×

Authentication policy orchestration for a user device

  • US 9,742,809 B1
  • Filed: 08/22/2016
  • Issued: 08/22/2017
  • Est. Priority Date: 07/28/2013
  • Status: Active Grant
First Claim
Patent Images

1. A server, comprising:

  • a network interface configured to be communicatively coupled to a network utilizing a secure communication protocol;

    at least one hardware processor configured to;

    implement authorization policies which are separately configurable between the authorization policies received from a relying party policy engine located on the server and the authorization policies received from an authorizing party policy engine located on at least one of a plurality of authorizing party user devices;

    obtain, from a client device via the network, a transaction request for a transaction;

    determine an authorization requirement for the transaction request based on the authorization policies as follows;

    a first policy of the authorization policies being configurable by the relying party policy engine but not the authorizing party policy engine;

    a second policy of the authorization policies being configurable by the authorizing party policy engine;

    a third policy of the authorization policies being based on risk factors related to the transaction and configurable by the relying party policy engine; and

    a fourth policy of the plurality of authorization policies based on a habit of at least one of the authorizing party user devices;

    obtain for the relying party policy engine a status of the plurality of the authorizing party user devices,provide a notification of the transaction and an associated transaction context;

    divide the transaction request into subtransaction authorization requests that are separately subject to approval by the plurality of authorizing party user devices and transmit the subtransaction authorization requests to the plurality of authorizing party user devices;

    receive authorization responses for the subtransaction authorization requests from the plurality of authorizing party user devices; and

    complete the transaction by approving the transaction based on the authorization requirement having been met.

View all claims
  • 4 Assignments
Timeline View
Assignment View
    ×
    ×