IP Library Granted Patent US 9,338,153
Granted Patent B2
US 9,338,153 · App. 13/860,094 · Granted May 10, 2016

Secure distribution of non-privileged authentication credentials

Inventors: Keith A. McFarland (Annapolis, MD); Kambiz Ghozati (Ellicott City, MD); John Stevens (Middle River, MD); Wiliam P. Wells (Federal Way, WA)
Assignee: TeleCommunication Systems, Inc.
H04L63/08H04L63/18
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,338,153
App. No.
13/860,094
Granted
May 10, 2016
Kind
B2
Abstract

An authentication credentials push service (ACPS) that securely pushes non-privileged authentication credentials to registered client entities. The ACPS comprises a classification server and a push server to provide access to non-privileged authentication credentials absent a pull transaction. The classification server in the ACPS classifies authentication credentials as either privileged (i.e. private, forgeable) or non-privileged (i.e. non-forgeable, non-sensitive). Credentials identified as being of a privileged nature are treated with restricted access. Alternatively, credentials classified as being of a non-privileged nature are made available for the push service. Authentication servers register with the ACPS to become consumers of the push service. A push server within the ACPS pushes non-privileged authentication credentials to registered authentication servers at predetermined intervals. Individual authentication credentials push services (ACPS) have access to different authentication credentials. An authentication server can use a dynamic name service (DNS) lookup to find a specific authentication credentials push service (ACPS).

Claims (15)

1. A method of receiving authenticating credentials without requiring a pull transaction, comprising:

requesting, from a physical credentials database of authentication credentials, by a physical authentication credentials push server, said authentication credentials including privileged authentication credentials and non-privileged authentication credentials;

registering, in a physical registration database, a plurality of non-requesting physical authentication servers registered for receipt of a non-requested push of non-privileged authentication credential data from said physical authentication credentials push server, said push being performed absent a pull transaction by at least one non-requesting physical authentication server receiving said non-privileged authentication credentials;

distinguishing, by said physical authentication credentials push server, between privileged and non-privileged authentication credentials within said physical credentials database; and

pushing at predetermined intervals, from said physical authentication credentials push server, said non-privileged authentication credentials to said at least one non-requesting physical authentication server.

2. The method of receiving authenticating credentials without requiring a pull transaction according to claim 1 , wherein said privileged authentication credentials comprise:

private, forgeable information.

3. The method of receiving authenticating credentials without requiring a pull transaction according to claim 1 , wherein said non-privileged authentication credentials comprise:

non-sensitive, non-forgeable information.

4. The method of receiving authenticating credentials according to claim 1 , further comprising:

restricting access to said privileged authentication credentials.

5. The method of receiving authenticating credentials according to claim 1 , further comprising:

registering said physical authentication credentials push server with a domain name service (DNS) system.

6. The method of receiving authenticating credentials according to claim 1 , further comprising:

communicating via a domain name service (DNS) lookup to acquire information sufficient to connect with said physical authentication credentials push server.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 11, 2013
From: MCFARLAND, KEITH A.; GHOZATI, KAMBIZ; STEVENS, JOHN; WELLS, WILLIAM P.
To: TELECOMMUNICATION SYSTEMS, INC.
Reel/Frame 031759/0594 →
Continuity (2)
Provisional Application 61622829 · Apr 11, 2012
Related Publication 20130291078A1 · Oct 31, 2013