IP Library Granted Patent US 12,143,396
Granted Patent B2
US 12,143,396 · App. 17/211,981 · Granted Nov 12, 2024

Injecting risk assessment in user authentication

Inventors: Moshe Kagan (Petach Tikva, IL); Scott Matthew Andrews (Ashmore, AU)
Assignee: International Business Machines Corporation
H04L63/105H04L63/0807H04L63/0815H04L63/083H04L63/0876H04L63/0884H04L63/102H04L2463/082
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,143,396
App. No.
17/211,981
Granted
Nov 12, 2024
Kind
B2
Abstract

In a method for authenticating a user, a processor receives a login request for an application. A processor directs the login request to a collection page. The collection page may include an authentication script. A processor receives a risk assessment based on an identity authenticated through the authentication script. A processor grants a level of access to the application based on the risk assessment.

Claims (44)

1. A computer-implemented method for authenticating a user, comprising:

receiving a login request for an application, wherein the application controls access only to a protected resource remote from a user, without an ability to control access to resources that are not the protected resource;

selecting a collection page from a plurality of collection pages stored on a server and customized to particular applications, wherein the collection page is selected based on the application for which the login request is received;

directing the login request to the collection page, wherein the collection page comprises an authentication script requesting log-in information that the application does not collect;

receiving a risk assessment based on an identity authenticated through the authentication script; and

granting a level of access to the application based on the risk assessment.

2. The method of claim 1 , wherein the login request comprises a selection from the group consisting of: (i) a username and password, (ii) a single sign on (SSO) authentication scheme, and (iii) a Kerberos-enabled authentication scheme.

3. The method of claim 1 , wherein the login request comprises information identifying the application.

4. The method of claim 1 , comprising selecting between the plurality of collection pages based on a selection from the group consisting of: a user identity, a client device, and the application.

5. The method of claim 1 , wherein the authentication script collects a user variable comprising a selection from the group consisting of: a hashed username, a user IP address, a user agent, and a browser.

6. The method of claim 1 , wherein the risk assessment is received from a backend server comprising an opaque, non-personally identifiable profile associated with the identity.

7. The method of claim 1 , wherein the level of access comprises a selection from the group consisting of: allowing the user to access the application, denying access to the application, and requesting a multi-factor authentication.

8. The method of claim 1 , comprising determining a primary risk level based on the login request.

9. A computer program product for authenticating a user, the computer program product comprising:

one or more computer-readable storage media and program instructions stored on the one or more computer-readable storage media, the program instructions comprising:

program instructions to receive a login request for an application, wherein the application controls access only to a protected resource remote from a user, without an ability to control access to resources that are not the protected resource;

program instructions to select a collection page from a plurality of collection pages stored on a server and customized to particular applications, wherein the collection page is selected based on the application for which the login request is received;

program instructions to direct the login request to the collection page, wherein the collection page comprises an authentication script requesting log-in information that the application does not collect;

program instructions to receive a risk assessment based on an identity authenticated through the authentication script; and

program instructions to grant a level of access to the application based on the risk assessment.

10. The computer program product of claim 9 , wherein the login request comprises a selection from the group consisting of: (i) a username and password, (ii) a single sign on (SSO) authentication scheme, and (iii) a Kerberos-enabled authentication scheme.

11. The computer program product of claim 9 , wherein the login request comprises information identifying the application.

12. The computer program product of claim 9 , wherein the authentication script comprises a code snippet for authenticating a device fingerprint.

13. The computer program product of claim 9 , wherein the authentication script collects a user variable comprising a selection from the group consisting of: a hashed username, a user IP address, a user agent, and a browser.

14. The computer program product of claim 9 , wherein the risk assessment is received from a backend server comprising an opaque, non-personally identifiable user profile associated with the identity.

15. The computer program product of claim 9 , wherein the level of access comprises a selection from the group consisting of: allowing the user to access the application, denying access to the application, and requesting a multi-factor authentication.

16. A computer system for authenticating a user, the computer system comprising:

one or more computer processors, one or more computer-readable storage media, and program instructions stored on the computer-readable storage media for execution by at least one of the one or more processors, the program instructions comprising program instruction to:

program instructions to receive a login request for an application, wherein the application controls access only to a protected resource remote from a user, without an ability to control access to resources that are not the protected resource;

program instructions to select a collection page from a plurality of collection pages stored on a server and customized to particular applications, wherein the collection page is selected based on the application for which the login request is received;

program instructions to direct the login request to the collection page, wherein the collection page comprises an authentication script requesting log-in information that the application does not collect;

program instructions to receive a risk assessment based on an identity authenticated through the authentication script; and

program instructions to grant a level of access to the application based on the risk assessment.

17. The computer system of claim 16 , wherein the login request comprises a selection from the group consisting of: (i) a username and password, (ii) a single sign on (SSO) authentication scheme, and (iii) a Kerberos-enabled authentication scheme.

18. The computer system of claim 16 , wherein the login request comprises information identifying the application.

19. The computer system of claim 16 , wherein the authentication script comprises a code snippet for authenticating a device fingerprint.

20. The computer system of claim 16 , wherein the risk assessment is received from a backend server comprising an opaque, non-personally identifiable user profile associated with the identity.

21. The system of claim 16 , wherein the level of access comprises a selection from the group consisting of: allowing the user to access the application, denying access to the application, and requesting a multi-factor authentication.

22. A computer-implemented method for authenticating a user, comprising:

inserting a proxy into a login procedure for an application configured to only access a protected resource, wherein the proxy (i) selects a collection page from a plurality of collection pages stored on a server and customized to particular applications, wherein the selection is based on the application using the login procedure, and (ii) accesses the collection page comprising an authentication script requesting log-in information that the application does not collect;

conducting a risk assessment based on identity information collected on a client device running the application;

granting a level of access to the application based on the risk assessment.

23. The method of claim 22 , wherein the level of access comprises a selection from the group consisting of: allowing the user to access the application, denying access to the application, and requesting a multi-factor authentication.

24. The method of claim 22 , comprising selecting between the plurality of collection pages based on a selection from the group consisting of: a user identity, a client device, and the application.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 25, 2021
From: KAGAN, MOSHE; ANDREWS, SCOTT MATTHEW
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 055711/0834 →
Continuity (1)
Related Publication 20220311776A1 · Sep 29, 2022