IP Library Granted Patent US 10,148,630
Granted Patent B2
US 10,148,630 · App. 14/448,814 · Granted Dec 4, 2018

System and method for implementing a hosted authentication service

Inventor: Davit Baghdasaryan (San Francisco, CA)
Assignee: NOK NOK LABS, INC.
H04L63/08H04L63/0884G06Q20/40H04L63/0823H04L63/10H04L63/12H04W4/008H04W4/80
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,148,630
App. No.
14/448,814
Granted
Dec 4, 2018
Kind
B2
Abstract

A system, apparatus, method, and machine readable medium are described for a hosted authentication service. For example, one embodiment of a system comprises: a hosted authentication service to provide authentication services for relying parties, the hosted authentication service registering a relying party by sharing a key with the relying party; a first program code component inserted into an application hosted by the relying party, the first program code component causing a client device accessing the application to be redirected to the hosted authentication service for authentication-related functions; and the hosted authentication service transmitting one or more assertions to the relying party specifying authentication-related events occurring between the client device and the hosted authentication service, the relying party validating the assertions using the key.

Claims (26)

1. A system comprising: one or more hardware platforms implementing a hosted authentication service to provide authentication services for relying parties, the hosted authentication service and the relying parties being separate parties, the hosted authentication service registering a relying party by sharing a key with the relying party, the hosted authentication service comprising an administration portal through which a relying party administrator configures the hosted authentication service to provide authentication services on behalf of the relying party;

a first program code component provided by the hosted authentication service is inserted into an application hosted by the relying party, the first program code component causing a client device accessing the application to be redirected to the hosted authentication service for user-authentication and other authentication-related functions including registering one or more new authenticators and deregistering one or more authenticators of a user's client device; and

the hosted authentication service, based on a plurality of different authentication-related events occurring between the client device and the hosted authentication service, transmitting a plurality of assertions directly to the relying party thereby bypassing the client device, each assertion of the plurality of assertions specifying one different authentication-related event occurring between the client device and the hosted authentication service, each assertion of the plurality of assertions including at least one indication, wherein a first assertion indicates that the user has registered a new authenticator, a second assertion indicates that the user has deregistered an authenticator, and a third assertion indicates that the user has authenticated with the authentication service using an authenticator, wherein the relying party validating each one of the plurality of assertions using the key.

2. The system as in claim 1 wherein the key comprises a symmetric assertion key.

3. The system as in claim 2 wherein the hosted authentication service generates a first signature over data in one of the plurality of assertions using the symmetric assertion key, the relying party using its copy of the symmetric assertion key to generate a second signature over the data in the one of the plurality of assertions and comparing the first signature with the second signature to validate the one of the plurality of assertions.

4. The system as in claim 1 wherein the first program code component comprises hypertext markup language (HTML) code and wherein the application comprises a Web application.

5. The system as in claim 1 further comprising: a second program code component inserted into a back-end component of the application hosted by the relying party, the second program code component securely storing the key.

6. The system as in claim 5 wherein the application comprises a Web application including the back-end and a front-end comprising hypertext markup language (HTML) code.

7. The system as in claim 1 wherein the administration portal generates front-end code to be applied to a front-end of the application and back-end code to be applied to a back-end of the application, the front-end code usable to redirect client devices to the hosted authentication service and the back-end code usable to securely store and access the key.

8. The system as in claim 1 wherein each one of the plurality of assertions further includes an indication of an authenticator type, model, and/or strength.

9. A method comprising: registering a relying party at a hosted authentication service by sharing a key with the relying party, the hosted authentication service and the relying parties being separate parties, the hosted authentication service comprising an administration portal through which a relying party administrator configures the hosted authentication service to provide authentication services on behalf of the relying party;

inserting a first program code component provided by the hosted authentication device into an application hosted by the relying party, the first program code component causing a client device accessing the application to be redirected to the hosted authentication service for user-authentication and other authentication-related functions including registering one or more new authenticators and deregistering one or more authenticators of a user's client device; and

transmitting, based on a plurality of authentication-related events occurring between the client device and the hosted authentication service, a plurality of assertions from the hosted authentication service directly to the relying party thereby bypassing the client device, each assertion of the plurality of assertions specifying one different authentication-related event occurring between the client device and the hosted authentication service, each assertion of the plurality of assertions including at least one indication, wherein a first assertion indicates that the user has registered a new authenticator, a second assertion indicates that the user has deregistered an authenticator, and a third assertion indicates that the user has authenticated with the authentication service using an authenticator, wherein the relying party validating each one of the plurality of assertions using the key.

10. The method as in claim 9 wherein the key comprises a symmetric assertion key.

11. The method as in claim 10 wherein the hosted authentication service generates a first signature over data in one of the plurality of assertions using the symmetric assertion key, the relying party using its copy of the symmetric assertion key to generate a second signature over the data in the one of the plurality of assertions and comparing the first signature with the second signature to validate the one of the plurality of assertions.

