IP Library Granted Patent US 12,647,411
Granted Patent B2
US 12,647,411 · App. 18/224,989 · Granted Jun 2, 2026

Authentication orchestration system

Inventors: Xiangfei Dong (Cupertino, CA); Robert Ellis Lee (Bellevue, WA)
Assignee: SNAP INC.
H04L63/0838H04L63/0861H04L63/105
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,647,411
App. No.
18/224,989
Granted
Jun 2, 2026
Kind
B2
Abstract

Systems, methods, and computer readable media for an authentication orchestration system. Example methods include receiving, from an authentication client, an authentication request, the authentication request comprising an indication of an account and an indication of a goal authentication level. The method further includes accessing a current authentication level and adjusting, based on a risk level, the goal authentication level to an adjusted goal authentication level. The method further includes selecting a challenge method of a plurality of challenge methods based on a difference between the adjusted goal authentication level and the current authentication level. The method further includes performing the selected challenge method with a user associated with the account, and causing to be sent, to the authentication client, an indication of whether the adjusted authentication level was achieved.

Claims (54)

1 . An apparatus of a computing device comprising:

one or more processors; and

a memory storing instructions that, when executed by the one or more processors, configure the one or more processors to perform operations comprising:

receiving, from an authentication client over a computer network, an authentication request, the authentication request comprising an indication of an account associated with a user and an indication of a goal authentication level for an assurance type;

accessing a current authentication level for the assurance type;

adjusting, based on a risk level, the goal authentication level to an adjusted goal authentication level;

selecting a challenge method of a plurality of challenge methods based on a difference between the adjusted goal authentication level for the assurance type and the current authentication level for the assurance type, the selected challenge method having different values for different assurance types, wherein the different assurance types comprise at least a certainty that a run-time environment the user is using has not been tampered with or a level of certainty that the user is not an automated application;

performing, over a computer network, the selected challenge method with the user associated with the account; and

causing to be sent, to the authentication client, an indication of whether the adjusted authentication level was achieved.

2 . The apparatus of claim 1 , wherein the selected challenge method is associated with an authentication value, and wherein the operations further comprise:

causing to be sent an indication of the authentication value.

3 . The apparatus of claim 1 , wherein the operations further comprise:

determining the risk level based on a number of authentication requests received from the authentication client for the account.

4 . The apparatus of claim 3 , wherein the risk level is determined based further on previous changes to the account.

5 . The apparatus of claim 1 , wherein the operations further comprise:

determining the risk level based on risk information regarding other accounts.

6 . The apparatus of claim 1 , wherein the authentication request further comprises the current authentication level.

7 . The apparatus of claim 1 , wherein the operations further comprise:

in response to the user associated with the account failing the selected challenge method, selecting another challenge method, and performing the another challenge method.

8 . The apparatus of claim 1 , wherein the operations further comprise:

causing to be displayed on a display associated with the user of the account, a list of available challenge methods, and wherein the selecting is further based on a received selection of the list of available challenge methods.

9 . The apparatus of claim 1 , wherein the operations further comprise:

accessing information associated with the user, the information indicating computing devices associated with the user, and wherein the selecting is further based on the computing devices associated with the user.

10 . The apparatus of claim 1 , wherein the operations further comprise:

determining whether the adjusted goal authentication level can be achieved; and

in response to determining the adjusted goal authentication level cannot be achieved, sending an indication that the adjusted goal authentication level cannot be achieved to the authentication client.

11 . The apparatus of claim 1 , wherein the plurality of challenge methods comprises one or more of: sending a code using a short message service, querying the user for a shared secret, calling a telephone number associated with the account, sending a code in an email associated with the account, and capturing biometric data of the user.

12 . The apparatus of claim 1 , wherein the computing device is a first computing device, and wherein the receiving further comprises:

receiving, from the authentication client on a second computing device, the authentication request, the authentication request comprising the indication of the account and the indication of the goal authentication level.

