IP Library Granted Patent US 9,832,252
Granted Patent B2
US 9,832,252 · App. 14/227,869 · Granted Nov 28, 2017

Systems, methods, and computer program products for third party authentication in communication services

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,832,252
App. No.
14/227,869
Granted
Nov 28, 2017
Kind
B2
Abstract

A method includes receiving a request from a first user at a first device to set up a communication session with a second user at a second device, in response to the request, directing the first device to authenticate the first user with a third party authentication service, receiving an authentication result corresponding to the first user, verifying the authentication result using information from the third party authentication service, and in response to verifying the authentication result, establishing the communication session on behalf of the first user.

Claims (59)

1. A method performed by a service node in a communication network, the method comprising:

with the service node, receiving a request from a first user at a first device to set up a communication session with a second user at a second device;

with the service node, in response to the request, sending a message to the first device, the message directing the first device to authenticate the first user with a third party authentication service, the message including a list of third party authentication services associated with nodes in the communication network other than the service node;

with the service node, receiving from the first device, a response that indicates a selected third party authentication service from the list of third party authentication services;

with the service node, in response to the response, establishing a shared secret with the selected third party authentication service, wherein the first user and first device do not have knowledge of the shared secret;

with the service node, receiving from the first device an authentication result corresponding to the first user, the authentication result including the shared secret;

with the service node, verifying the authentication result using information from the selected third party authentication service; and

with the service node, in response to verifying the authentication result, establishing the communication session on behalf of the first user.

2. The method of claim 1 , wherein verifying the authentication result includes confirming an identity of the first user, the method further comprising:

after the first user's identity is confirmed, requesting policy information from a policy entity;

receiving the policy information from the policy entity; and

applying usage policies to the communication session in accordance with the policy information.

3. The method of claim 2 , wherein the policy information includes usage requirements for communications with the first user.

4. The method of claim 2 , wherein the usage requirements are set by the second user in advance of the communication session.

5. The method of claim 2 , wherein the usage policies include at least one of:

restrictions on types of media;

restrictions on whether communication with specific users is allowed;

restrictions in time where communication is allowed; and

restrictions based on requested communication priority.

6. The method of claim 1 , wherein the service node comprises a web server in communication with the first device and in communication with an authentication server of the authentication service, the method further comprising:

establishing a shared secret with the authentication server; and

verifying the authentication result using the shared secret.

7. The method of claim 1 , wherein the authentication result is encrypted by the authentication service before being received from the first device.

8. The method of claim 7 , wherein verifying the authentication result includes decrypting the authentication result.

9. The method of claim 1 , wherein the service node comprises a web server, further wherein the web server and the first user communicate using Hypertext Transfer Protocol (HTTP).

10. The method of claim 9 , wherein the second device participates in the communication session through a communication server that negotiates with the web server to establish the communication session.

11. A system comprising: a network server configured to communicatively couple a first network device to a second network device, the network server comprising:

a processor configured to:

send a message from the network server to the first network device in response to a request by the first network device to establish a communication session, the message comprising a list of third party authentication services associated with servers other than the network server;

receive a response from the first network device, the response indicating a selected third party authentication from the list of third party authentication services, wherein the selected third party authentication service is not controlled by the first network device and is in communication with the first network device over the Internet;

establish a shared secret with the selected third party authentication service in response to receiving the response wherein the first network device does not have knowledge of the shared secret;

authenticate a user of the first network device by verifying information returned by the selected third party information service and information from the first network device that includes the shared secret; and

establish the communication session between the first and second network devices in response to authenticating the user of the first network device.

12. The system of claim 11 , wherein the network server has a pre-established relationship with the third party authentication service.

13. The system of claim 11 , wherein the processor is further configured to:

communicate with a policy entity to retrieve policy information defining policies of use with respect to the user of the first network device.

14. The system of claim 13 , wherein processor is further configured to:

applying the policies of use when establishing the communication session.

