-
公开(公告)号:US12035136B1
公开(公告)日:2024-07-09
申请号:US17392016
申请日:2021-08-02
申请人: Acceptto Corporation
IPC分类号: H04W12/065 , G06N20/00 , H04L9/40 , G06Q20/40 , G06Q40/02
CPC分类号: H04W12/065 , G06N20/00 , H04L63/08 , G06Q20/40145 , G06Q20/4016 , G06Q40/02
摘要: Aspects of the disclosure provide techniques for using bio-behavior based information for providing and restricting access to a secure website or computer network and its assets to a user entity. The bio-behavior system and method 100 uses processes to learn models that relate heterogeneous data that connects the analog, physical space with the online/cyber world. The process is a nonparametric, probabilistic mixture model. The system 100 is capable of detecting behavioral patterns in mixed data composed of inputs of varying complexity. This includes the low-level, mainly unprocessed data generated by a user entity device's intrinsic sensors that monitor the internal state of the phone as well as extrinsic sensors that capture the state of the surrounding environment.
-
公开(公告)号:US10158675B2
公开(公告)日:2018-12-18
申请号:US15706475
申请日:2017-09-15
摘要: An alert source issues security alerts to an identity provider, which acts as a gatekeeper to a secure resource. Each security alert is associated with an alert user identity and a security threat. When a user identity requests access to the secure resource, the identity provider may look up security alerts associated with the user identity, such as by matching up the user identity with the alert user identity associated with each alert. Based on any discovered security alerts that correspond to the user identity and a pre-defined security policy, the identity provider may perform various security actions on the user identity. The identity provider may provide access to the secure resource without containing the user identity if there are no discovered security alerts associated with the user identity, or if the discovered security alerts pose a minor threat.
-
公开(公告)号:US09930040B2
公开(公告)日:2018-03-27
申请号:US15140074
申请日:2016-04-27
CPC分类号: H04L63/10 , H04L9/3215 , H04L9/3228 , H04L63/08 , H04L63/0853 , H04L67/42
摘要: The provisioning of a security token object to a user is disclosed. The security token object is used for accessing a computing resource through a mobile device. A security token object provisioning request may be received from the mobile device. In response, an authentication request may be transmitted. The user is authenticated against a user identity based upon a set of received identity credentials provided by the user. The extraction of a unique token identifier from the security token object is initiated, and completed without intervention from the user. The unique token identifier received from the client computer system is associated with to the user identity in a data store. By providing the security token object, the user can gain access to the computing resource.
-
公开(公告)号:US09473310B2
公开(公告)日:2016-10-18
申请号:US14256270
申请日:2014-04-18
CPC分类号: H04L9/3268 , H04L9/14 , H04L9/30 , H04L9/3252 , H04L9/3263 , H04L9/3271 , H04L9/3297 , H04L63/06 , H04L63/0823 , H04L2209/56 , H04L2209/805
摘要: Methods for managing digital certificates, including issuance, validation, and revocation are disclosed. Various embodiments involve querying a directory service with entries that correspond to a particular client identity and have attributes including certificate issuance limits and certificate validity time values. The validity time values are adjustable to revoke selectively the certificates based upon time intervals set forth in validity identifiers included therein.
摘要翻译: 公开了管理数字证书的方法,包括发行,验证和撤销。 各种实施例涉及使用与特定客户端标识对应的条目来查询目录服务,并具有包括证书颁发限制和证书有效时间值的属性。 有效时间值可调,可以根据其中包含的有效性标识符中列出的时间间隔有选择地撤销证书。
-
公开(公告)号:US09288195B2
公开(公告)日:2016-03-15
申请号:US14105932
申请日:2013-12-13
CPC分类号: H04L63/0815 , G06F21/335 , G06F21/41 , G06F2221/2141 , G06F2221/2151 , H04L9/3234 , H04L9/3263 , H04L63/08 , H04L63/0807 , H04L63/0823 , H04L63/10 , H04L2463/082
摘要: The authentication of a client to multiple server resources with a single sign-on procedure using multiple factors is disclosed. One contemplated embodiment is a method in which a login session is initiated with the authentication system of a primary one of the multiple server resources. A first set of login credentials is transmitted thereto, and validated. A token is stored on the client indicating that the initial authentication was successful, which is then used to transition to a secondary one of the multiple resources. A second set of login credentials is also transmitted, and access to the secondary one of the multiple resources is granted on the basis of a validated token and second set of login credentials.
-
公开(公告)号:US08769651B2
公开(公告)日:2014-07-01
申请号:US13830506
申请日:2013-03-14
CPC分类号: H04L63/0815 , G06F17/30876 , G06F21/31 , G06F21/41 , H04L63/08 , H04L63/0823 , H04L63/083 , H04L63/0853 , H04L63/168 , H04L2463/082 , H04W12/06
摘要: Features are disclosed for authentication of mobile device applications using a native, independent browser using a single-sign-on system. An authentication module within the mobile application can direct the mobile device's native browser to a URL to initiate authentication with an authentication appliance. The mobile browser can receive and store a browser-accessible token to indicate previous authentication performed by the user. The mobile application can receive from the application appliance and store a client application ID token that may be presented to network services for access. A second mobile device application may direct the same browser to the authentication appliance. The authentication appliance may inspect the persistent browser-accessible token and issue a second client application ID identity to the second application without collecting additional authentication information, or collecting additional authentication information that is different from the first authentication information.
