IP Library Granted Patent US 10,110,584
Granted Patent B1
US 10,110,584 · App. 15/266,096 · Granted Oct 23, 2018

Elevating trust in user identity during RESTful authentication and authorization

Inventors: Timothy Schmoyer (Harvard, MA); Michael Dufel (Boulder, CO); David Staggs (Austin, TX); Vijayababu Subramanium (Columbia, SC)
Assignee: JERICHO SYSTEMS CORPORATION
H04L63/08H04L63/0428H04L63/10H04L63/20H04L67/42
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,110,584
App. No.
15/266,096
Granted
Oct 23, 2018
Kind
B1
Abstract

Credentials sent over a back channel during the authentication of a user to a RESTful service can elevate the trust the recipient system can place in the user's identity. The addition of an identity credential of higher strength can increase confidence in user identities electronically presented with a lower strength credential. Attributes from either credential can be used to determine authorization to a protected resource.

Claims (29)

1. A computer-implemented method for authorizing an entity to access a protected resource, said method comprising:

receiving at a RESTful service implemented at a first server having a first processor and first memory a request by the entity to access the protected resource;

providing an indication of the request to a relying party implemented at a second server having a second processor and second memory that facilitates entity authentication;

receiving, at the RESTful service, a first credential transmitted upon a front channel;

receiving, at the RESTful service, a second credential comprising a SAML credential transmitted upon a back channel;

authenticating the entity based upon the first and second credentials, respectively; and

authorizing the entity, once authenticated, to access the protected resource based upon attributes contained in the SAML credential that comprises the second credential.

2. The method of claim 1 wherein said authenticating comprises authenticating the entity based upon credential strengths of the first and second credentials.

3. The method of claim 1 wherein said providing the indication comprises redirecting the request to the relying party.

4. The method of claim 1 further comprising storing the first credential and the second credential at the relying party.

5. The method of claim 4 wherein said receiving the first credential comprises receiving the first credential from the relying party.

6. The method of claim 4 wherein said receiving the second credential comprises receiving the second credential from the relying party.

7. The method of claim 1 wherein the second credential transmitted upon the back channel is transmitted in encrypted form.

8. The method of claim 1 wherein the first credential comprises a CAS credential.

9. A computer-implemented system for authorizing an entity to access a protected resource, said system comprising:

a RESTful service implemented at a first server having a first processor and first memory and operable to:

receive a request by the entity to access the protected resource;

provide an indication of the request to a relying party implemented at a second server having a second processor and second memory that facilitates entity authentication;

receive a first credential transmitted upon a front channel;

receive a second credential comprising a SAML credential transmitted upon a back channel;

authenticate the entity based upon the first and second credentials, respectively; and

authorize the entity to access the protected resource based upon attributes contained in the SAML credential that comprises the second credential.

10. The system of claim 9 wherein said RESTful service is operable to authenticate the entity based upon credential strengths of the first and second credentials.

11. The system of claim 9 wherein said RESTful service is operable to provide the indication by redirecting the request to the relying party.

12. The system of claim 9 wherein said RESTful service is further operable to store the first credential and the second credential at the relying party.

13. The system of claim 12 wherein said RESTful service is operable to receive the first credential from the relying party.

14. The system of claim 12 wherein said RESTful service is operable to receive the second credential from the relying party.

15. The system of claim 9 wherein the second credential transmitted upon the back channel is transmitted in encrypted form.

16. The system of claim 9 wherein the first credential comprises a CAS credential.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 6, 2021
From: BIN 2020, SERIES 550 ALLIED SECURITY TRUST I
To: CROWDSTRIKE, INC.
Reel/Frame 058310/0455 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 3, 2020
From: JERICHO SYSTEMS CORPORATION
To: BIN 2020, SERIES 550 OF ALLIED SECURITY TRUST I
Reel/Frame 052831/0119 →
Continuity (3)
Continuation 14506825 · Oct 6, 2014
Continuation 13844622 · Mar 15, 2013
Provisional Application 61691248 · Aug 20, 2012
Cited By (3)
US 12,294,573 US 12,323,414 US 12,375,489