Multi-dimensional framework for defining criteria that indicate when authentication should be revoked
First Claim
Patent Images
1. An aggregator system comprising:
- a storage system configured to store;
authentication information associated with a client device, wherein the authentication information indicates that the client device has been authenticated,first rules information received from a first interested party,second rules information received from a second interested party, wherein the first rules information and the second rules information each comprise respective rules of at least two different rule types selected from the group consisting of;
a predetermined number of uses of the client device, an event identifying the device as lost, an event identifying the client device as stolen, an event identifying a deactivated mobile number associated with the client device, an event identifying a fraud alert associated with the client device, a detected change between previously stored hashed information associated with the client device and current hashed information associated with the client device, a change in geographic location of the client device, detected mismatch in biometric authentication associated with the client device, an event identifying a change of account ownership associated with the client device, and an event identifying that an account associated with the client device has a payment status of past-due;
circuitry implementing a credentials engine configured to;
reconcile the respective rules of the first rules information and the second rules information having the same rule type based on a priority associated with each of the respective rules;
define criteria indicating when authentication of the client device will be revoked based on the authentication information and on the reconciling; and
invalidation circuitry configured to revoke authentication for the identified client device based on the criteria.
3 Assignments
0 Petitions
Accused Products
Abstract
Methods and systems are presented for defining criteria that indicate when authentication for an identified client device should be revoked based on rules associated with interested parties. Authentication information is stored that indicates that an identified client device is authenticated. Rules that are associated with a plurality of interested parties and include rules of different rule types may also be stored. Criteria may be defined based on the rules and the authentication information, the criteria indicating when authentication of the identified client device should be revoked. Authentication of the identified client device may be revoked based on the criteria.
-
Citations
20 Claims
-
1. An aggregator system comprising:
-
a storage system configured to store; authentication information associated with a client device, wherein the authentication information indicates that the client device has been authenticated, first rules information received from a first interested party, second rules information received from a second interested party, wherein the first rules information and the second rules information each comprise respective rules of at least two different rule types selected from the group consisting of;
a predetermined number of uses of the client device, an event identifying the device as lost, an event identifying the client device as stolen, an event identifying a deactivated mobile number associated with the client device, an event identifying a fraud alert associated with the client device, a detected change between previously stored hashed information associated with the client device and current hashed information associated with the client device, a change in geographic location of the client device, detected mismatch in biometric authentication associated with the client device, an event identifying a change of account ownership associated with the client device, and an event identifying that an account associated with the client device has a payment status of past-due;circuitry implementing a credentials engine configured to; reconcile the respective rules of the first rules information and the second rules information having the same rule type based on a priority associated with each of the respective rules; define criteria indicating when authentication of the client device will be revoked based on the authentication information and on the reconciling; and invalidation circuitry configured to revoke authentication for the identified client device based on the criteria. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10)
-
-
11. A method comprising:
-
storing, on a storage device, authentication information associated with an identified client device, wherein the authentication information indicates that the client device has been authenticated; storing, on the storage device, first rules information received from a first interested party; storing, on the storage device, second rules information received from a second interested party, wherein the first rules information and the second rules information each comprise respective rules of at least two different rule types selected from the group consisting of;
a predetermined number of uses of the client device, an event identifying the device as lost, an event identifying the client device as stolen, an event identifying a deactivated mobile number associated with the client device, an event identifying a fraud alert associated with the client device, a detected change between previously stored hashed information associated with the client device and current hashed information associated with the client device, a change in geographic location of the client device, detected mismatch in biometric authentication associated with the client device, an event identifying a change of account ownership associated with the client device, and an event identifying that an account associated with the client device has a payment status of past-due;reconciling, using a credentials engine, the respective rules of the first rules information and the second rules information having the same rule type based on a priority associated with each of the respective rules defining, using the credentials engine, criteria indicating when authentication of the client device will be revoked based on the authentication information and on the reconciling; and revoking, using invalidation circuitry, authentication for the identified client device based on the criteria. - View Dependent Claims (12, 13, 14, 15, 16, 17, 18, 19, 20)
-
Specification