IP Library Granted Patent US 10,348,769
Granted Patent B1
US 10,348,769 · App. 15/463,600 · Granted Jul 9, 2019

User-portable device and method of use in a user-centric identity management system

Inventor: Gail-Joon Ahn (Phoenix, AZ)
Assignee: OPEN INVENTION NETWORK LLC
H04L63/20G06F21/34G06F21/6245G06F21/6263H04L63/0853H04L63/0876H04L63/102H04L63/105
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,348,769
App. No.
15/463,600
Granted
Jul 9, 2019
Kind
B1
Abstract

A user-portable computing device configured as a smart card enables a user to carry identification information and to generate security tokens for use in authenticating the user to a service provider. The device includes memory for storing user identities as information cards that are exported to a host computer, presented to a user in visual form, and then selected for use in the authentication process. A security token service installed on the device issues a security token in response to a token request sent from the host computer that references the selected user identity. The security token service uses user attribute information stored on the user device to compose the claim assertions needed to issue the security token. The token is returned to the host computer and used to facilitate the authentication process.

Claims (67)

1. A system, comprising:

a security token generator that:

receives a token request in reference to a first user identity of a plurality of first user identities from an identity management module executing on a host computing system, the receipt of the token request responsive to a security policy from a relying party;

generates a security token in accordance with the token request, using at least one user attribute;

retrieves information related to the user attribute to support claim assertions of the security token; and

issues the security token contained in an information card based on the token request, using the information related to the user attribute, the information card presented visually in a graphical user interface as a card-shaped picture.

2. The system of claim 1 , wherein a plurality of information cards are presented visually.

3. The system of claim 2 , wherein the information card is a smart card.

4. The system of claim 2 , wherein at least one of the visually presented information cards is selectable.

5. The system of claim 2 , wherein the information card comprises at least one of:

at least one self-issued card; and

at least one third-party managed card.

6. The system of claim 1 , further comprises:

a service provider environment including at least one identity provider and at least one relying party;

the identity management module executing on a host computing system facilitates online interactions between a user and the service provider environment by managing identity requirements of the interactions; and

a network access connection to enable communications between the identity management module and the service provider environment.

7. The system of claim 6 , wherein the identity management module executing on a host computing system: (i) receives identity requirements from the service provider environment relating to a service request, (ii) identifies, as an eligible identity, any user identity among the plurality of first user identities that satisfies the identity requirements, (iii) generates a token request in reference to an eligible user identity, (iv) sends the token request to the security token generator of the user computing device, and (v) receives the security token issued by the security token generator in response to the token request.

8. The system of claim 6 , wherein the identity management module further:

provides a plurality of second user identities each associated with a respective identity provider;

responsive to a security policy from a relying party, determines whether any user identity satisfies the security policy from among the plurality of first user identities and the plurality of second user identities;

enables the user to make a selection from among the user identities determined to satisfy the security policy;

responsive to a user selection drawn from the plurality of first user identities, provides a token request based on the selected user identity, communicates the token request to the security token generator of the user computing device, and receives the security token generated thereby; and

responsive to a user selection drawn from the plurality of second user identifies, provides a token request based on the selected user identity, communicates the token request to the identity provider associated with the selected user identity, and receives any security token issued by the identity provider occurring in response to the token request.

9. A method, comprising:

a host computing system generating a token request in reference to at least one exported user identity based on an identity management module executing on the host computing system;

a user computing device receiving the token request relative to the at least one exported user identity; and

the user computing device issuing a security token contained in an information card according to the token request and user attribute information associated with the at least one exported user identity, the information card presented visually for selection in a graphical user interface as a card-shaped picture,

wherein a security token generator retrieves a set of user attributes related to the security token and indicative of the first user identity.

10. The method of claim 9 , further comprises:

the host computing system generating a token request based on the selected user identity; and

the host computing system communicating the token request to the user computing device.

