IP Library › Granted Patent US 9,544,314
Granted Patent B2
US 9,544,314 · App. 15/165,436 · Granted Jan 10, 2017

Method for managing access to protected computer resources

Inventors: Richard L. Gregg (Elkhorn, NE); Sandeep Giri (San Francisco, CA); Timothy C. Goeke (Elkhorn, NE)
Assignee: PRISM TECHNOLOGIES LLC
H04L63/10G06F2221/2101
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,544,314
App. No.
15/165,436
Granted
Jan 10, 2017
Kind
B2
Abstract

A system for securing and tracking usage of transaction services or computer resources by a client computer from a first server computer, which includes clearinghouse means for storing identity data of the first server computer and the client computer(s); server software means and client software means adapted to forward its identity data and identity data of the client computer(s) to the clearinghouse means at the beginning of an operating session; and a hardware key connected to the client computer, the key being adapted to generate a digital identification as part of the identity data; wherein the hardware key is implemented using a hardware token access system, a magnetic card access system, a smart card access system, a biometric identification access system or a central processing unit with a unique embedded digital identification.

Claims (84)

1. A method for controlling access to selected computer resources using at least one of a transmission control protocol and a user datagram protocol, the method comprising:

provisioning, with at least one associated database of at least one authentication server, identity data associated with at least one client computer device;

storing, by the at least one authentication server in the at least one associated database, the identity data associated with the at least one client computer device;

receiving, by at least one access server from the at least one client computer device, (i) the identity data associated with the at least one client computer device, and (ii) a request for the selected computer resources by the at least one client computer device;

forwarding, by the at least one access server to the at least one authentication server, the identity data associated with the at least one client computer device and the request for the selected computer resources by the at least one client computer device;

authenticating, by the at least one authentication server, the identity data associated with the at least one client computer device in response to the request for the selected computer resources by the at least one client computer device;

authorizing, by at least one server associated with the at least one authentication server, the at least one client computer device to receive at least a portion of the selected computer resources; and

permitting access, by the at least one authentication server, to the at least a portion of the selected computer resources (i) upon successfully authenticating the identity data associated with the at least one client computer device, and (ii) upon successfully authorizing the at least one client computer device.

2. The method of claim 1 , further comprising acquiring, by another at least one server associated with the at least one authentication server, usage data associated with the at least a portion of the selected computer resources provided to the at least one client computer device.

3. The method of claim 1 , further comprising storing, by the at least one server associated with the at least one authentication server in the at least one associated database, authorization data associated with the selected computer resources.

4. The method of claim 1 , further comprising storing, by the at least one server associated with the at least one authentication server, in another at least one associated database, authorization data associated with the selected computer resources.

5. The method of claim 1 , further comprising storing, by the at least one authentication server in another at least one associated database, the identity data associated with the at least one client computer device.

6. The method of claim 1 , further comprising forwarding, by the at least one access server to the at least one client computer device, an acknowledgement of the request for selected computer resources of the at least one client computer device.

7. The method of claim 1 , further comprising operating the at least one authentication server on a single computer with the at least one access server.

8. The method of claim 1 , further comprising operating the at least one authentication server and the at least one server associated with the authentication server on a single computer with the at least one access server.

9. The method of claim 1 , further comprising operating the at least one authentication server on a different computer than the at least one access server.

10. The method of claim 1 , further comprising operating the at least one server associated with the authentication server on a different computer than the at least one access server.

11. The method of claim 1 , further comprising operating the at least one authentication server and the at least one server associated with the authentication server on a different computer than the at least one access server.

12. The method of claim 1 , further comprising performing at least one of the functions of the at least one authentication server by another at least one server associated with the at least one authentication server.

13. The method of claim 1 , wherein the at least a portion of the selected computer resources is encrypted.

14. The method of claim 1 , further comprising authenticating, by the at least one authentication server, the at least one access server.

15. The method of claim 1 , further comprising receiving, by the at least one server associated with the at least one authentication server, a request for authorization data from the at least one client computer device.

16. The method of claim 1 , wherein the at least one server associated with the at least one authentication server is adapted to assign one of a plurality of authorization levels to the at least a portion of the selected computer resources.

17. The method of claim 1 , further comprising re-authenticating, by the at least one authentication server, the identity data associated with the at least one client computer device.

