IP Library › Granted Patent US 10,592,978
Granted Patent B1
US 10,592,978 · App. 13/537,525 · Granted Mar 17, 2020

Methods and apparatus for risk-based authentication between two servers on behalf of a user

Inventors: Alex Vaystikh (Hod Hasharon, IL); Alon Kaufman (Bnei-Dror, IL); Yael Villa (Tel-Aviv, IL)
Assignee: EMC IP Holding Company LLC
G06Q40/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,592,978
App. No.
13/537,525
Filed
Jun 29, 2012
Granted
Mar 17, 2020
Kind
B1
Art Unit
2438
USPC
726/4
Abstract

Methods and apparatus are provided for risk-based authentication between two servers on behalf of a user. A method is provided for controlling access by a consumer to a service provider on behalf of a user. An authentication request is issued responsive to an initial access request from the consumer to access the service provider on behalf of the user. An access token is provided to the consumer upon approval from the user to grant access to the consumer. Upon receiving a subsequent access request from the consumer with the access token to access the service provider on behalf of the user; a risk analysis is performed to determine if the subsequent access request should be granted. The risk analysis can determine if the subsequent access complies with one or more rules of the user. The user is optionally prompted to specify whether to allow the subsequent access request and/or future similar transactions.

Claims (52)

1. A method for controlling access by a consumer to a service provider on behalf of a user, the method comprising the steps of:

obtaining by an authentication manager and gateway one or more rules from said user specifying one or more permissions of the consumer;

issuing an authentication request responsive to an initial access request from the consumer to access the service provider on behalf of the user in accordance with a server-to-server protocol;

providing an access token to the consumer upon approval from the user to grant access to the consumer on behalf of said user, wherein said access token authorizes the consumer to act on behalf of said user until said access token is revoked;

enabling said consumer to use said access token for initial access to the service provider on behalf of the user;

receiving, using at least one processing device of the authentication manager and gateway, a subsequent access request from the consumer with said access token to access the service provider on behalf of the user, wherein the subsequent access request is subsequent to said initial access to the service provider;

performing a risk analysis, using at least one processing device of the authentication manager and gateway, in response to receiving from said consumer said subsequent access request with said access token authorizing the consumer to act on behalf of said user when said access token has not been revoked, to improve security by detecting an anomalous access request by said authorized consumer, wherein said risk analysis (i) determines when the subsequent access request from said consumer to act on behalf of said user should be granted, and (ii) determines when said subsequent access request demonstrates anomalous behavior comprising one or more of abnormal, risky and atypical behavior relative to (a) prior transactions, stored in at least one memory, performed by said consumer on behalf of said user, and (b) said one or more rules, stored in said at least one memory, specified by said user who has granted access to the consumer on behalf of said user;

initiating an investigating by the user when the subsequent access request is denied by the authentication manager and gateway based upon said risk analysis; and

prompting said user, by the authentication manager and gateway, based on said risk analysis, to specify whether to allow said subsequent access request by said consumer when said subsequent access request is determined to demonstrate said anomalous behavior;

receiving an updating of the one or more rules by the user based upon the results of the user investigating when the subsequent access request was denied; and

validating the updated one or more rules by the authentication manager and gateway.

2. The method of claim 1 , wherein said risk analysis determines if said subsequent access request complies with said one or more rules from said user.

3. The method of claim 1 , further comprising the step of prompting said user to specify whether to allow future transactions that are similar to said subsequent access request.

4. The method of claim 1 , wherein the service provider comprises one or more of an application, web site or hardware device.

5. The method of claim 1 , wherein the authentication request comprises a request for at least a portion of at least one password or other authentication credential associated with the user.

6. The method of claim 1 , further comprising the step of learning typical access patterns of said consumer.

7. The method of claim 1 , wherein said one or more rules from said user specifying said one or more permissions of the consumer comprise permissions of the consumer to act on behalf of said user.

8. An apparatus for controlling access by a consumer to a service provider on behalf of a user, the apparatus comprising:

a memory; and

at least one processing device, coupled to the memory, operative to implement the following steps:

obtaining by an authentication manager and gateway one or more rules from said user specifying one or more permissions of the consumer;

issuing an authentication request responsive to an initial access request from the consumer to access the service provider on behalf of the user in accordance with a server-to-server protocol;

providing an access token to the consumer upon approval from the user to grant access to the consumer on behalf of said user, wherein said access token authorizes the consumer to act on behalf of said user until said access token is revoked;

enabling said consumer to use said access token for initial access to the service provider on behalf of the user;

receiving, using at least one processing device of the authentication manager and gateway, a subsequent access request from the consumer with said access token to access the service provider on behalf of the user, wherein the subsequent access request is subsequent to said initial access to the service provider;

