Method and system for transmitting authentication context information
First Claim
1. A system for facilitating an authentication of a user comprising:
- a first computer system configured to verify an identity of said user and transmit characteristics regarding a process used to initially associate user credentials to said user, physical controls of a facility housing said first computer, and at least one of information regarding a process used to verify said identity, procedural security controls of said first computer, and how a secret is kept secure; and
a second computer system configured to provide services to said user, wherein said second computer system communicates with said first computer system; and
further wherein,said second computer system is configured to request additional authentication credentials from said first computer system upon determining that said process used to verify said identity does not substantially comply with a predetermined class established by said second computer system; and
further wherein,said second computer system allows interaction with said second computer system provided that said process used to verify said identity at said first computer system substantially complies with a predetermined class established by said second computer system.
3 Assignments
0 Petitions
Accused Products
Abstract
A system of the present invention uses an identity provider to provide the authentication services for multiple service providers. An identity provider communicates with one or more service providers. A user that wishes to gain access to a service provider is authenticated through the use of the identity provider. A user desiring to access a service provider is first authenticated by the identity provider. The identity provider determines if the user meets the desired class level and provides various information related to the authentication. When the user attempts to access a second service provider that is associated with the same identity provider, the second service provider accesses the identity provider and determines that the user was recently authenticated. The identity provider then transmits the relevant information regarding the authentication process to the second service provider, which can then allow or deny the user access to the second service provider.
64 Citations
11 Claims
-
1. A system for facilitating an authentication of a user comprising:
-
a first computer system configured to verify an identity of said user and transmit characteristics regarding a process used to initially associate user credentials to said user, physical controls of a facility housing said first computer, and at least one of information regarding a process used to verify said identity, procedural security controls of said first computer, and how a secret is kept secure; and a second computer system configured to provide services to said user, wherein said second computer system communicates with said first computer system; and
further wherein,said second computer system is configured to request additional authentication credentials from said first computer system upon determining that said process used to verify said identity does not substantially comply with a predetermined class established by said second computer system; and
further wherein,said second computer system allows interaction with said second computer system provided that said process used to verify said identity at said first computer system substantially complies with a predetermined class established by said second computer system. - View Dependent Claims (2, 3)
-
-
4. A method for facilitating validation of an identity of a user comprising:
-
receiving information indicative of said identity of said user by a first computer system; verifying said identity of said user by said first computer system; transmitting data from said first computer system to a second computer system, wherein said data includes characteristics regarding a process used to initially associate user credentials to said user, physical controls of a facility housing said first computer, and at least one of information regarding a process used to verify said identity, procedural security controls of said first computer and how a secret is kept secure; facilitating a request from said second computer system to said first computer system for additional authentication credentials upon determining that said data does not substantially comply with a predetermined class established by said second computer system; and
,allowing access to said second computer system provided that said data substantially complies with said predetermined class established by said second computer system. - View Dependent Claims (5, 6, 7, 8, 9, 10)
-
-
11. A method for facilitating validation of an identity of a user to allow said user to access a second computer system, said method comprising:
-
receiving information indicative of said identity of said user by a first computer system; verifying said identity of said user by said first computer system; transmitting data from said first computer system to said second computer system to facilitate a request from said second computer system to said first computer system for additional authentication credentials upon determining that said data does not substantially comply with a predetermined class established by said second computer system, wherein said data includes characteristics regarding a process used to initially associate said authentication credentials to said user, physical controls of a facility housing said first computer, and at least one of information regarding a process used to verify said identity, procedural security controls of said first computer and how a secret is kept secure; and
,allowing access to said second computer system provided that said data substantially complies with said predetermined class established by said second computer system.
-
Specification