US2022086166A1PendingUtilityA1

Access Control Based on Combined Multi-System Authentication Factors

Assignee: AT & T IP I LPPriority: Aug 8, 2018Filed: Nov 29, 2021Published: Mar 17, 2022
Est. expiryAug 8, 2038(~12 yrs left)· nominal 20-yr term from priority
G06F 21/31H04L 63/08H04L 63/105H04L 63/102H04L 63/20H04L 2463/082G06F 21/45G06F 21/6218
61
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

An access gateway may control access of user devices to remote computer resource systems in a multi-resource computing environment. The access gateway may determine an assurance level associated with a user of the multi-resource environment, where the assurance level is based on multiple authentication factors included in multiple previous access requests. The access gateway may receive, from a user device, an additional access request to access an additional resource system in the multi-resource environment. Based on a comparison of the assurance level with a threshold authentication level for the additional resource system, the access gateway may allow or deny access to the additional resource system. In addition, based on the comparison, the access system may request additional authentication data from the user device.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method comprising:
 storing, by an access gateway, authentication data including a plurality of authentication factors, wherein each authentication factor of the plurality of authentication factors corresponds to a particular user of a multi-resource computing environment, wherein each authentication factor of the plurality of authentication factors is received at a different time over a period of time from a different one of a plurality of computing devices associated with the particular user, and wherein each authentication factor of the plurality of authentication factors is included in a corresponding access request received from a respective one of the plurality of computing devices during the period of time to access a corresponding one of a plurality of computing resource systems in the multi-resource computing environment;   determining, by the access gateway for each authentication factor of the plurality of authentication factors, a respective intrinsic value, wherein the respective intrinsic value indicates a corresponding level of validity for each authentication factor of the plurality of authentication factors;   determining, by the access gateway, a cumulative assurance level of the authentication data, wherein the cumulative assurance level is based on a combination of respective intrinsic values associated with the plurality of authentication factors;   after the period of time, receiving, by the access gateway from a computing device of the plurality of computing devices associated with the particular user, an access request to access a computing resource system of the plurality of computing resource systems in the multi-resource computing environment, the computing resource system associated with a threshold authentication level;   in response to receiving the access request from the computing device, determining, by the access gateway based on a comparison of the cumulative assurance level of the authentication data with the threshold authentication level of the computing resource system, that the cumulative assurance level of the authentication data at least meets the threshold authentication level of the computing resource system; and   responsive to determining that the cumulative assurance level of the authentication data at least meets the threshold authentication level of the computing resource system, providing, by the access gateway, the computing device that provided the access request as well as each of the plurality of computing devices that provided the corresponding access request received during the period of time with access to the computing resource system.   
     
     
         2 . The method of  claim 1 , wherein the threshold authentication level of the computing resource system is indicated by a policy associated with the computing resource system. 
     
     
         3 . The method of  claim 2 , wherein the policy further indicates a permission level associated with the computing resource system, the permission level indicating an authorization requirement for accessing the computing resource system. 
     
     
         4 . The method of  claim 3 , wherein determining that the cumulative assurance level of the authentication data at least meets the threshold authentication level of the computing resource system is further based on a comparison of the permission level to authorization information associated with the access request. 
     
     
         5 . The method of  claim 1 , wherein the comparison of the cumulative assurance level of the authentication data to the threshold authentication level of the computing resource system is performed by a policy decision point. 
     
     
         6 . The method of  claim 1 , wherein a policy decision point determines a risk score associated with the access request, the risk score indicating a likelihood of the access request being a fraudulent request. 
     
     
         7 . The method of  claim 6 , wherein determining that the cumulative assurance level of the authentication data at least meets the threshold authentication level of the computing resource system is further based on a comparison of the risk score to a risk tolerance associated with the computing resource system. 
     
     
         8 . An access gateway comprising:
 a processor; and   a memory storing instructions that, when executed by the processor, cause the processor to perform operations comprising
 storing authentication data including a plurality of authentication factors, wherein each authentication factor of the plurality of authentication factors corresponds to a particular user of a multi-resource computing environment, wherein each authentication factor of the plurality of authentication factors is received at a different time over a period of time from a different one of a plurality of computing devices associated with the particular user, and wherein each authentication factor of the plurality of authentication factors is included in a corresponding access request received from a respective one of the plurality of computing devices during the period of time to access a corresponding one of a plurality of computing resource systems in the multi-resource computing environment, 
 determining, for each authentication factor of the plurality of authentication factors, a respective intrinsic value, wherein the respective intrinsic value indicates a corresponding level of validity for each authentication factor of the plurality of authentication factors, 
 determining a cumulative assurance level of the authentication data, wherein the cumulative assurance level is based on a combination of respective intrinsic values associated with the plurality of authentication factors, 
 after the period of time, receiving, from a computing device of the plurality of computing devices associated with the particular user, an access request to access a computing resource system of the plurality of computing resource systems in the multi-resource computing environment, the computing resource system associated with a threshold authentication level, 
 in response to receiving the access request from the computing device, determining, based on a comparison of the cumulative assurance level of the authentication data with the threshold authentication level of the computing resource system, that the cumulative assurance level of the authentication data at least meets the threshold authentication level of the computing resource system, and 
 responsive to determining that the cumulative assurance level of the authentication data at least meets the threshold authentication level of the computing resource system, providing the computing device that provided the access request as well as each of the plurality of computing devices that provided the corresponding access request received during the period of time with access to the computing resource system. 
   
