System and method for graduated security in user authentication
US-9195820-B2 · Nov 24, 2015 · US
US10776477B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-10776477-B2 |
| Application number | US-201815921547-A |
| Country | US |
| Kind code | B2 |
| Filing date | Mar 14, 2018 |
| Priority date | Dec 8, 2010 |
| Publication date | Sep 15, 2020 |
| Grant date | Sep 15, 2020 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
There is presented a system and method for coordinating asset entitlements, the system comprising a server including a processor and a memory and accessible by multiple domains over a network, and an asset entitlement database searchable by the server, wherein an entry of the asset entitlement database links a domain transcendent user identification (ID) of a user and at least one asset entitlement acquired by the user from any of the domains. In one embodiment, the server is configured to receive an asset entitlement inquiry from one of the domains, search the asset entitlement database for asset entitlements acquired by the user from any of the domains, generate a search result identifying the asset entitlements acquired by the user from the domains, and send data corresponding to the search result to the domain from which the asset entitlement inquiry was received.
Opening claim text (preview).
What is claimed is: 1. A server comprising: a processor; a memory; and an asset entitlement database stored in the memory, wherein an entry of the asset entitlement database links a domain transcendent user ID of a user to at least one asset entitlement acquired by the user from any of a plurality of domains; the processor configured to: receive an asset entitlement inquiry including a domain specific user ID of the user from one of the plurality of domains; determine, in response to receiving the asset entitlement inquiry, the domain transcendent user ID associated with the domain specific user ID, wherein the domain transcendent user ID identifies the user to all of the plurality of domains, and the domain specific user ID identifies the user to the one of the plurality of domains only; search, using the domain transcendent user ID, the asset entitlement database for asset entitlements previously acquired by the user from all of the plurality of domains; generate, based on the search, a search result identifying the asset entitlements previously acquired by the user from all of the plurality of domains; filter the search result to omit one or more identified asset entitlements for which the one of the plurality of domains lacks at least one of a domain asset right or a domain entitlement right; and send the filtered search result to the one of the plurality of domains. 2. The server of claim 1 , wherein the plurality of domains comprise secure domains. 3. The server of claim 1 , wherein the one of the plurality of domains to which the filtered search result is sent comprises an authorized domain. 4. The server of claim 1 , wherein the domain transcendent user ID comprises an ID generated by a trusted third-party identity provider. 5. The server of claim 1 , wherein the processor is further configured to identify the one of the plurality of domains as authorized to submit the asset entitlement inquiry to the server, before the server sends the filtered search result to the one of the plurality of domains. 6. The server of claim 1 , wherein at least one of the asset entitlements previously acquired by the user corresponds to an asset selected from one of digital movie content, digital music content, or digital literary content. 7. The server of claim 1 , wherein the asset entitlements comprise one or more of a user asset right or a user entitlement right, wherein the user asset right comprises a right to enjoy an asset by the user, and wherein the user entitlement right defines conditions governing enjoyment of the asset by the user. 8. The server of claim 7 , wherein the conditions governing enjoyment of the asset by the user are selected from one of licensing of the asset by the user, rental of the asset by the user, or subscription to the asset by the user. 9. The server of claim 1 , wherein the domain asset right comprises a right to provide an asset by a domain and the domain entitlement right defines conditions governing provision of the asset by the domain. 10. The server of claim 9 , wherein the conditions governing provision of the asset by the domain are selected from one of sale of the asset by the domain, rental of the asset by the domain, or transmission of the asset by the domain over a network. 11. A method for use by a server including a processor, a memory, and an asset entitlement database stored in the memory, an entry of the asset entitlement database linking a domain transcendent user ID of a user to at least one asset entitlement acquired by the user from any of a plurality of domains; receiving, by the processor, an asset entitlement inquiry including a domain specific user ID of the user from one of the plurality of domains; determining, by the processor, in response to receiving the asset entitlement inquiry, the domain transcendent user ID associated with the domain specific user ID, wherein the domain transcendent user ID identifies the user to all of the plurality of domains, and the domain specific user ID identifies the user to the one of the plurality of domains only; searching, by the processor using the domain transcendent user ID, the asset entitlement database for asset entitlements previously acquired by the user from all of the plurality of domains; generating, by the processor based on the search, a search result identifying the asset entitlements previously acquired by the user from all of the plurality of domains; filtering, by the processor, the search result to omit one or more identified asset entitlements for which the one of the plurality of domains lacks at least one of a domain asset right or a domain entitlement right; and sending, by the processor, the filtered search result to the one of the plurality of domains. 12. The method of claim 11 , wherein the plurality of domains comprise secure domains. 13. The method of claim 11 , wherein the one of the plurality of domains to which the filtered search result is sent comprises an authorized domain. 14. The method of claim 11 , wherein the domain transcendent user ID comprises an ID generated by a trusted third-party identity provider. 15. The method of claim 11 further comprises: identifying, by the processor, the one of the plurality of domains as authorized to submit the asset entitlement inquiry to the server, before the server sends the filtered search result to the one of the plurality of domains. 16. The method of claim 11 , wherein at least one of the asset entitlements previously acquired by the user corresponds to an asset selected from one of digital movie content, digital music content, or digital literary content. 17. The method of claim 11 , wherein the asset entitlements comprise one or more of a user asset right or a user entitlement right, wherein the user asset right comprises a right to enjoy an asset by the user and wherein the user entitlement right defines conditions governing enjoyment of the asset by the user. 18. The method of claim 17 , wherein the conditions governing enjoyment of the asset by the user are selected from one of licensing of the asset by the user, rental of the asset by the user, or subscription to the asset by the user. 19. The method of claim 11 , wherein the domain asset right comprises a right to provide an asset by a domain and the domain entitlement right defines conditions governing provision of the asset by the domain. 20. The method of claim 19 , wherein the conditions governing provision of the asset by the domain are selected from one of sale of the asset by the domain, rental of the asset by the domain, or transmission of the asset by the domain over a network.
where a single sign-on provides access to a plurality of computers · CPC title
between heterogeneous systems · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.