IP Library Granted Patent US 10,148,699
Granted Patent B1
US 10,148,699 · App. 15/682,377 · Granted Dec 4, 2018

Authentication policy orchestration for a user device

Inventors: Nahal Shahidzadeh (Portland, OR); Haitham Akkary (Portland, OR)
H04L63/20H04L63/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,148,699
App. No.
15/682,377
Granted
Dec 4, 2018
Kind
B1
Abstract

A system and method for authentication policy orchestration may include a user device, a client device, and a server. The server may include a network interface configured to be communicatively coupled to a network. The server may further include a processor configured to obtain, from a client device via the network, a transaction request for a transaction, determine an authorization requirement for the transaction request based, at least in part, on a plurality of authorization policies, individual ones of the plurality of authorization policies being separately configurable by at least one of a relying party and an authorizing party, and complete the transaction based on the authorization requirement having been met.

Claims (53)

1. A server comprising:

a network interface configured to be communicatively coupled to a network utilizing a secure communication protocol;

at least one hardware processor of a plurality of hardware processors configured to:

implement authorization policies which are separately configurable between the authorization policies received from a relying party policy engine located on the server and the authorization policies received from an authorizing party policy engine located on at least one of a plurality of authorizing party user devices;

obtain, from a client device via the network, a transaction request for a transaction;

determine an authorization requirement for the transaction request based on the authorization policies as follows:

a first policy of the authorization policies being configurable by the relying party policy engine but not the authorizing policy engine;

a second policy of the authorization policies being configurable by the authorizing policy engine;

a third policy of the authorization policies being configurable by the relying party policy engine or the authorizing policy engine and being based on a predetermined distance of the client device to at least one of the authorizing party user devices; and

a fourth policy of the authorization policies based on a habit of at least one of the authorizing party user devices;

obtain for the relying party policy engine a status of the plurality of the authorizing party user devices;

provide a notification of the transaction and an associated transaction context to at least one of the plurality of authorizing party user devices;

divide the transaction request into subtransaction authorization requests that are separately subject to approval by the plurality of authorizing party user devices;

receive authorization responses for the subtransaction authorization requests from the plurality of authorizing party user devices; and

complete the transaction by approving the transaction based on the authorization requirement having been met.

2. The server of claim 1 , further comprising:

a fifth policy of the authorization policies being configurable by the relying party policy engine or the authorizing policy engine and being based on context of at least one of the plurality of authorizing party user devices.

3. The server of claim 1 , further comprising:

a fifth policy of the authorization policies being configurable by the relying party policy engine or the authorizing policy engine and being based on location of at least one of the plurality of authorizing party user devices.

4. The server of claim 1 , wherein the transaction is at least one of a monetary transaction.

5. The server of claim 1 , wherein the transaction is an attempt to access a physical location.

6. The server of claim 1 , wherein the transaction is an attempt to utilize personal information.

7. The server of claim 1 , wherein the transaction is an attempt to access electronic data.

8. A server comprising:

a network interface configured to be communicatively coupled to a network utilizing a secure communication protocol;

at least one hardware processor of a plurality of hardware processors configured to:

implement authorization policies which are separately configurable between the authorization policies received from a relying party policy engine located on the server and the authorization policies received from an authorizing party policy engine;

obtain, from a client device via the network, a transaction request for a transaction;

determine an authorization requirement for the transaction request based on the authorization policies as follows:

a first policy of the authorization policies being configurable by the relying party policy engine but not the authorizing policy engine;

a second policy of the authorization policies being configurable by the authorizing policy engine;

a third policy of the authorization policies being configurable by the relying party policy engine or the authorizing policy engine and being based on a predetermined distance of the client device to at least one of a plurality of authorizing party user devices;

a fourth policy of the authorization policies based on a habit of at least one of the plurality of authorizing party user devices; and

a fifth policy of the authorization policies based on predetermined criteria regarding the number of approvals and rejections received from the plurality of authorizing party devices;

obtain for the relying party policy engine a status of the plurality of the authorizing party user devices;

provide a notification of the transaction and an associated transaction context to the plurality of authorizing party user devices;

divide the transaction request into subtransaction authorization requests and send them to the plurality of authoring party user devices;

receive responses for the subtransaction authorization requests from at least one of the plurality of authorizing party user devices;

and

complete the transaction by approving the transaction based on the authorization requirement having been met.