     
     
         9 . The access gateway of  claim 8 , wherein the threshold authentication level of the computing resource system is indicated by a policy associated with the computing resource system. 
     
     
         10 . The access gateway of  claim 9 , wherein the policy further indicates a permission level associated with the computing resource system, the permission level indicating an authorization requirement for accessing the computing resource system. 
     
     
         11 . The access gateway of  claim 10 , wherein determining that the cumulative assurance level of the authentication data at least meets the threshold authentication level of the computing resource system is further based on a comparison of the permission level to authorization information associated with the access request. 
     
     
         12 . The access gateway of  claim 8 , wherein the comparison of the cumulative assurance level of the authentication data to the threshold authentication level of the computing resource system is performed by a policy decision point. 
     
     
         13 . The access gateway of  claim 8 , wherein a policy decision point determines a risk score associated with the access request, the risk score indicating a likelihood of the access request being a fraudulent request. 
     
     
         14 . The access gateway of  claim 13 , wherein determining that the cumulative assurance level of the authentication data at least meets the threshold authentication level of the computing resource system is further based on a comparison of the risk score to a risk tolerance associated with the computing resource system. 
     
     
         15 . A non-transitory computer-readable medium having instructions stored thereon that, when executed by a processor of an access gateway, cause the access gateway to perform operations comprising:
 storing authentication data including a plurality of authentication factors, wherein each authentication factor of the plurality of authentication factors corresponds to a particular user of a multi-resource computing environment, wherein each authentication factor of the plurality of authentication factors is received at a different time over a period of time from a different one of a plurality of computing devices associated with the particular user, and wherein each authentication factor of the plurality of authentication factors is included in a corresponding access request received from a respective one of the plurality of computing devices during the period of time to access a corresponding one of a plurality of computing resource systems in the multi-resource computing environment;   determining, for each authentication factor of the plurality of authentication factors, a respective intrinsic value, wherein the respective intrinsic value indicates a corresponding level of validity for each authentication factor of the plurality of authentication factors;   determining a cumulative assurance level of the authentication data, wherein the cumulative assurance level is based on a combination of respective intrinsic values associated with the plurality of authentication factors;   after the period of time, receiving, from a computing device of the plurality of computing devices associated with the particular user, an access request to access a computing resource system of the plurality of computing resource systems in the multi-resource computing environment, the computing resource system associated with a threshold authentication level;   in response to receiving the access request from the computing device, determining, based on a comparison of the cumulative assurance level of the authentication data with the threshold authentication level of the computing resource system, that the cumulative assurance level of the authentication data at least meets the threshold authentication level of the computing resource system; and   responsive to determining that the cumulative assurance level of the authentication data at least meets the threshold authentication level of the computing resource system, providing the computing device that provided the access request as well as each of the plurality of computing devices that provided the corresponding access request received during the period of time with access to the computing resource system.   
     
     
         16 . The non-transitory computer-readable medium of  claim 15 , wherein the threshold authentication level of the computing resource system is indicated by a policy associated with the computing resource system. 
     
     
         17 . The non-transitory computer-readable medium of  claim 16 , wherein the policy further indicates a permission level associated with the computing resource system, the permission level indicating an authorization requirement for accessing the computing resource system. 
     
     
         18 . The non-transitory computer-readable medium of  claim 17 , wherein determining that the cumulative assurance level of the authentication data at least meets the threshold authentication level of the computing resource system is further based on a comparison of the permission level to authorization information associated with the access request. 
     
     
         19 . The non-transitory computer-readable medium of  claim 15 , wherein the comparison of the cumulative assurance level of the authentication data to the threshold authentication level of the computing resource system is performed by a policy decision point. 
     
     
         20 . The non-transitory computer-readable medium of  claim 15 , wherein a policy decision point determines a risk score associated with the access request, the risk score indicating a likelihood of the access request being a fraudulent request, and wherein determining that the cumulative assurance level of the authentication data at least meets the threshold authentication level of the computing resource system is further based on a comparison of the risk score to a risk tolerance associated with the computing resource system.

Join the waitlist — get patent alerts

Track US2022086166A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.