IP Library › Granted Patent US 9,294,452
Granted Patent B1
US 9,294,452 · App. 13/706,254 · Granted Mar 22, 2016

Authentication translation

Inventor: Bjorn Markus Jakobsson (Mountain View, CA)
Assignee: RightQuestion, LLC
H04L63/08H04L63/0815H04L63/0823H04L63/0861H04L63/0869
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,294,452
App. No.
13/706,254
Granted
Mar 22, 2016
Kind
B1
Abstract

Authentication translation is disclosed. A request to access a resource is received at an authentication translator, as is an authentication input. The authentication input corresponds to at least one stored record. The stored record is associated at least with the resource. In response to the receiving, a previously stored credential associated with the resource is accessed. The credential is provided to the resource.

Claims (46)

1. A system, comprising:

a hardware processor configured to:

receive, at an authentication translator, a request to access a resource and an authentication input;

in response to the receiving, perform authentication using the authentication input;

based at least in part on a result of the performed authentication, determine that access should be granted to at least one stored record corresponding to the authentication input that is associated at least with the requested resource;

in response to the determination, access the stored record that is associated at least with the requested resource to obtain previously stored authentication information associated with the resource, wherein the previously stored authentication information includes a credential;

establish a session between the authentication translator and the resource;

cause the obtained credential to be provided to the resource, wherein a user associated with the obtained credential is authenticated to the requested resource using the obtained credential;

facilitate a session renegotiation;

receive a credential change request from the resource; and

update the credential without user input; and

a memory coupled to the hardware processor and configured to provide the hardware processor with instructions.

2. The system of claim 1 wherein the authentication input comprises a biometric input.

3. The system of claim 1 wherein the authentication input is received in response to a user-supplied biometric input matching a template.

4. The system of claim 1 wherein the system comprises a device and wherein the device further includes a biometric input component.

5. The system of claim 1 wherein the request to access the resource and the authentication input are received from a client device that is different and physically separate from the authentication translator.

6. The system of claim 1 wherein the processor is further configured to receive, from a remote system, an encrypted container that includes the credential.

7. The system of claim 1 wherein the processor is further configured to receive, from a remote system, an encrypted container that includes at least one template containing biometric features.

8. The system of claim 1 wherein the authentication input comprises user agent information.

9. The system of claim 1 wherein the authentication input comprises at least one cookie.

10. A method, comprising:

receiving, at an authentication translator, a request to access a resource and an authentication input;

in response to the receiving, performing authentication using the authentication input;

based at least in part on a result of the performed authentication, determining that access should be granted to at least one stored record corresponding to the authentication input that is associated at least with the requested resource;

in response to the determining, accessing the stored record that is associated at least with the requested resource to obtain previously stored authentication information associated with the resource, wherein the previously stored authentication information includes a credential;

establishing a session between the authentication translator and the resource;

causing the obtained credential to be provided to the resource, wherein a user associated with the obtained credential is authenticated to the requested resource using the obtained credential;

facilitating a session renegotiation;

receiving a credential change request from the resource; and

updating the credential without user input.

11. The method of claim 10 further comprising receiving, from a remote system, an encrypted container that includes the credential.

12. The method of claim 10 further comprising receiving, from a remote system, an encrypted container that includes at least one template containing biometric features.

13. A system, comprising:

a hardware processor configured to:

receive, at an authentication translator, a first authentication information, wherein the first authentication information includes a biometric input;

perform authentication using the biometric input, wherein performing the authentication includes determining whether the biometric input matches to one or more templates in accordance with at least one policy;

based at least in part on a result of the authentication performed using the biometric input, determine whether to provide unlocked access to one or more of a plurality of entries associated with a first user profile;

wherein a first entry in the plurality of entries includes an identifier of a resource and a second authentication information, wherein the second authentication information includes a credential associated with the resource, and wherein the credential is used to authenticate a user associated with the credential to the resource; and

wherein access to the first entry in the plurality of entries associated with the first user profile is allowed based on the determination; and

wherein access to a second entry in the plurality of entries associated with the first user profile is disallowed based on the determination;

establishing a session between the authentication translator and the resource;

facilitating a session renegotiation;

receiving a credential change request from the resource; and

updating the credential without user input; and

a memory coupled to the hardware processor and configured to provide the hardware processor with instructions.

14. The system of claim 1 wherein the processor is further configured to receive, at the authentication translator, a second request to access a second resource and a second authentication input that is different from the received authentication input.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 21, 2023
From: CARBYNE LLC
To: CARBYNE BIOMETRICS, LLC
Reel/Frame 063049/0162 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 22, 2022
From: RIGHTQUESTION, LLC
To: CARBYNE LLC
Reel/Frame 062191/0638 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 2, 2014
From: JAKOBSSON, BJORN MARKUS
To: RIGHTQUESTION, LLC
Reel/Frame 033653/0764 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 20, 2014
From: EXTRICATUS LLC
To: JAKOBSSON, BJORN MARKUS
Reel/Frame 033577/0067 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 2, 2013
From: JAKOBSSON, BJORN MARKUS
To: EXTRICATUS LLC
Reel/Frame 030135/0464 →
Continuity (2)
Provisional Application 61569112 · Dec 9, 2011
Provisional Application 61587387 · Jan 17, 2012