IP Library Granted Patent US 11,159,525
Granted Patent B2
US 11,159,525 · App. 16/694,372 · Granted Oct 26, 2021

Multi-dimensional framework for defining criteria that indicate when authentication should be revoked

Inventors: Atreedev Banerjee (San Jose, CA); Jillian Cocklin (San Jose, CA)
Assignee: BOKU IDENTITY, INC.
H04L63/0876G06F21/335G06F21/41G06Q20/322H04L9/3268H04L63/08H04L63/0807H04L63/0815H04L63/0823H04L63/0884H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,159,525
App. No.
16/694,372
Granted
Oct 26, 2021
Kind
B2
Abstract

Methods and systems are presented for defining criteria that indicate when authentication for an identified client device should be revoked based on rules associated with interested parties. Authentication information is stored that indicates that an identified client device is authenticated. Rules that are associated with a plurality of interested parties and include rules of different rule types may also be stored. Criteria may be defined based on the rules and the authentication information, the criteria indicating when authentication of the identified client device should be revoked. Authentication of the identified client device may be revoked based on the criteria.

Claims (45)

1. An aggregator system comprising:

a storage system configured to store:

authentication information associated with an identified client device, wherein the authentication information indicates that the client device has been authenticated; and

rules information comprising rules of different rule types, the rules being associated with a plurality of interested parties, including:

a first party having a first rule type and a second rule type associated therewith;

a second party having a third rule type associated therewith; and

a third party having the first rule type and the second rule type associated therewith;

a credentials engine comprising a multi-dimensional framework that defines criteria indicating when authentication of the identified client device should be revoked based on the authentication information and the rules information, wherein the credentials engine is configured to reconcile the rules associated with the plurality of interested parties, including when a conflict exists, including creating:

a first combination including the first party and the second party, wherein the first rule type of the first party prevails for the first combination; and

a second combination including the first party and the third party, wherein the second rule type of the first party is reconciled with the second rule type of the third party for the second combination; and

invalidation circuitry configured to revoke authentication for the identified client device based on the criteria or one of the first combination and the second combination.

2. The system of claim 1 , wherein the plurality of interested parties comprises at least one of a country, a carrier system, a merchant system, a government organization, and a school organization.

3. The system of claim 1 , wherein the authentication information comprises at least one credential.

4. The system of claim 3 , wherein the at least one credential comprises a digital key.

5. The system of claim 1 , wherein each of the rules has a priority associated therewith.

6. The system of claim 5 , wherein the credentials engine is configured to define the criteria based at least in part on the priority associated with each rule.

7. The system of claim 1 , wherein the invalidation circuitry is further configured to revoke authentication for the identified client device based on the criteria being met.

8. The system of claim 7 , wherein the criteria are met upon receiving an event notification which matches at least one predetermined event.

9. The system of claim 7 , wherein the criteria are met when data associated with the authentication matches at least one condition.

10. The system of claim 1 , wherein the rule types comprise at least one of a predetermined time period, a predetermined number of uses, an event identifying the device as lost, an event identifying the device as stolen, an event identifying a deactivated mobile number associated with the client device, an event identifying a fraud alert associated with the client device, a detected change between previously stored hashed information associated with a client device and current hashed information associated with a client device, and any combination thereof.

11. The system of claim 1 , wherein the rule types comprise a rule type which specifies detecting a change of information associated with the client device based at least in part on a comparison of previously stored encrypted information associated with the client device to current encrypted information associated with the client device.

12. The system of claim 1 , wherein the credentials engine is configured to define criteria which comprise one rule of each of the rule types.

13. The system of claim 1 , wherein the criteria comprise a criterion based on a default rule type if the rules do not include a rule of the default rule type.

14. A method comprising:

storing, on a storage device, authentication information associated with an identified client device, wherein the authentication information indicates that the client device has been authenticated;

storing, on a storage device, rules information comprising rules of different rule types, the rules being associated with a plurality of interested parties, including:

a first party having a first rule type and a second rule type associated therewith;

a second party having a third rule type associated therewith; and

a third party having the first rule type and the second rule type associated therewith;

defining, using a credentials engine, criteria that indicate when authentication of the identified client device should be revoked based on the authentication information and the rules information, wherein defining the criteria comprises reconciling the rules associated with the plurality of interested parties when a conflict exists, including creating:

a first combination including the first party and the second party, wherein the first rule type of the first party prevails for the first combination; and

a second combination including the first party and the third party, wherein the second rule type of the first party is reconciled with the second rule type of the third party for the second combination; and

revoking, using invalidation circuitry, authentication for the identified client device based on the criteria or one of the first combination and the second combination.

15. The method of claim 14 , wherein the plurality of interested parties comprises at least one of a country, a carrier system, a merchant system, a government organization, and a school organization.

16. The method of claim 14 , wherein the authentication information comprises at least one credential.

17. The method of claim 16 , wherein the at least one credential comprises a digital key.

18. The method of claim 14 , wherein each of the rules has a priority associated therewith.

19. The method of claim 18 , wherein the criteria are defined based at least in part on the priority associated with each rule.

20. The method of claim 14 , wherein authentication is revoked for the identified client device based on the criteria being met.

21. The method of claim 20 , wherein the criteria are met upon receiving an event notification which matches at least one predetermined event.

22. The method of claim 20 , wherein the criteria are met when a particular data point associated with the credential matches at least one condition.

23. The method of claim 14 , wherein the rule types comprise at least one of a predetermined time period, a predetermined number of uses, an event identifying the device as lost, an event identifying the device as stolen, an event identifying a deactivated mobile number associated with the client device, an event identifying a fraud alert associated with the client device, a detected change between previously stored hashed information associated with a client device and current hashed information associated with a client device, and any combination thereof.

24. The method of claim 14 , wherein the rule types comprise a rule type which specifies detecting a change of information associated with the client device based at least in part on a comparison of previously stored encrypted information associated with the client device to current encrypted information associated with the client device.

25. The method of claim 14 , wherein the criteria comprise one rule of each of the rule types.

26. The method of claim 14 , wherein the criteria comprise a criterion based on a default rule type if the rules do not include a rule of the default rule type.

Assignments (3)
CHANGE OF ADDRESS Recorded Nov 29, 2021
From: BOKU IDENTITY, INC.
To: BOKU IDENTITY, INC.
Reel/Frame 058257/0204 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 19, 2020
From: BANERJEE, ATREEDEV; COCKLIN, JILLIAN
To: DANAL INC.
Reel/Frame 053543/0194 →
MERGER AND CHANGE OF NAME Recorded Aug 19, 2020
From: DANAL, INC.; BOKU IDENTITY, INC.
To: BOKU IDENTITY, INC.
Reel/Frame 053554/0726 →
Continuity (4)
Continuation 15926602 · Mar 20, 2018
Continuation 15250810 · Aug 29, 2016
Continuation 14458058 · Aug 12, 2014
Related Publication 20210029117A1 · Jan 28, 2021