13 . The apparatus of claim 1 , wherein the authentication request comprises a session identification, and wherein the operations further comprise:

generating a transaction identification; and

associating the transaction identification with the session identification and the authentication request.

14 . The apparatus of claim 1 , wherein the selecting is based on a convenience to the user.

15 . The apparatus of claim 1 , wherein the operations further comprise:

determining, based at least on a user device of the user, a plurality of challenge methods available to the user.

16 . The apparatus of claim 1 , wherein the goal authentication level, the current authentication level, and the different values for different assurance types are integer values.

17 . A non-transitory computer-readable storage medium including instructions that, when processed by one or more processors, configure the one or more processors to perform operations comprising:

receiving, from an authentication client over a computer network, an authentication request, the authentication request comprising an indication of an account associated with a user and an indication of a goal authentication level for an assurance type;

accessing a current authentication level for the assurance type;

adjusting, based on a risk level, the goal authentication level to an adjusted goal authentication level;

selecting a challenge method of a plurality of challenge methods based on a difference between the adjusted goal authentication level for the assurance type and the current authentication level for the assurance type, the selected challenge method having different values for different assurance types, wherein the different assurance types comprise at least a certainty that a run-time environment the user is using has not been tampered with or a level of certainty that the user is not an automated application;

performing, over a computer network, the selected challenge method with the user associated with the account; and

causing to be sent, to the authentication client, an indication of whether the adjusted authentication level was achieved.

18 . The non-transitory computer-readable storage medium of claim 17 , wherein the selected challenge method is associated with an authentication value, and wherein the operations further comprise:

causing to be sent an indication of the authentication value.

19 . The non-transitory computer-readable storage medium of claim 17 , wherein the operations further comprise:

determining the risk level based on a number of authentication requests received from the authentication client for the account.

20 . A method performed on an apparatus of a computing device, the method comprising:

receiving, from an authentication client over a computer network, an authentication request, the authentication request comprising an indication of an account associated with a user and an indication of a goal authentication level for an assurance type;

accessing a current authentication level for the assurance type;

adjusting, based on a risk level, the goal authentication level to an adjusted goal authentication level;

selecting a challenge method of a plurality of challenge methods based on a difference between the adjusted goal authentication level for the assurance type and the current authentication level for the assurance type, the selected challenge method having different values for different assurance types, wherein the different assurance types comprise at least a certainty that a run-time environment the user is using has not been tampered with or a level of certainty that the user is not an automated application;

performing, over a computer network, the selected challenge method with the user associated with the account; and

causing to be sent, to the authentication client, an indication of whether the adjusted authentication level was achieved.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 21, 2023
From: DONG, XIANGFEI; LEE, ROBERT ELLIS
To: SNAP INC.
Reel/Frame 064344/0483 →
Continuity (1)
Related Publication 20250030681A1 · Jan 23, 2025
References Cited (14)
US 9485237B1 · Johansson · 2016 [cited by examiner]
US 11233788B1 · Hitchcock · 2022 [cited by examiner]
US 20110225625A1 · Wolfson · 2011 [cited by examiner]
US 20160087957A1 · Shah · 2016 [cited by examiner]
US 20160335639A1 · Merz · 2016 [cited by examiner]
US 20210297422A1 · McDorman · 2021 [cited by examiner]
US 20210409405A1 · Salajegheh · 2021 [cited by examiner]
US 20220222371A1 · Liu · 2022 [cited by examiner]
US 20220277070A1 · Robert Jose · 2022 [cited by examiner]
US 20240137342A1 · Akkapeddi · 2024 [cited by examiner]
CN 111552942 · 2020 [cited by applicant]
JP 2003006161A · 2003 [cited by examiner]
“International Application Serial No. PCT/US2024/038498, International Search Report mailed Sep. 17, 2024”, 4 pgs. [cited by applicant]
“International Application Serial No. PCT/US2024/038498, Written Opinion mailed Sep. 17, 2024”, 7 pgs. [cited by applicant]