Brokered authentication with risk sharing
Abstract
Embodiments described herein are implemented in authentication brokering systems where an authentication broker issues security tokens that represent its authentications of users. Client devices operated by the users store the security tokens and send them to resource providers. The resource providers authenticate and grant access to the users based on validation of the security tokens. Authentication related messages exchanged between the resource providers and the authentication broker are used to exchange authentication risk data that is obtained or derived by the resource providers and the authentication broker. The resource providers obtain authentication risk data directly from the authentication broker and indirectly, via the authentication broker, from each other. As security tokens are used or managed, authentication risk data is shared among the participants in the authentication brokering system. The participants are able to modify their authentication procedures or make authentication decisions based on shared authentication risk data.
Claims
exact text as granted — not AI-modified1 . A method performed by an authentication broker comprising one or more computing devices comprising processing hardware and storage hardware configured with instructions to enable the processing hardware to perform the method, the method performed by the authentication broker comprising:
receiving a token request via a network from a client device operated by a user, the token request comprising a user identity associated with the token request, the token request generated by the client device, the token request received in a first message conforming to a protocol; based on receiving the token request, performing a user authentication procedure to authenticate the user identity associated with the token request, the user authentication procedure comprising verifying an authentication factor provided by the client device, wherein the authentication broker receives first risk factors that the authentication broker uses to determine a risk score in association with performing the authentication procedure; based on the authenticating of the user identity, generating a security token associated with the user identity, storing an indication of the security token, generating a second message conforming to the protocol and comprising the security token, and transmitting the second message to the client device via the network; and storing the first authentication risk factors in association with the indication of the security token.
2 . A method according to claim 1 , the method according to claim 1 , further comprising:
receiving a validation request via the network from a first resource provider, the validation request comprising the security token, the validation request initiated by the first resource provider while performing a second authentication procedure to authenticate a user that corresponds to the user identity; receiving second authentication risk factors from the first resource provider, the first risk factors obtained by the first resource provider in association with the second authentication procedure; and storing the received second authentication risk factors in association with the indication of the security token.
3 . A method according to claim 2 , further comprising:
based on the validation request, validating the received security token, and based on the validation generating a validation confirmation message conforming to the protocol; sending the validation confirmation message to the first resource provider; and in association with validating the received security token, and based on the stored association between the indication of the security token and the first authentication risk factors, sending at least one of the stored first authentication risk factors to the first resource provider.
4 . A method according to claim 1 , wherein the first resource provider performs the second authentication procedure using the at least one of the first authentication risk factors.
5 . A method according to claim 1 , further comprising:
receiving a second validation request from a second resource provider, the second validation request comprising the security token; based on the second validation request, validating the security token from the second validation request and generating a second validation confirmation message by incorporating therein at least one of the first authentication risk factors and at least one of the second authentication risk factors.
6 . A method according to claim 5 , wherein the second resource provider authorizes the client device to access a resource provided thereby by authenticating the client device based on the at least one of the first authentication risk factors and based on the at least one of the second authentication risk factors.
7 . A method according to claim 5 , wherein the authentication broker validates the security token from the second validation request based on at least one of the second authentication risk factors.
8 . A method according to claim 1 , wherein the validating the received security token is performed according to the stored indication of the security token and one or more of the first authentication risk factors.
9 . A method performed by an authentication broker comprising a first computing device, the method comprising:
receiving, via a network, from a client application, a request to authenticate a user of the client application; based on the authentication request, performing a first authentication procedure to authenticate the user; generating a token representing authentication of the user by the first authentication procedure, storing an indication of the token in association with the user, and transmitting the token to the client device via the network; receiving, from a first resource provider, the token and first authentication risk data, wherein the token and first authentication risk data are sent by the first resource provider based on the first resource provider performing a second authentication procedure to authenticate the user, and wherein the authentication broker maintains, after the second authentication procedure is finished, storage of an association between the first authentication risk data and the token; and receiving, from a second resource provider, the token and second authentication risk data, wherein the token and second authentication risk data are sent by the second resource provider based on the second resource provider performing a third authentication procedure to authenticate the user, and wherein the authentication broker stores, after the third authentication procedure is complete, storage of an association between the second authentication risk data and the token.
10 . A method according to claim 9 , wherein the token and the authentication risk data are received in Hypertext Transfer Protocol (HTTP) messages, and wherein the first and second resource providers comprise respective web servers in respective different security domains.
11 . A method according to claim 10 , wherein the authentication broker comprises a Security Token Service (STS) endpoint.
12 . A method according to claim 9 , wherein the request to authenticate the user and messages containing the received authentication risk data comply with a version or extension of the OAuth protocol.
13 . A method according to claim 9 , wherein the first and second authentication risk data comprise respective risk scores computed by the first and second resource providers, respectively.
14 . A method according to claim 9 , wherein, based on the storage of the association between the first authentication risk data and the token, and based on receipt of the token from the second resource provider, the authentication broker sends the first authentication risk data to the second resource provider.
15 . A method according to claim 14 , wherein the second resource provider computes a risk score estimating risk of authenticating the user based on the first authentication risk data.
16 . A method for providing identity authentication brokering, the method performed by one or more computing devices, the method comprising:
issuing, by a security token service (STS), security tokens to respective clients operated by respective users, the security tokens comprising indications of respective first authentications of the users by the STS; receiving, by the STS, first messages sent to the STS by resource servers, the first messages sent in association with the resource servers receiving the security tokens from the clients and using the security tokens to perform second authentications of the users, the first messages comprising respective first authentication risk items, wherein the first authentication risk items are used by the resource servers for computing risk measures of the second authentications; and storing the first authentication risk items by the STS in association with the security tokens corresponding thereto, wherein each first authentication risk item is stored in association with the security token for which a corresponding second authentication was performed, and wherein the stored first authentication risk items are retained, in association with the corresponding tokens, for use by the STS after the corresponding second authentications are completed by the resource servers.
17 . A method according to claim 16 , wherein the first messages comprise requests to validate or refresh the security tokens.
18 . A method according to claim 16 , further comprising sending, by the STS, a second message to a resource server, wherein the second message comprises a first authentication risk item previously provided to the STS by another resource server and retained by the STS, wherein the first authentication risk item is selected by the STS for inclusion in the second message based on the STS receiving a request from the resource server to validate or refresh the security token.
19 . A method according to claim 18 , wherein the STS services a request from a resource server to validate or refresh a security token identified therein, and based on the identification of the security token in the second message the STS obtains the first authentication risk item.
20 . A method according to claim 19 , wherein the resource server completes a second authentication of a user based on the first authentication risk item in the second message.Join the waitlist — get patent alerts
Track US2020236147A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.