摘要翻译: 公开了使用使用单点登录系统的本机独立浏览器对移动设备应用进行认证的功能。 移动应用程序内的身份验证模块可以将移动设备的本机浏览器引导到URL,以启动身份验证设备的身份验证。 移动浏览器可以接收和存储浏览器可访问令牌,以指示用户执行的先前身份验证。 移动应用程序可以从应用程序设备接收并存储可以呈现给网络服务以进行访问的客户端应用程序ID令牌。 第二移动设备应用可以将相同的浏览器引导到认证设备。 验证设备可以检查永久性浏览器可访问令牌,并向第二应用发出第二客户端应用ID身份,而不收集附加认证信息,或者收集与第一认证信息不同的附加认证信息。
-
公开(公告)号:US20140181946A1
公开(公告)日:2014-06-26
申请号:US14105932
申请日:2013-12-13
IPC分类号: H04L29/06
CPC分类号: H04L63/0815 , G06F21/335 , G06F21/41 , G06F2221/2141 , G06F2221/2151 , H04L9/3234 , H04L9/3263 , H04L63/08 , H04L63/0807 , H04L63/0823 , H04L63/10 , H04L2463/082
摘要: The authentication of a client to multiple server resources with a single sign-on procedure using multiple factors is disclosed. One contemplated embodiment is a method in which a login session is initiated with the authentication system of a primary one of the multiple server resources. A first set of login credentials is transmitted thereto, and validated. A token is stored on the client indicating that the initial authentication was successful, which is then used to transition to a secondary one of the multiple resources. A second set of login credentials is also transmitted, and access to the secondary one of the multiple resources is granted on the basis of a validated token and second set of login credentials.
摘要翻译: 公开了使用多个因素对具有单一登录过程的客户机对多个服务器资源的认证。 一个预期的实施例是一种方法,其中使用多个服务器资源中的主要的身份验证系统来启动登录会话。 第一组登录凭证被传送到其中并被验证。 令牌存储在客户机上,指示初始认证成功,然后将令牌转换为多个资源中的辅助节点。 还传输第二组登录凭证,并且基于经过验证的令牌和第二组登录凭证来授予对多个资源中的次要资源的访问。
-
公开(公告)号:US20140082715A1
公开(公告)日:2014-03-20
申请号:US13830506
申请日:2013-03-14
IPC分类号: H04L29/06
CPC分类号: H04L63/0815 , G06F17/30876 , G06F21/31 , G06F21/41 , H04L63/08 , H04L63/0823 , H04L63/083 , H04L63/0853 , H04L63/168 , H04L2463/082 , H04W12/06
摘要: Features are disclosed for authentication of mobile device applications using a native, independent browser using a single-sign-on system. An authentication module within the mobile application can direct the mobile device's native browser to a URL to initiate authentication with an authentication appliance. The mobile browser can receive and store a browser-accessible token to indicate previous authentication performed by the user. The mobile application can receive from the application appliance and store a client application ID token that may be presented to network services for access. A second mobile device application may direct the same browser to the authentication appliance. The authentication appliance may inspect the persistent browser-accessible token and issue a second client application ID identity to the second application without collecting additional authentication information, or collecting additional authentication information that is different from the first authentication information.
摘要翻译: 公开了使用使用单点登录系统的本机独立浏览器对移动设备应用进行认证的功能。 移动应用程序内的身份验证模块可以将移动设备的本机浏览器引导到URL,以启动身份验证设备的身份验证。 移动浏览器可以接收和存储浏览器可访问令牌,以指示用户执行的先前身份验证。 移动应用程序可以从应用程序设备接收并存储可以呈现给网络服务以进行访问的客户端应用程序ID令牌。 第二移动设备应用可以将相同的浏览器引导到认证设备。 验证设备可以检查永久性浏览器可访问令牌,并向第二应用发出第二客户端应用ID身份,而不收集附加认证信息,或者收集与第一认证信息不同的附加认证信息。
-
公开(公告)号:US11888839B1
公开(公告)日:2024-01-30
申请号:US18094787
申请日:2023-01-09
发明人: Shahrokh Shahidzadeh , Nadal Shahidzadeh , Christopher Clifford , Haitham Akkary , Seyedamir Karimikho
CPC分类号: H04L63/0815 , H04L63/0807 , H04W4/029 , H04W4/14
摘要: A system and method for secure authentication of user entity and user entity device identity. The system and method described herein allows an identity to be continuously proven because of user entity's behavior and their biometrics. With all the fraud and risk that exists today, if someone has a user entity's driver's license they can do a lot of harm. A primary identity provider passes user contextual and behavioral information to third party secondary identity providers to allow risk based continuous authentication and step up post-authorization authentication or termination of session as required upon detection of an anomaly.
-
公开(公告)号:US11838762B1
公开(公告)日:2023-12-05
申请号:US17671504
申请日:2022-02-14
发明人: Shahrokh Shahidzadeh
摘要: A system and method for rapid check-in and inheriting trust using a user entity device. The system and method described herein allows an identity to be continuously proven because of user entity's behavior and their biometrics. With all the fraud and risk that exists today, if someone has a user entity's driver's license they can do a lot of harm. By tying a user entity's identity to their user entity device (e.g., a mobile smartphone), then when a user entity checks into a location (e.g., airport, hotel, bank), an identity provider continues a process of continuous authentication while the user entity device travels about a location and interacts with the services offered by the location.
-
-
-
-
-
-
-
-
-