METHOD AND APPARATUS FOR AN IDENTITY ASSURANCE SCORE WITH TIES TO AN ID-LESS AND PASSWORD-LESS AUTHENTICATION SYSTEM
A technique is provided by which a user goes to a site and instead of the authentication system of the site going to their own databases to match an ID and password given by the user, because doing so is not secure, the site companies makes a call to an identity assurance score server (with ties to the ID-less and password-less system) and send a parameter such as a number. Then, based on that parameter (e.g., number or score), the identity assurance score server (with ties to the ID-less and password-less system, such as described hereinabove) sends a corresponding login protocol or factors to be satisfied to authenticate the user.
1 . A computer-implemented method, comprising:
receiving, at an identity assurance server, a first request initiated from a company server for an identity assurance score corresponding to an entity requesting the company server for access to an asset of the company;
generating, in response to the request, the identity assurance score and determining a collection of requirements that the entity must satisfy to access the asset, wherein the collection of requirements are based on a predetermined hierarchy of levels of requirements to be satisfied for the request to be approved and are based on the generated identity assurance score;
transmitting by the identity assurance server for delivery to the company server, the identity assurance score and the collection of requirements for the entity to satisfy;
receiving, at the identity assurance server and originating from the company server, informational data corresponding to the collection of requirements completed by the entity;
confirming, at the identity assurance server, that the received informational data matches data previously saved on a database at the identity assurance server; and
notifying the company that the received information data has been confirmed; wherein one or more steps are performed on at least a processor coupled to at least a memory.
2 . The method of claim 1 , wherein The method of claim 1 , wherein the asset of the company is any of a computer-related account or service or a room or building under control of the company.
3 . The method of claim 1 , wherein the step of generating the identity assurance score comprises generating the identity assurance score based, at least in part, on cumulative informational data associated with the entity that is stored over time and associated with a level from among the predetermined hierarchy of levels.
4 . The method of claim 1 , wherein the requirements of each level in the hierarchy of levels are cumulative, meaning that the identity assurance score causes the requirements for a current level and previous levels to be checked for satisfaction before approving the request.
5 . The method of claim 1 , wherein the identity assurance score for a current level does not have to incorporate requirements of any other level of any other identity assurance score before approving the request.
6 . The method of claim 1 , wherein the generated identity assurance score corresponds to a current level from among the hierarchy of levels, and the step of determining a collection of requirements that the entity must satisfy to access the asset comprises identifying one or more levels of the predetermined hierarchy of levels which are above the current level.
7 . The method of claim 1 , wherein the first request for an identity assurance score is received by the identity assurance server in response to a login event initiated by the entity at a social network identity provider.
8 . The method of claim 1 , wherein the step of determining a collection of requirements that the entity must satisfy to access the asset, comprises determining a plurality of collections of requirements that the user may satisfy to access the asset, wherein the user must satisfy at least one collection of requirements from among the plurality of collections of requirements to access the asset.
9 . The method of claim 1 , wherein the identity assurance server is a social single sign-on (SSO) provider server.
10 . An apparatus, comprising at least one processor operatively connected to at least one computer readable medium having computer executable instructions stored thereon, wherein when executed by the at least one processor, the computer executable instructions perform the following steps:
receiving a first request initiated from a company server for an identity assurance score corresponding to an entity requesting the company server for access to an asset of the company;
generating the identity assurance score and determining a collection of requirements that the entity must satisfy to access the asset, wherein the collection of requirements are based on a predetermined hierarchy of levels of requirements to be satisfied for the request to be approved and are based on the generated identity assurance score;
transmitting, for delivery to the company server, the identity assurance score and the collection of requirements for the entity to satisfy;
receiving, from the company server, informational data corresponding to the collection of requirements completed by the entity;
confirming that the received informational data matches data previously saved on a database at the identity assurance server; and
notifying the company that the received information data has been confirmed.
11 . The apparatus of claim 10 , wherein the asset of the company is any of a computer-related account or service or a room or building under control of the company.
12 . The apparatus of claim 10 , wherein the generating processor is further configured to generate the identity assurance score based, at least in part, on cumulative informational data associated with the entity that is stored over time and associated with a level from among the predetermined hierarchy of levels.
13 . The apparatus of claim 10 , wherein the requirements of each level are cumulative, meaning that the identity assurance score causes the requirements for a current level and previous levels to be checked for satisfaction before approving the request.
14 . The apparatus of claim 10 , wherein the identity assurance score for a current level does not have to incorporate requirements of any other level of any other identity assurance score before approving the request.
15 . The apparatus of claim 10 , wherein the generated identity assurance score corresponds to a current level from among the hierarchy of levels, and the generating processor is further configured to determine the collection of requirements that the entity must satisfy to access the asset by identifying one or more levels of the predetermined hierarchy of levels which are above the current level.
16 . The apparatus of claim 10 , wherein the receiving processor is further configured to receive the first request for an identity assurance score in response to a login event initiated by the entity at a social network identity provider.
17 . The apparatus of claim 10 , wherein the generating processor is further configured to determine a plurality of collections of requirements that the user may satisfy to access the asset, and the collection of requirements that the entity must satisfy to access the assets is at least one of the collections of requirements that the user may satisfy to access the asset from among the plurality of collections of requirements that the user may satisfy to access the asset.
18 . The apparatus of claim 10 , wherein the identity assurance server is a social single sign-on (SSO) provider server.