System and Method for Providing Persistent Authentication in an Information Handling System
An information handling system includes a secure resource, an input device that receives an authentication credential from a user and generates authentication information based upon the authentication credential, an authentication engine that receives the authentication information and provides confidence information based upon the authentication information, and an authentication agent that receives the confidence information and grants the user a level access to the secure resource based upon the confidence information.
1 . An information handling system, comprising:
a first secure resource;
a first input device that receives a first authentication credential from a user and generates first authentication information based upon the first authentication credential;
an authentication engine that receives the first authentication information and provides first confidence information based upon the first authentication information; and
a first authentication agent that receives the first confidence information and grants to the user a first level access to the first secure resource based upon the first confidence information.
2 . The information handling system of claim 1 , wherein the information handling system receives an authenticated token for the user in response to receiving the first authentication credential at the first input device.
3 . The information handling system of claim 2 , wherein the first input device:
generates a generated token for the user based upon the first authentication information;
determines if the generated token matches the authenticated token; and
generates the first authentication information when the generated token matches the authenticated token.
4 . The information handling system of claim 1 , wherein:
the first authentication information comprises a generated token for the user;
in providing the first confidence information, the authentication engine:
determines if the generated token matches the authenticated token; and
provides the first confidence information when the generated token matches the authenticated token.
5 . The information handling system of claim 1 , wherein:
the confidence information comprises a confidence score that is based upon first authentication information; and
the first authentication agent grants the user the first level access to the first secure resource when the confidence score is above a confidence score threshold.
6 . The information handling system of claim 5 , wherein:
the confidence information further comprises a confidence level that is based upon confidence score; and
the first authentication agent grants the user the first level access to the first secure resource when the confidence level is above a confidence level threshold.
7 . The information handling system of claim 6 , wherein:
the confidence information further comprises confidence metadata that is based upon a condition of the authentication information; and
the first authentication agent grants the user the first level access to the first secure resource based upon the confidence metadata.
8 . The information handling system of claim 1 , further comprising:
a second input device that receives a second authentication credential from the user and generates second authentication information based upon the second authentication credential;
wherein:
the authentication engine receives the second authentication information and provides second confidence information based upon the second authentication information; and
the first authentication agent that receives the second confidence information and grants the user a second level access to the first secure resource based upon the second confidence information.
9 . The information handling system of claim 1 , further comprising:
a second secure resource; and
a second authentication agent that receives the first confidence information and grants the user a second level access to the second secure resource based upon the first confidence information.
10 . A method, comprising:
receiving, at a first input device of an information handling system, a first authentication credential from a user;
generating first authentication information based upon the first authentication credential;
receiving, at an authentication engine of the information handling system, the first authentication information;
providing first confidence information based upon the first authentication information;
receiving, at a first authentication agent of the information handling system, the first confidence information; and
granting to the user a first level access to a first secure resource of the information handling system based upon the first confidence information.
11 . The method of claim 10 , further comprising:
receiving an authenticated token for the user in response to receiving the first authentication credential at the first input device.
12 . The method of claim 11 , further comprising:
generating, by the first input device, a generated token for the user based upon the first authentication information; and
determining if the generated token matches the authenticated token; and
wherein the first authentication information is generated when the generated token matches the authenticated token.
13 . The method of claim 10 , wherein:
the first authentication information comprises a generated token for the user;
in providing the first confidence information, the method further comprises determining if the generated token matches the authenticated token; and
the first confidence information is provided when the generated token matches the authenticated token.
14 . The method of claim 10 , wherein:
the confidence information comprises a confidence score that is based upon first authentication information; and
the user is granted the first level access to the first secure resource when the confidence score is above a confidence score threshold.
15 . The method of claim 14 , wherein:
the confidence information further comprises a confidence level that is based upon confidence score; and
the user is granted the first level access to the first secure resource when the confidence level is above a confidence level threshold.
16 . The method of claim 15 , wherein:
the confidence information further comprises confidence metadata that is based upon a condition of the authentication information; and
the user is granted the first level access to the first secure resource based upon the confidence metadata.
17 . The method of claim 10 , further comprising:
receiving, by a second input device of the information handling system, a second authentication credential from the user;
generating second authentication information based upon the second authentication credential;
receiving, at the authentication engine, the second authentication information; and
providing second confidence information based upon the second authentication information;
receiving, at the first authentication agent, the second confidence information; and
granting the user a second level access to the first secure resource based upon the second confidence information.
18 . The method of claim 10 , further comprising:
receiving, at a second authentication agent of the information handling system, the first confidence information; and
granting the user a second level access to a second secure resource of the information handling system based upon the first confidence information.
19 . A non-transitory computer-readable medium including code for performing a method, the method comprising:
receiving, at a first input device of an information handling system, a first authentication credential;
generating first authentication information based upon the first authentication credential;
receiving, at an authentication engine of the information handling system, the first authentication information;
providing first confidence information based upon the first authentication information;
receiving the first confidence information; and
granting a first level access to a first secure resource of the information handling system based upon the first confidence information.
20 . The computer-readable medium of claim 19 , wherein:
the first authentication information comprises a generated token for the user;
in providing the first confidence information, the method further comprises determining if the generated token matches the authenticated token; and
the first confidence information is provided when the generated token matches the authenticated token.