IP Library Granted Patent US 11,032,261
Granted Patent B2
US 11,032,261 · App. 16/263,276 · Granted Jun 8, 2021

Account recovery using identity assurance scoring system

Inventors: Salah E. Machani (Medford, MA); Kevin Bowers (Medford, MA)
Assignee: RSA Security LLC
H04L63/08G06F21/41H04L9/321
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,032,261
App. No.
16/263,276
Granted
Jun 8, 2021
Kind
B2
Abstract

Techniques are provided for account recovery using an identity assurance scoring system. One method comprises providing multiple available identity assurance techniques, each assigned a corresponding identity assurance value indicating a level of assurance for the corresponding available identity assurance technique; in response to a user request to obtain access to a protected resource following a loss incident of a user authenticator: receiving, from the user, authentication information associated with the available identity assurance techniques; aggregating the corresponding assigned identity assurance values for the received available identity assurance techniques to determine an aggregate identity assurance value; determining if the aggregate identity assurance value satisfies a predefined identity assurance level criteria; and evaluating the user request to access the protected resource based on the determining. The corresponding assigned identity assurance value of a given available identity assurance technique is optionally modified based on the available identity assurance techniques that have already been performed.

Claims (43)

1. A method, comprising:

providing a plurality of available identity assurance techniques, wherein the plurality of available identity assurance techniques are assigned respective identity assurance values each indicating a level of assurance for the corresponding available identity assurance technique;

performing the following steps, using at least one processing device, in response to a user request to obtain access to a protected resource following a loss incident of a user authenticator:

receiving, from the user, authentication information associated with at least two selected identity assurance techniques of the plurality of available identity assurance techniques;

determining whether there is an overlap between the received authentication information associated with the at least two selected identity assurance techniques;

modifying the identity assurance value associated with at least one of the selected identity assurance techniques upon determining there is an overlap between the received authentication information;

aggregating the corresponding assigned identity assurance values for each of the at least two selected identity assurance techniques to determine an aggregate identity assurance value;

determining whether the aggregate identity assurance value satisfies a predefined identity assurance level criteria; and

evaluating the user request to access the protected resource based on the determination of whether the aggregate identity assurance value satisfies a predefined identity assurance level criteria.

2. The method of claim 1 , wherein the plurality of available identity assurance techniques comprises one or more of at least one user authenticator technique, at least one user identity verification technique and at least one identity evidence validation technique.

3. The method of claim 1 , wherein the loss incident comprises one or more of loss, theft, damage, replacement and compromise of the user authenticator.

4. The method of claim 1 , wherein the corresponding assigned identity assurance value comprises one or more of a corresponding weight and a corresponding score.

5. The method of claim 1 , wherein the receiving step further comprises the user selecting one or more available identity assurance techniques to perform one or more of user identity proofing and user authentication until the user satisfies the predefined identity assurance level criteria.

6. The method of claim 1 , wherein the receiving, aggregating and determining steps are performed iteratively until the user satisfies the predefined identity assurance level criteria.

7. The method of claim 1 , wherein the predefined identity assurance level criteria is based on an identity assurance value assigned to the user authenticator associated with the loss incident.

8. The method of claim 1 , wherein the user enrolls a selection of the plurality of available identity assurance techniques to be used for recovery after satisfying a specified enrollment authentication assurance level.

9. A system, comprising:

a memory; and

at least one processing device, coupled to the memory, operative to implement the following steps:

providing a plurality of available identity assurance techniques, wherein the plurality of available identity assurance techniques are assigned respective identity assurance values each indicating a level of assurance for the corresponding available identity assurance technique;

performing the following steps, in response to a user request to obtain access to a protected resource following a loss incident of a user authenticator:

receiving, from the user, authentication information associated with at least two selected identity assurance techniques of the plurality of available identity assurance techniques;

determining whether there is an overlap between the received authentication information associated with the at least two selected identity assurance techniques;

modifying the identity assurance value associated with at least one of the selected identity assurance techniques upon determining there is an overlap between the received authentication information;

aggregating the corresponding assigned identity assurance values for each of the at least two selected identity assurance techniques to determine an aggregate identity assurance value;

determining whether the aggregate identity assurance value satisfies a predefined identity assurance level criteria; and

evaluating the user request to access the protected resource based on the determination of whether the aggregate identity assurance value satisfies a predefined identity assurance level criteria.