15. The system of claim 11 , wherein the network server comprises a web server.

16. A computer program product having a non-transitory computer readable medium tangibly recording computer program logic for establishing a call between a first user and a second user, the computer program product comprising:

code to receive a message at a service node, the message being from the first user requesting establishment of a call with a second user;

code to send a message from the service node to the first user, the message directing the first user to a third party authenticator before establishing the call, the message comprising a list of third party authentication services associated with network nodes other than the service node;

code to receive, from the first user, a response indicating a selected third party authentication service from the list of third party authentication services;

code to establish a shared secret with the selected third party authentication service in response to the response;

code to receive an authentication result from the first user, the authentication result including the shared secret, wherein the first user does not have knowledge of the shared secret;

code to verify an identity of the first user according to an authentication process of the selected third party authentication service; and

code to establish the call in response to verifying the identity.

17. The computer program product of claim 16 , wherein the call comprise at least one of:

text media;

video media; and

voice media.

18. The computer program product of claim 16 , further comprising:

code to pass identity information of the first user to the second user as a part of a call set-up process.

19. The computer program product of claim 16 , further comprising:

code to request use policies from a policy server based on identity information of the first user; and

code to apply received use policies as part of a call set-up process.

20. The computer program product of claim 16 , wherein code to verify an identity comprises:

code to receive an authentication result from the first user; and

code to decrypt the authentication result using an encryption secret shared with the third party authenticator.

Assignments (10)
SHORT-FORM PATENTS SECURITY AGREEMENT Recorded Sep 5, 2024
From: RIBBON COMMUNICATIONS OPERATING COMPANY, INC.
To: HPS INVESTMENT PARTNERS, LLC, AS ADMINISTRATIVE AGENT
Reel/Frame 068857/0290 →
RELEASE OF SECURITY INTEREST Recorded Jun 24, 2024
From: CITIZENS BANK, N.A.
To: RIBBON COMMUNICATIONS OPERATING COMPANY, INC. (F/K/A GENBAND US LLC AND SONUS NETWORKS, INC.)
Reel/Frame 067822/0433 →
TERMINATION AND RELEASE OF PATENT SECURITY AGREEMENT AT R/F 044978/0801 Recorded Dec 6, 2021
From: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
To: RIBBON COMMUNICATIONS OPERATING COMPANY, INC. (F/K/A GENBAND US LLC AND SONUS NETWORKS, INC.)
Reel/Frame 058949/0497 →
MERGER Recorded Jul 15, 2020
From: GENBAND US LLC
To: RIBBON COMMUNICATIONS OPERATING COMPANY, INC.
Reel/Frame 053223/0260 →
SECURITY INTEREST Recorded Mar 3, 2020
From: RIBBON COMMUNICATIONS OPERATING COMPANY, INC.
To: CITIZENS BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 052076/0905 →
SECURITY INTEREST Recorded Jan 2, 2018
From: GENBAND US LLC; SONUS NETWORKS, INC.
To: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
Reel/Frame 044978/0801 →
TERMINATION AND RELEASE OF PATENT SECURITY AGREEMENT Recorded Dec 29, 2017
From: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
To: GENBAND US LLC
Reel/Frame 044986/0303 →
CORRECTIVE ASSIGNMENT TO CORRECT PATENT NO. 6381239 PREVIOUSLY RECORDED AT REEL: 039269 FRAME: 0234. ASSIGNOR(S) HEREBY CONFIRMS THE PATENT SECURITY AGREEMENT. Recorded Jan 3, 2017
From: GENBAND US LLC
To: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
Reel/Frame 041422/0080 →
PATENT SECURITY AGREEMENT Recorded Jul 6, 2016
From: GENBAND US LLC
To: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
Reel/Frame 039269/0234 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 25, 2014
From: SYLVAIN, DANY
To: GENBAND US LLC
Reel/Frame 032761/0211 →