12. The method as in claim 9 wherein the first program code component comprises hypertext markup language (HTML) code and wherein the application comprises a Web application.

13. The method as in claim 9 further comprising: a second program code component inserted into a back-end component of the application hosted by the relying party, the second program code component securely storing the key.

14. The method as in claim 13 wherein the application comprises a Web application including the back-end and a front-end comprising hypertext markup language (HTML) code.

15. The method as in claim 9 wherein the administration portal generates front-end code to be applied to a front-end of the application and back-end code to be applied to a back-end of the application, the front-end code usable to redirect client devices to the hosted authentication service and the back-end code usable to securely store and access the key.

16. The method as in claim 9 wherein each one of the plurality of assertions further includes an indication of an authenticator type, model, and/or strength.

17. A non-transitory machine-readable medium having program code stored thereon which, when executed by a machine, causes the machine to perform operations of: registering a relying party at a hosted authentication service by sharing a key with the relying party, the hosted authentication service and the relying parties being separate parties, the hosted authentication service comprising an administration portal through which a relying party administrator configures the hosted authentication service to provide authentication services on behalf of the relying party;

inserting a first program code component provided by the hosted authentication service into an application hosted by the relying party, the first program code component causing a client device accessing the application to be redirected to the hosted authentication service for user-authentication and other authentication-related functions including registering one or more new authenticators and deregistering one or more authenticators of a user's client device; and

transmitting, based on a plurality of different authentication-related-events occurring between the client device and the hosted authentication service, a plurality of assertions from the hosted authentication service directly to the relying party thereby bypassing the client device, each assertion of the plurality of assertions specifying one different authentication-related event occurring between the client device and the hosted authentication service, each assertion of the plurality of assertions including at least one indication, wherein a first assertion indicates that the user has registered a new authenticator, a second assertion indicates that the user has deregistered an authenticator, and a third assertion indicates that the user has authenticated with the authentication service using an authenticator, wherein the relying party validating each one of the plurality of assertions using the key.

18. The non-transitory machine-readable medium as in claim 17 wherein the key comprises a symmetric assertion key.

19. The non-transitory machine-readable medium as in claim 18 wherein the hosted authentication service generates a first signature over data in one of the plurality of assertions using the symmetric assertion key, the relying party using its copy of the symmetric assertion key to generate a second signature over the data in the one of the plurality of assertions and comparing the first signature with the second signature to validate the one of the plurality of assertions.

20. The non-transitory machine-readable medium as in claim 17 wherein the first program code component comprises hypertext markup language (HTML) code and wherein the application comprises a Web application.

Assignments (8)
CORRECTIVE ASSIGNMENT TO CORRECT THE APPLICATION NUMBER PREVIOUSLY RECORDED AT REEL: 71257 FRAME: 566. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST. Recorded Aug 26, 2025
From: VENTURE LENDING & LEASING VII, INC.; VENTURE LENDING & LEASING VIII, INC.
To: NOK NOK LABS, INC.
Reel/Frame 073057/0274 →
SECURITY INTEREST Recorded Jul 1, 2025
From: NOK NOK LABS, INC.
To: MUFG BANK, LTD.
Reel/Frame 071773/0493 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ERRONEOUSLY RECORDED PATENT APPLICATION NUMBER 14488747 PREVIOUSLY RECORDED ON REEL 71273 FRAME 25. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Jun 18, 2025
From: VENTURE LENDING & LEASING IX, INC.; VENTURE LENDING & LEASING VIII, INC.
To: NOK NOK LABS, INC.
Reel/Frame 071773/0352 →
RELEASE OF SECURITY INTEREST Recorded May 30, 2025
From: VENTURE LENDING & LEASING VIII, INC.; VENTURE LENDING & LEASING IX, INC.
To: NOK NOK LABS, INC.
Reel/Frame 071273/0025 →
RELEASE OF SECURITY INTEREST Recorded May 29, 2025
From: VENTURE LENDING & LEASING VII, INC.; VENTURE LENDING & LEASING VIII, INC.
To: NOK NOK LABS, INC.
Reel/Frame 071257/0566 →
SECURITY INTEREST Recorded Jul 5, 2018
From: NOK NOK LABS, INC.
To: VENTURE LENDING & LEASING IX, INC.; VENTURE LENDING & LEASING VIII, INC.
Reel/Frame 046492/0870 →
SECURITY INTEREST Recorded Jan 12, 2017
From: NOK NOK LABS, INC.
To: VENTURE LENDING & LEASING VII, INC.; VENTURE LENDING & LEASING VIII, INC.
Reel/Frame 041352/0867 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 24, 2015
From: BAGHDASARYAN, DAVIT
To: NOK NOK LABS, INC.
Reel/Frame 035012/0767 →
Continuity (1)
Related Publication 20160248742A1 · Aug 25, 2016