IP Library Granted Patent US 9,985,993
Granted Patent B2
US 9,985,993 · App. 14/859,328 · Granted May 29, 2018

Query system and method to determine authentication capabilities

Inventors: Davit Baghdasaryan (San Francisco, CA); Matthew Lourie (San Jose, CA); Rolf Lindemann (Steele, DE); Brendon J. Wilson (San Jose, CA); Marc Briceno (San Francisco, CA)
Assignee: NOK NOK LABS, INC.
H04L63/20G06F17/30991G06F21/32G06F21/34G06F21/45H04L63/08H04L63/0853H04L63/0861H04L63/205G06F2221/2115G06F2221/2117
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,985,993
App. No.
14/859,328
Granted
May 29, 2018
Kind
B2
Abstract

A system, apparatus, method, and machine readable medium are described for determining the authentication capabilities. For example, one embodiment of a method comprises: receiving a policy identifying a set of acceptable authentication capabilities; determining a set of client authentication capabilities; and filtering the set of acceptable authentication capabilities based on the determined set of client authentication capabilities to arrive at a filtered set of one or more authentication capabilities for authenticating a user of the client.

Claims (38)

1. A method comprising:

receiving a policy identifying a set of acceptable authentication capabilities;

determining a set of client authentication capabilities of a client by identifying, by the client based on a secure storage of the client, a set of authentication devices on the client corresponding to the set of client authentication capabilities;

filtering, by the client, the set of acceptable authentication capabilities based on a privacy preference level of a user of the client and the determined set of client authentication capabilities to arrive at a filtered set of one or more authentication capabilities for authenticating the user; and

using the filtered set of one or more authentication capabilities to authenticate the user over a network.

2. The method as in claim 1 wherein the policy comprises a set of authentication device types and/or classes deemed acceptable by a network server.

3. The method as in claim 1 further comprising:

displaying one or more of the filtered set of authentication capabilities in a graphical user interface (GUI);

querying the user to select or prioritize one or more of authentication capabilities from the GUI; and

generating a filtered, user specified list of authentication capabilities based on user input to the query.

4. The method as in claim 1 wherein the authentication capabilities include a fingerprint sensor.

5. The method as in claim 1 wherein the authentication capabilities include voice authentication capabilities.

6. The method as in claim 1 wherein the authentication capabilities include a smartcard.

7. The method as in claim 1 wherein the authentication capabilities include a trusted platform module (TPM).

8. The method of claim 1 , wherein the filtering of the set of acceptable authentication capabilities is further based on an authentication capability priority.

9. The method of claim 1 , wherein using the filtered set of the one or more authentication capabilities including generating and sending a set of keys for each of the filtered set of the one or more authentication capabilities to the server.

10. A system comprising:

a client to receive a policy identifying a set of acceptable authentication capabilities and to determine a set of client authentication capabilities, the client comprising a secure storage with which the client identifies a set of authentication devices on the client corresponding to the set of client authentication capabilities, the client further comprising a policy filter to filter the set of acceptable authentication capabilities based on a privacy preference level of a user of the client and the determined set of client authentication capabilities to arrive at a filtered set of one or more authentication capabilities for authenticating a user of the client; and

the client to use the filtered set of one or more authentication capabilities to authenticate the user over a network.

11. The system as in claim 10 wherein the policy comprises a set of authentication device types and/or classes deemed acceptable by a network server.

12. The system as in claim 11 further comprising:

the client displaying one or more of the filtered set of authentication capabilities in a graphical user interface (GUI);

querying the user to select or prioritize one or more of authentication capabilities from the GUI; and

generating a filtered, user specified list of authentication capabilities based on user input to the query.

13. The system as in claim 10 wherein the authentication capabilities include a fingerprint sensor.

14. The system as in claim 10 wherein the authentication capabilities include voice authentication capabilities.

15. The system as in claim 10 wherein the authentication capabilities include a smartcard.

16. The system as in claim 10 wherein the authentication capabilities include a trusted platform module (TPM).

17. A non-transitory machine: readable medium having program code stored thereon which, when executed by a machine, causes the machine to perform operations of:

receiving a policy identifying a set of acceptable authentication capabilities;

determining a set of client authentication capabilities of a client by identifying, by the client based on a secure storage of the client, a set of authentication devices on the client corresponding to the set of client authentication capabilities;

filtering, by the client, the set of acceptable authentication capabilities based on a privacy preference level of a user of the client and the determined set of client authentication capabilities to arrive at a filtered set of one or more authentication capabilities for authenticating a user of the client; and

using the filtered set of one or more authentication capabilities to authenticate the user over a network.

18. The non-transitory machine readable medium as in claim 17 wherein the policy comprises a set of authentication device types and/or classes deemed acceptable by a network server.

19. The non-transitory machine readable medium as in claim 17 comprising additional program code to cause the machine to perform operations of:

displaying one or more of the filtered set of authentication capabilities in a graphical user interface (GUI);

querying the user to select or prioritize one or more of authentication capabilities from the GUI; and

generating a filtered, user specified list of authentication capabilities based on user input to the query.

Assignments (8)
CORRECTIVE ASSIGNMENT TO CORRECT THE APPLICATION NUMBER PREVIOUSLY RECORDED AT REEL: 71257 FRAME: 566. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST. Recorded Aug 26, 2025
From: VENTURE LENDING & LEASING VII, INC.; VENTURE LENDING & LEASING VIII, INC.
To: NOK NOK LABS, INC.
Reel/Frame 073057/0274 →
SECURITY INTEREST Recorded Jul 1, 2025
From: NOK NOK LABS, INC.
To: MUFG BANK, LTD.
Reel/Frame 071773/0493 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ERRONEOUSLY RECORDED PATENT APPLICATION NUMBER 14488747 PREVIOUSLY RECORDED ON REEL 71273 FRAME 25. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Jun 18, 2025
From: VENTURE LENDING & LEASING IX, INC.; VENTURE LENDING & LEASING VIII, INC.
To: NOK NOK LABS, INC.
Reel/Frame 071773/0352 →
RELEASE OF SECURITY INTEREST Recorded May 30, 2025
From: VENTURE LENDING & LEASING VIII, INC.; VENTURE LENDING & LEASING IX, INC.
To: NOK NOK LABS, INC.
Reel/Frame 071273/0025 →
RELEASE OF SECURITY INTEREST Recorded May 29, 2025
From: VENTURE LENDING & LEASING VII, INC.; VENTURE LENDING & LEASING VIII, INC.
To: NOK NOK LABS, INC.
Reel/Frame 071257/0566 →
SECURITY INTEREST Recorded Jul 5, 2018
From: NOK NOK LABS, INC.
To: VENTURE LENDING & LEASING IX, INC.; VENTURE LENDING & LEASING VIII, INC.
Reel/Frame 046492/0870 →
SECURITY INTEREST Recorded Jan 12, 2017
From: NOK NOK LABS, INC.
To: VENTURE LENDING & LEASING VII, INC.; VENTURE LENDING & LEASING VIII, INC.
Reel/Frame 041352/0867 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 21, 2016
From: BAGHDASARYAN, DAVIT; LOURIE, MATT; LINDEMANN, ROLF; WILSON, BRENDON J.; BRICENO, MARC
To: NOK NOK LABS, INC.
Reel/Frame 038049/0317 →
Continuity (2)
Continuation 13730761 · Dec 28, 2012
Related Publication 20160014162A1 · Jan 14, 2016