOK NOK LABS, INC.
Reel/Frame 034913/0103 →
Continuity (2)
Provisional Application 61804568 · Mar 22, 2013
Related Publication 20140289790A1 · Sep 25, 2014
Cited By (1)
US 12,437,107