10. The system of claim 9 , wherein the receiving step further comprises the user selecting one or more plurality of the available identity assurance techniques to perform one or more of user identity proofing and user authentication until the user satisfies the predefined identity assurance level criteria.

11. The system of claim 9 , wherein the receiving, aggregating and determining steps are performed iteratively until the user satisfies the predefined identity assurance level criteria.

12. The system of claim 9 , wherein the predefined identity assurance level criteria is based on an identity assurance value assigned to the user authenticator associated with the loss incident.

13. The system of claim 9 , wherein the user enrolls a selection of the plurality of available identity assurance techniques to be used for recovery after satisfying a specified enrollment authentication assurance level.

14. A computer program product, comprising a non-transitory tangible machine-readable storage medium having encoded therein executable code of one or more software programs, wherein the one or more software programs when executed by at least one processing device perform the following steps:

providing a plurality of available identity assurance techniques, wherein the plurality of available identity assurance techniques are assigned respective identity assurance values each indicating a level of assurance for the corresponding available identity assurance technique;

performing the following steps, in response to a user request to obtain access to a protected resource following a loss incident of a user authenticator:

receiving, from the user, authentication information associated with at least two selected identity assurance techniques of the plurality of available identity assurance techniques;

determining whether there is an overlap between the received authentication information associated with the at least two selected identity assurance techniques;

modifying the identity assurance value associated with at least one of the selected identity assurance techniques upon determining there is an overlap between the received authentication information;

aggregating the corresponding assigned identity assurance values for each of the at least two selected identity assurance techniques to determine an aggregate identity assurance value;

determining whether the aggregate identity assurance value satisfies a predefined identity assurance level criteria; and

evaluating the user request to access the protected resource based on the determination of whether the aggregate identity assurance value satisfies a predefined identity assurance level criteria.

15. The computer program product of claim 14 , wherein the receiving step further comprises the user selecting one or more available identity assurance techniques to perform one or more of user identity proofing and user authentication until the user satisfies the predefined identity assurance level criteria.

16. The computer program product of claim 14 , wherein the receiving, aggregating and determining steps are performed iteratively until the user satisfies the predefined identity assurance level criteria.

17. The computer program product of claim 14 , wherein the predefined identity assurance level criteria is based on an identity assurance value assigned to the user authenticator associated with the loss incident.

Assignments (16)
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 70587/0885 Recorded Mar 5, 2026
From: JPMORGAN CHASE BANK, N.A.
To: RSA SECURITY LLC; RSA SECURITY USA LLC
Reel/Frame 075031/0394 →
RELEASE OF SECURITY INTEREST RECORDED AT REEL/FRAME 56098/0534 Recorded Mar 5, 2026
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: RSA SECURITY LLC
Reel/Frame 075041/0175 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Mar 21, 2025
From: RSA SECURITY LLC; RSA SECURITY USA LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 070587/0885 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY LLC
Reel/Frame 069762/0401 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2024
From: RSA SECURITY LLC
To: RSA SECURITY USA, LLC
Reel/Frame 069762/0529 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 056098/0534 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 054155, FRAME 0815 Recorded Apr 29, 2021
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056104/0841 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 053666, FRAME 0767 Recorded Apr 29, 2021
From: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056095/0574 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 7, 2020
From: EMC IP HOLDING COMPANY LLC
To: RSA SECURITY LLC
Reel/Frame 053717/0020 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054191/0287 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (049452/0223) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054250/0372 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: JEFFERIES FINANCE LLC
Reel/Frame 053666/0767 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 054155/0815 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 31, 2019
From: MACHANI, SALAH E.; BOWERS, KEVIN
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 048203/0264 →