IP Library Granted Patent US 9,836,594
Granted Patent B2
US 9,836,594 · App. 14/280,849 · Granted Dec 5, 2017

Service channel authentication token

Inventors: Xianhong Zhang (Issaquah, WA); Andrew T. Keys (Albany, OR); Kapil Pruthi (Bothell, WA); Daniel Lynn Carpenter (Matthews, NC); Mark A. Pender (Morrestown, NJ); Spencer Yezo (Millstone, NJ); Apeksh M. Dave (Weddington, NC)
Assignee: Bank of America Corporation
G06F21/44G06F21/45G06F21/73H04L29/06H04L63/08H04L63/0807H04L63/0838H04L63/0861H04L63/0876H04L63/10H04L63/105
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,836,594
App. No.
14/280,849
Granted
Dec 5, 2017
Kind
B2
Abstract

A computer system receives an authentication request from a user device and determines a determined device identification from a set of received device attributes. When the device is properly authenticated, the computer system generates an authentication token that is signed by the determined device identification and returns the authentication token to the user device. When the computer system subsequently receives a service request with an authentication token and a plurality of device attributes for a protected resource from a user device, the computer system determines a derived device identification from some or all of the received device attributes. When a signed device identification of the authentication token and the derived device identification are equal, the apparatus continues processing the service request. Otherwise, the service request is rejected.

Claims (49)

1. An apparatus comprising:

at least one memory device;

at least one processor coupled to the at least one memory device and configured to perform, based on instructions stored in the at least one memory device:

receiving a service request for a protected resource from a first user device, wherein the service request includes a plurality of device attributes and an authentication token;

selecting, based on a first attribute selection, a first attribute set from the plurality of device attributes contained in the service request, wherein at least one attribute in the plurality of device attributes is not included in the first attribute set and wherein the first attribute selection of the first user device is different from a second attribute selection for a second user device;

determining a derived device identification from the first attribute set;

when a signed device identification of the authentication token contained in the service request and the derived device identification are equal, continue processing the service request;

when the signed device identification is not equal to the derived device identification, rejecting the service request; and

replacing one attribute of the first attribute set with at least one other attribute from the plurality of device attributes to obtain a greater degree of security and preserving uniqueness of the derived device identification.

2. The apparatus of claim 1 , wherein the at least one processor is further configured to perform:

when the signed device identification and the derived device identification are equal, sending a challenge to the first user device for authentication information; and

only when the authentication information is determined to be correct, servicing the service request.

3. The apparatus of claim 1 , wherein the at least one processor is further configured to perform:

when a signed device identification of the authentication token and the derived device identification are equal, challenging the first user device for authentication information until a degree of authentication is achieved.

4. The apparatus of claim 1 , wherein the at least one processor is further configured to perform:

extracting an extracted authentication level from the authentication token; and

processing the service request based on the extracted authentication level.

5. The apparatus of claim 1 , wherein the at least one processor is further configured to perform:

receiving an expired authentication token with the service request;

challenging the first user device for authentication information; and

when the authentication is determined to be correct, determining a new expiration time;

inserting the new expiration time in an updated authentication token;

signing the updated authentication token with the signed device identification; and

returning the updated authentication token to the first user device.

6. The apparatus of claim 1 , wherein the at least one processor is further configured to perform:

when the signed device identification is not equal to the derived device identification, generating an notification about an authentication failure for the first user device.

7. The apparatus of claim 1 , wherein the first attribute set includes a browser attribute.

8. A computer-assisted method for authenticating a user device, the method comprising:

receiving a service request for a protected resource from a user device, wherein the service request includes a plurality of device attributes and a received authentication token;

selecting, based on a first attribute selection, an attribute set from the plurality of device attributes contained in the service request, wherein at least one attribute in the plurality of device attributes is not included in the attribute set and wherein the first attribute selection of the first user device is different from a second attribute selection for a second user device;

determining a derived device identification from the attribute set contained in the plurality of device attributes;

when a signed device identification of the received authentication token contained in the service request and the derived device identification are equal, continue processing the service request; and

when the signed device identification is not equal to the derived device identification, rejecting the service request; and

replacing one attribute of the first attribute set with at least one other attribute from the plurality of device attributes to obtain at least a same degree of security and preserving uniqueness of the derived device identification.

9. The method of claim 8 further comprising:

when the signed device identification and the derived device identification are equal, sending a challenge to the user device for authentication information; and

only when the authentication information is determined to be correct, servicing the service request.

10. The method of claim 8 further comprising:

when a signed device identification of the received authentication token and the derived device identification are equal, challenging the user device for authentication information until a degree of authentication is achieved.

11. The method of claim 8 further comprising:

extracting an extracted authentication level from the received authentication token; and

processing the service request based on the extracted authentication level.

12. A non-transitory computer-readable storage medium storing computer-executable instructions that, when executed, cause a processor at least to perform operations comprising:

receiving a service request for a protected resource from a user device, wherein the service request includes a plurality of device attributes and an authentication token;

selecting, based on a first attribute selection, a first attribute set from the plurality of device attributes contained in the service request, wherein at least one attribute in the plurality of device attributes is not included in the attribute set and wherein the first attribute selection of the first user device is different from a second attribute selection for a second user device;

determining a derived device identification from the first attribute set contained in the plurality of device attributes;

when a signed device identification of the authentication token contained in the service request and the derived device identification are equal, continue processing the service request;

when the signed device identification is not equal to the derived device identification, rejecting the service request; and

replacing one attribute of the first attribute set with at least one other attribute from the plurality of device attributes to obtain at least a same degree of security and preserving uniqueness of the derived device identification.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2014
From: ZHANG, XIANHONG; KEYS, ANDREW T.; PRUTHI, KAPIL; CARPENTER, DANIEL LYNN; PENDER, MARK A.; YEZO, SPENCER; DAVE, APEKSH M.
To: BANK OF AMERICA CORPORATION
Reel/Frame 032922/0178 →
Continuity (1)
Related Publication 20150334099A1 · Nov 19, 2015