18. The method of claim 1 , further comprising re-authorizing by the at least one server associated with the at least one authentication server, the at least one client computer device to receive the at least a portion of the selected computer resources.

19. The method of claim 1 , further comprising authenticating, by the at least one client computer device, the at least one access server.

20. The method of claim 1 , wherein the identity data associated with the at least one client computer device is a unique identifier.

21. The method of claim 1 , further comprising receiving, at the at least one authentication server, the identity data associated with the at least one client computer device read from a digital certificate.

22. The method of claim 1 , further comprising receiving, at the at least one authentication server, the identity data associated with the at least one client computer device derived from a digital certificate.

23. The method of claim 1 , further comprising receiving, by the at least one authentication server, a request for an authentication server network address from the at least one client computer device.

24. The method of claim 23 , further comprising sending, by the at least one authentication server, the authentication server network address in response to the request for an authentication server network address from the at least one client computer device.

25. The method of claim 1 , further comprising encapsulating the at least one of a transmission control protocol and a user datagram protocol in at least another protocol.

26. The method of claim 1 , wherein the at least a portion of the selected computer resources is an IP address, and the IP address affords Internet access.

27. A method for controlling access to selected computer resources using at least one of a transmission control protocol and a user datagram protocol, the method comprising:

receiving, by at least one access server from at least one client computer device, (i) identity data associated with the at least one client computer device, and (ii) a request for the selected computer resources by the at least one client computer device;

forwarding, by the at least one access server to at least one authentication server, the identity data associated with the at least one client computer device and the request for the selected computer resources;

authenticating, by the at least one authentication server, the identity data associated with the at least one client computer device in response to the request for the selected computer resources;

authorizing, by at least one server associated with the at least one authentication server, the at least one client computer device to receive at least a portion of the selected computer resources;

controlling access, by the at least one authentication server, to the at least a portion of the selected computer resources (i) upon successfully authenticating the identity data associated with the at least one client computer device, and (ii) upon successfully authorizing the at least one client computer device.

28. The method of claim 27 , further comprising acquiring, by another at least one server associated with the at least one authentication server, usage data associated with the at least a portion of the selected computer resources provided to the at least one client computer device.

29. The method of claim 27 , further comprising storing, by the at least one authentication server in at least one associated database, the identity data associated with the at least one client computer device.

30. The method of claim 29 , further comprising storing, by the at least one server associated with the at least one authentication server in the at least one associated database, authorization data associated with the selected computer resources.

31. The method of claim 29 , further comprising storing, by the at least one server associated with the at least one authentication server in another at least one associated database, authorization data associated with the selected computer resources.

32. The method of claim 29 , further comprising storing, by the at least one authentication server in another at least one associated database, the identity data associated with the at least one client computer device.

33. The method of claim 27 , further comprising storing, by the at least one server associated with the at least one authentication server in at least one associated database, authorization data associated with the selected computer resources.

34. The method of claim 27 , further comprising forwarding, by the at least one access server to the at least one client computer device, an acknowledgement of the request for selected computer resources of the at least one client computer device.

35. The method of claim 27 , further comprising operating the at least one authentication server on a single computer with the at least one access server.

36. The method of claim 27 , further comprising operating the at least one authentication server and the at least one server associated with the authentication server on a single computer with the at least one access server.

37. The method of claim 27 , further comprising operating the at least one authentication server on a different computer than the at least one access server.

38. The method of claim 27 , further comprising operating the at least one server associated with the authentication server on a different computer than the at least one access server.

39. The method of claim 27 , further comprising operating the at least one authentication server and the at least one server associated with the authentication server on a different computer than the at least one access server.

40. The method of claim 27 , further comprising performing at least one of the functions of the at least one authentication server by another at least one server associated with the at least one authentication server.

41. The method of claim 27 , wherein the at least a portion of the selected computer resources is encrypted.

42. The method of claim 27 , further comprising authenticating, by the at least one authentication server, the at least one access server.

43. The method of claim 27 , further comprising receiving, by the at least one server associated with the at least one authentication server, a request for authorization data from the at least one client computer device.

44. The method of claim 27 , wherein the at least one server associated with the at least one authentication server is adapted to assign one of a plurality of authorization levels to the at least a portion of the selected computer resources.

45. The method of claim 27 , further comprising re-authenticating, by the at least one authentication server, the identity data associated with the at least one client computer device.