9. The server of claim 8 , wherein the predetermined criteria is receipt of the approvals from more than half of the plurality of authorizing party devices.

10. The server of claim 8 , wherein the predetermined criteria receipt of an approval from at least one of the plurality of authorizing party devices.

11. The server of claim 8 , wherein the predetermined criteria is receipt of an approvals from at least one of the plurality of authorizing party devices and no receipt of a rejection.

12. The server of claim 8 , wherein the subtransaction authorization requests are sent in a reverse sequence with the senior authorizing party receiving the substransaction authorization request after approvals have been received from more junior authorizing parties.

13. The server of claim 8 , wherein the predetermined criteria is receipt of an approval from at least one of the plurality of authorizing party devices and a rejection from at least one of the plurality of authorizing party devices.

14. The server of claim 8 , further comprising:

a sixth policy of the authorization policies being configurable by the relying party policy engine or the authorizing policy engine and being based on context of at least one of the plurality of authorizing party user devices.

15. The server of claim 8 , further comprising:

a sixth policy of the authorization policies being configurable by the relying party policy engine or the authorizing policy engine and being based on location of at least one of the plurality of authorizing party user devices.

16. The server of claim 8 , wherein the transaction is at least one of a monetary transaction.

17. The server of claim 8 , wherein the transaction is an attempt to access a physical location.

18. The server of claim 8 , wherein the transaction is an attempt to utilize personal information.

19. The server of claim 8 , wherein the transaction is an attempt to access electronic data.

Assignments (8)
RELEASE OF SECURITY INTEREST Recorded Feb 3, 2025
From: PNC BANK, NATIONAL ASSOCIATION
To: ACCEPTTO CORPORATION
Reel/Frame 070086/0470 →
RELEASE OF SECURITY INTEREST Recorded Aug 14, 2024
From: MIDTOWN MADISON MANAGEMENT LLC (AS SUCCESSOR TO ELM PARK CAPITAL MANAGEMENT, LLC)
To: ACCEPTTO CORPORATION
Reel/Frame 068288/0686 →
SECURITY INTEREST Recorded Aug 12, 2024
From: CLOUDENTITY, INC.; SECUREAUTH CORPORATION
To: WESTERN ALLIANCE BANK
Reel/Frame 068563/0176 →
RELEASE OF SECURITY INTEREST Recorded Aug 12, 2024
From: PNC BANK, NATIONAL ASSOCIATION
To: ACCEPTTO CORPORATION
Reel/Frame 068250/0987 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 2, 2022
From: ACCEPTTO CORPORATION
To: SECUREAUTH CORPORATION
Reel/Frame 059152/0521 →
SECURITY INTEREST Recorded Dec 14, 2021
From: ACCEPTTO CORPORATION
To: ELM PARK CAPITAL MANAGEMENT, LLC
Reel/Frame 058386/0330 →
SECURITY INTEREST Recorded Dec 14, 2021
From: ACCEPTTO CORPORATION
To: PNC BANK, NATIONAL ASSOCIATION
Reel/Frame 058384/0501 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 21, 2017
From: SHAHIDZADEH, NAHAL; AKKARY, HAITHAM
To: ACCEPTTO CORPORATION
Reel/Frame 043348/0843 →
Continuity (4)
Continuation 15243462 · Aug 22, 2016
Continuation 14444865 · Jul 28, 2014
Provisional Application 61870162 · Aug 26, 2013
Provisional Application 61859285 · Jul 28, 2013
Cited By (1)
US 12,217,232