Conditional login promotion

US10237254B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10237254-B2
Application numberUS-201514780528-A
CountryUS
Kind codeB2
Filing dateMar 27, 2015
Priority dateNov 13, 2014
Publication dateMar 19, 2019
Grant dateMar 19, 2019

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

The present disclosure relates to a system and method for providing conditional login promotion. An example system includes at least one processor and at least one memory element, wherein the system is configured for receiving an indication of a local operating system login by a user from a client device associated with the user; receiving one or more authentication factors associated with the user from the client device; and determining whether the local operating system login is to be promoted to a relying party entity based upon the one or more authentication factors associated with the user.

First claim

Opening claim text (preview).

The invention claimed is: 1. A system for authentication comprising at least one processor and at least one memory element, wherein the system is configured for: receiving an indication of a local operating system login by a user from a client device associated with the user; receiving one or more authentication factors associated with the user from the client device; and determining whether the local operating system login is to be promoted to a plurality of relying party entities based upon the one or more authentication factors associated with the user; wherein, each of the plurality of relying party entities comprise at least one server, configured to provide at least one of data and services to the client device. 2. The system of claim 1 , wherein determining whether the local operating system login is to be promoted to the plurality of relying party entities includes determining whether the one or more authentication factors meet a required level of security. 3. The system of claim 2 , wherein the system is further configured for promoting the local operating system login to the plurality of relying party entities responsive to determining that the authentication factors meet the required level of security. 4. The system of claim 3 , wherein promoting the local operating system login to each of the plurality of relying party entities includes authorizing the client device to access one or more resources associated with each of the plurality of relying party entities. 5. The system of claim 4 , wherein the one or more resources include at least one of a service provided by each of the plurality of relying party entities or an application provided by each of the plurality of relying party entities. 6. The system of claim 3 , wherein the system is further configured for establishing an active session between the client device and each of the plurality of relying party entities responsive to promoting the local operating system login to each of the plurality of relying party entities. 7. The system of claim 1 , wherein the one or more authentication factors include one or more of at least one active authentication factor and at least one passive authentication factor. 8. The system of claim 7 , wherein the at least one active authentication factor includes a biometric authentication factor. 9. The system of claim 8 , wherein the biometric authentication factor includes facial recognition of the user. 10. The system of claim 7 , wherein the at least one active authentication factor includes a liveliness indication of the user. 11. The system of claim 7 , wherein the at least one passive authentication factor includes a device identifier associated with the client device. 12. At least one non-transitory computer storage medium to store computer code comprising: computer code to receive an indication of a local operating system login by a user from a client device associated with the user; computer code to receive one or more authentication factors associated with the user from the client device; and computer code to determine whether the local operating system login is to be promoted to a plurality of relying party entities based upon the one or more authentication factors associated with the user; wherein, each of the plurality of relying party entities comprise at least one server, configured to provide at least one of data and services to the client device. 13. The at least one non-transitory computer storage medium of claim 12 , wherein determining whether the local operating system login is to be promoted to each of the plurality of relying party entities includes determining whether the one or more authentication factors meet a required level of security. 14. The at least one non-transitory computer storage medium of claim 13 , wherein the system is further configured for promoting the local operating system login to each of the plurality of relying party entities responsive to determining that the authentication factors meet the required level of security. 15. The at least one non-transitory computer storage medium of claim 14 , wherein promoting the local operating system login to each of the plurality of relying party entities includes authorizing the client device to access one or more resources associated with each of the plurality of relying party entities. 16. The at least one non-transitory computer storage medium of claim 15 , wherein the one or more resources include at least one of a service provided by each of the plurality of relying party entities or an application provided by each of the plurality of relying party entities. 17. The at least one non-transitory computer storage medium of claim 14 , wherein the system is further configured for establishing an active session between the client device and each of the plurality of relying party entities responsive to promoting the local operating system login to each of the plurality of relying party entities. 18. The at least one non-transitory computer storage medium of claim 12 , wherein the one or more authentication factors include one or more of at least one active authentication factor and at least one passive authentication factor. 19. The at least one non-transitory computer storage medium of claim 18 , wherein the at least one active authentication factor includes a biometric authentication factor. 20. The at least one non-transitory computer storage medium of claim 19 , wherein the biometric authentication factor includes facial recognition of the user. 21. The at least one non-transitory computer storage medium of claim 18 , wherein the at least one active authentication factor includes a liveliness indication of the user. 22. The at least one non-transitory computer storage medium of claim 18 , wherein the at least one passive authentication factor includes a device identifier associated with the client device. 23. A system comprising at least one processor and at least one memory element, wherein the system is configured for: generating a token within a secure element of a client device associated with a user; sending the token to a server; receiving one or more first biometric authentication factors associated with the user; and sending the one or more first biometric authentication factors to the server, wherein the server is configured to associate the token with the one or more biometric authentication factors; wherein, the server is configured to provide at least one of data and services to the client device from a plurality of relying parties based on the authentication of the token. 24. At least one non-transitory computer storage medium to store computer code comprising: computer code to generate a token within a secure element of a client device associated with a user; computer code to send the token to a server; computer code to receive one or more first biometric authentication factors associated with the user; and computer code to send the one or more first biometric authentication factors to the server, wherein the server is configured to associate the token with the one or more biometric authentication factors wherein, the server is configured to provide at least one of data and services to the client device from a plurality of relying parties based on the authentication of the token. 25. The at least one non-transitory computer storage medium of claim 24 , further comprising: computer code to capture one or mo

Assignees

Inventors

Classifications

  • applying multi-factor authentication · CPC title

  • by delegation of authentication, e.g. a proxy authenticates an entity to be authenticated on behalf of this entity vis-à-vis an authentication entity · CPC title

  • H04L9/321Primary

    involving a third party or a trusted authority · CPC title

  • H04L63/08Primary

    for authentication of entities (cryptographic mechanisms or cryptographic arrangements for entity authentication H04L9/32) · CPC title

  • Multiple levels of security · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10237254B2 cover?
The present disclosure relates to a system and method for providing conditional login promotion. An example system includes at least one processor and at least one memory element, wherein the system is configured for receiving an indication of a local operating system login by a user from a client device associated with the user; receiving one or more authentication factors associated with the …
Who is the assignee on this patent?
Mcafee Llc
What technology area does this patent fall under?
Primary CPC classification H04L9/321. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Mar 19 2019 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 2 related publications on this page (citations in our corpus or others sharing the same primary CPC).