46. The method of claim 27 , further comprising re-authorizing by the at least one server associated with the at least one authentication server, the at least one client computer device to receive the at least a portion of the selected computer resources.

47. The method of claim 27 , further comprising authenticating, by the at least one client computer device, the at least one access server.

48. The method of claim 27 , wherein the identity data associated with the at least one client computer device is a unique identifier.

49. The method of claim 27 , further comprising receiving, at the at least one authentication server, the identity data associated with the at least one client computer device derived from a digital certificate.

50. The method of claim 27 , further comprising receiving, at the at least one authentication server, the identity data associated with the at least one client computer device read from a digital certificate.

51. The method of claim 27 , further comprising receiving, by the at least one authentication server, a request for an authentication server network address from the at least one client computer device.

52. The method of claim 51 , further comprising sending, by the at least one authentication server, the authentication server network address in response to the request for an authentication server network address from the at least one client computer device.

53. The method of claim 27 , further comprising encapsulating the at least one of a transmission control protocol and a user datagram protocol in at least another protocol.

54. The method of claim 27 , wherein the at least a portion of the selected computer resources is an IP address, and the IP address affords Internet access.

55. A method for controlling access to selected computer resources using at least one of a transmission control protocol and a user datagram protocol, the method comprising:

receiving, by at least one access server from at least one client computer device, identity data associated with the at least one client computer device;

receiving, by the at least one access server from the at least one client computer device, a request for the selected computer resources by the at least one client computer device;

forwarding, by the at least one access server to at least one authentication server, the identity data associated with the at least one client computer device and the request for the selected computer resources;

authenticating, by the at least one authentication server, the identity data associated with the at least one client computer device in response to the request for the selected computer resources;

authorizing, by at least one server associated with the at least one authentication server, the at least one client computer device to receive at least a portion of the selected computer resources;

permitting access, by the at least one authentication server, to the at least a portion of the selected computer resources (i) upon successfully authenticating the identity data associated with the at least one client computer device, and (ii) upon successfully authorizing the at least one client computer device.

56. The method of claim 55 , wherein the at least a portion of the selected computer resources is an IP address, and the IP address permits Internet access.

57. A method for controlling access to selected computer resources using at least one of a transmission control protocol and a user datagram protocol, the method comprising:

encapsulating the at least one of a transmission control protocol and a user datagram protocol in at least another protocol;

receiving, by at least one access server from at least one client computer device, (i) identity data associated with the at least one client computer device, and (ii) a request for the selected computer resources by the at least one client computer device;

forwarding, by the at least one access server to at least one authentication server, the identity data associated with the at least one client computer device and the request for the selected computer resources;

authenticating, by the at least one authentication server, the identity data associated with the at least one client computer device in response to the request for the selected computer resources;

receiving, by at least one server associated with the at least one authentication server, a request for authorization data from the at least one client computer device;

authorizing, by the at least one server associated with the at least one authentication server, the at least one client computer device to receive at least a portion of the selected computer resources;

permitting access, by the at least one authentication server, to the at least a portion of the selected computer resources upon (i) successfully authenticating the identity data associated with the at least one client computer device, and (ii) successfully authorizing the at least one client computer device;

re-authorizing by the at least one server associated with the at least one authentication server, the at least one client computer device to receive a portion of the selected computer resources; and

acquiring, by another at least one server associated with the at least one authentication server, usage data associated with the at least a portion of the selected computer resources provided to the at least one client computer device.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 26, 2016
From: GREGG, RICHARD L.
To: PRISM RESOURCES
Reel/Frame 038729/0171 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 26, 2016
From: PRISM RESOURCES
To: PRISM TECHNOLOGIES LLC
Reel/Frame 038729/0190 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 26, 2016
From: GIRI, SANDEEP; GOEKE, TIMOTHY C.
To: PRISM TECHNOLOGIES LLC
Reel/Frame 038729/0216 →
Continuity (7)
Continuation 14549943 · Nov 21, 2014
Continuation 13752036 · Jan 28, 2013
Continuation 12944473 · Nov 11, 2010
Continuation 11978919 · Oct 30, 2007
Continuation 10230638 · Aug 29, 2002
Continuation In Part 08872710 · Jun 11, 1997
Related Publication 20160277398A1 · Sep 22, 2016