11. The method of claim 10 , further comprises:

the user computing device communicating the security token issued in response to the token request to the host computing system; and

the host computing system presenting the security token to the service provider environment in connection with an identification operation.

12. The method of claim 10 , further comprises:

the host computing system receiving from the service provider environment a security policy having requirements, the security policy communicated in connection with a request for service;

the host computing system determining whether the at least one exported user identity satisfies the requirements of the security policy; and

the host computing system presenting the at least one exported user identity determined to satisfy the requirements of the security policy.

13. The method of claim 9 , further comprises:

the user computing device exporting at least one user identity to the host computing system, in response to an import request from the host computing system; and

the host computing system generating further includes generating a token request using the at least one exported user identity.

14. The method of claim 9 , further comprises:

the host computing system receiving from the service provider environment a security policy having requirements, the security policy communicated in connection with a request for service;

the host computing system determining whether the at least one exported user identity satisfies the requirements of the security policy; and

the host computing system generating further includes generating a token relative to a user-selectable one of the at least one exported user identity determined to satisfy the requirements of the security policy.

15. The method of claim 9 , further comprises:

the host computing system receiving from the service provider environment a security policy having requirements, the security policy communicated in connection with a request for service;

the host computing system providing at least one second user identity each associated with a respective identity provider in the identity provider environment;

determining whether any of the at least one exported user identity and the at least one second user identity satisfies the security policy requirements;

the user selecting one of the at least one exported user identity determined to satisfy the security policy requirements;

upon a user selection drawn from the at least one exported user identity, the host computing system generating a token request based on the selected user identity, communicating the token request to the user computing device, and receiving the security token generated thereby; and

upon a user selection drawn from the at least one second user identity, the host computing system generating a token request based on the selected user identity, communicating the token request to the identity provider associated with the selected user identity, and receiving any security token issued by the identity provider occurring in response to the token request.

16. A non-transitory computer-readable medium having computer-executable instructions for execution by a processor, that, when executed, cause the processor to:

receive a token request in reference to a first user identity of a plurality of first user identities from an identity management module executing on a host computing system, the receipt of the token request responsive to a security policy from a relying party;

generate a security token in accordance with the token request, using at least one user attribute;

retrieve information related to the user attribute to support claim assertions of the security token; and

issue the security token in an information card based on the token request, using the information related to the user attribute, the information card presented visually for selection in a graphical user interface as a card-shaped picture.

17. The non-transitory computer-readable medium of claim 16 , wherein the instructions further cause the processor to:

associate each user identity with at least one user attribute located on the medium; and

generate the security token using any user attribute associated with the user identity referenced by the token request.

18. The non-transitory computer-readable medium of claim 16 , wherein the instructions further cause the processor to:

receive a determination specifying whether any of the user identities satisfies requirements of a security policy; and

export any user identity determined to satisfy requirements of the security policy.

19. The non-transitory computer-readable medium of claim 18 , wherein the instructions further cause the processor to:

receive a token request made in connection with user selection of one of the exported user identities; and

generate a security token in accordance with the token request relating to the user identity selection.

20. The non-transitory computer-readable medium of claim 16 , wherein the plurality of user identities are located on the medium.

Assignments (3)
CORRECTIVE ASSIGNMENT TO CORRECT THE EFFECTIVE DATE OF THE PATENT ASSIGNMENT AGREEMENT DATED NOVEMBER 30, 2021 PREVIOUSLY RECORDED AT REEL: 058426 FRAME: 0791. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 14, 2022
From: OPEN INVENTION NETWORK LLC
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 058736/0436 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2021
From: OPEN INVENTION NETWORK LLC
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 058426/0791 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 12, 2021
From: AHN, GAIL-JOON
To: OPEN INVENTION NETWORK LLC
Reel/Frame 057166/0672 →
Continuity (4)
Continuation 14926489 · Oct 29, 2015
Continuation 14315477 · Jun 26, 2014
Continuation 12472512 · May 27, 2009
Provisional Application 61056249 · May 27, 2008