performing a risk analysis, using at least one processing device of the authentication manager and gateway, in response to receiving from said consumer said subsequent access request with said access token authorizing the consumer to act on behalf of said user when said access token has not been revoked, to improve security by detecting an anomalous access request by said authorized consumer, wherein said risk analysis (i) determines when the subsequent access request from said consumer to act on behalf of said user should be granted, and (ii) determines when said subsequent access request demonstrates anomalous behavior comprising one or more of abnormal, risky and atypical behavior relative to (a) prior transactions, stored in at least one memory, performed by said consumer on behalf of said user, and (b) said one or more rules, stored in said at least one memory, specified by said user who has granted access to the consumer on behalf of said user;

initiating an investigating by the user when the subsequent access request is denied by the authentication manager and gateway based upon said risk analysis; and

prompting said user, by the authentication manager and gateway, based on said risk analysis, to specify whether to allow said subsequent access request by said consumer when said subsequent access request is determined to demonstrate said anomalous behavior;

receiving an updating of the one or more rules by the user based upon the results of the user investigating when the subsequent access request was denied; and

validating the updated one or more rules by the authentication manager and gateway.

9. The apparatus of claim 8 , wherein said risk analysis determines if said subsequent access request complies with said one or more rules from said user.

10. The apparatus of claim 8 , wherein said at least one processing device is further configured to prompt said user to specify whether to allow future transactions that are similar to said subsequent access request.

11. The apparatus of claim 8 , wherein the service provider comprises one or more of an application, web site or hardware device.

12. The apparatus of claim 8 , wherein the authentication request comprises a request for at least a portion of at least one password or other authentication credential associated with the user.

13. The apparatus of claim 8 , wherein said one or more rules from said user specifying said one or more permissions of the consumer comprise permissions of the consumer to act on behalf of said user.

14. An article of manufacture for controlling access by a consumer to a service provider on behalf of a user, comprising a non-transitory machine readable recordable medium containing one or more programs which when executed implement the steps of:

obtaining by an authentication manager and gateway one or more rules from said user specifying one or more permissions of the consumer;

issuing an authentication request responsive to an initial access request from the consumer to access the service provider on behalf of the user in accordance with a server-to-server protocol;

providing an access token to the consumer upon approval from the user to grant access to the consumer on behalf of said user, wherein said access token authorizes the consumer to act on behalf of said user until said access token is revoked;

enabling said consumer to use said access token for initial access to the service provider on behalf of the user;

receiving, using at least one processing device of the authentication manager and gateway a subsequent access request from the consumer with said access token to access the service provider on behalf of the user, wherein the subsequent access request is subsequent to said initial access to the service provider;

performing a risk analysis, using at least one processing device of the authentication manager and gateway, in response to receiving from said consumer said subsequent access request with said access token authorizing the consumer to act on behalf of said user when said access token has not been revoked, to improve security by detecting an anomalous access request by said authorized consumer, wherein said risk analysis (i) determines when the subsequent access request from said consumer to act on behalf of said user should be granted, and (ii) determines when said subsequent access request demonstrates anomalous behavior comprising one or more of abnormal, risky and atypical behavior relative to (a) prior transactions, stored in at least one memory, performed by said consumer on behalf of said user, and (b) said one or more rules, stored in said at least one memory, specified by said user who has granted access to the consumer on behalf of said user;

initiating an investigating by the user when the subsequent access request is denied by the authentication manager and gateway based upon said risk analysis; and

prompting said user, by the authentication manager and gateway, based on said risk analysis, to specify whether to allow said subsequent access request by said consumer when said subsequent access request is determined to demonstrate said anomalous behavior;

receiving an updating of the one or more rules by the user based upon the results of the user investigating when the subsequent access request was denied; and

validating the updated one or more rules by the authentication manager and gateway.

15. The article of manufacture of claim 14 , wherein said risk analysis determines if said subsequent access request complies with said one or more rules from said user.

16. The article of manufacture of claim 14 , wherein the service provider comprises one or more of an application, web site or hardware device.

17. The article of manufacture of claim 14 , wherein the authentication request comprises a request for at least a portion of at least one password or other authentication credential associated with the user.

18. The article of manufacture of claim 14 , further comprising the step of prompting said user to specify whether to allow future transactions that are similar to said subsequent access request.

19. The article of manufacture of claim 14 , further comprising the step of learning typical access patterns of said consumer.

20. The article of manufacture of claim 14 , wherein said one or more rules from said user specifying said one or more permissions of the consumer comprise permissions of the consumer to act on behalf of said user.

Assignments (5)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 14, 2020
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 051581/0409 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 10, 2012
From: VAYSTIKH, ALEX; KAUFMAN, ALON; VILLA, YAEL
To: EMC CORPORATION
Reel/Frame 028928/0491 →
Cited By (3)
US 12,231,430 US 12,452,253 US 12,682,027