Nova Patents
CA2974536C

Authentication management services

Abstract

Disclosed are various embodiments for account management tor multiple network sites. Multiple accounts of a user arc maintained for multiple network sites in a computing device. A secured resource of a network site is to be accessed by the computing device. A new account is created, or an existing account is upgraded, in response to determining that the accounts are not capable of accessing the secured resource. A set of information about the user is provided to the network site to create, or upgrade, the account.

CA2974536C, drawing sheet 1
Sheet 1 of 12

Term

6.4 yearsleft in the term

Expires 30 January 2033.

  1. Priority and filed
  2. Granted
  3. Today
  4. Expires

13 claims: 2 independent, 11 dependent

  1. 1
    EMBODIMENTS IN WHICH AN EXCLUSIVE PROPERTY OR PRIVILEGE IS CLAIMED ARE DEFINED AS FOLLOWS:1. A system, comprising: at least one computing device;and an authentication service executable in the at least one computing device, the authentication service comprising: logic that obtains a first authentication request by way of an authentication protocol from a first authentication management client application executed in a first client computing device, the first authentication request specifying a first security credential associated with a first user account;logic that authenticates the first user account at the first client computing device for access to at least one secured resource of a network site hosted by at least one other computing device in response to the first authentication request;logic that obtains a second authentication request by way of the authentication protocol from a second authentication management client application executed in a second client computing device, the second authentication request specifying a second security credential associated with a second user account;and logic that authenticates the second user account at the second client computing device for access to the at least one secured resource of the network site in response to the second authentication request, CA 2974536 2017-07-21 wherein the first authentication management client application and the second authentication management client application are different authentication management client applications deployed by different providers of authentication management services.
  2. 7
    A non-transitory computer-readable medium embodying at least one program executable in a client computing device, the at least one program comprising:code that decrypts a security credential associated with a user account stored by a first authentication management client in response to receiving a master security credential from an input device of the client computing device, wherein the security credential is stored in the client computing device in an encrypted form;code that sends a first authentication request using the first authentication management client by way of an authentication protocol to an authentication service associated with a first secured resource of a network site, the first authentication request specifying the security credential associated with the user account;CA 2974536 2017-07-21 code that accesses the first secured resource after being authenticated by the authentication service in response to the first authentication request;code that imports the user account and the decrypted security credential associated with the user account from the first authentication management client into a second authentication management client configured to interact with a second secured resource;code that sends a second authentication request using the second authentication management client by way of the authentication protocol to the authentication service, the second authentication request specifying the decrypted security credential;code that accesses the second secured resource after being authenticated by the authentication service in response to the second authentication request;code that, in response to receiving a denial of an access request to another secured resource, sends an account upgrade request for the user account using the second authentication management client to the authentication service, wherein the account upgrade request seeks a permission for the user account associated with the user to access the another secured resource and specifies a set of information about the user;and code that accesses the another secured resource of the network site after the user account receives the permission to access the another secured resource. CA 2974536 2017-07-21
  3. 9
    A method, comprising:obtaining, in at least one computing device, a first authentication request by way of an authentication protocol from a first authentication management client application executed in a first client computing device, the first authentication request specifying a first security credential associated with a first user account;authenticating, in the at least one computing device, the first user account submitted by the first client computing device for access to at least one secured resource of a network site hosted by at least one other computing device in response to the first authentication request;obtaining, in the at least one computing device, a second authentication request by way of the authentication protocol from a second authentication management client application executed in a second client computing device, the second authentication request specifying a second security credential associated with a second user account;authenticating, in the at least one computing device, the second user account submitted by the second client computing device for access to the at least one secured resource of the network site in response to the second authentication request;and wherein the first authentication management client application and the second authentication management client application are different CA 2974536 2017-07-21 10. 11. 12. authentication management client applications deployed by different providers of authentication management services. The method of claim 9, further comprising: sending, in the at least one computing device, branded experience data to the first authentication management client application and the second authentication management client application;and wherein the first authentication management client application is configured to customize a first user interface in the first client computing device based at least in part on the branded experience data, and the second authentication management client application is configured to customize a second user interface in the second client computing device based at least in part on the branded experience data. The method of claim 9, further comprising: determining, in the at least one computing device, whether the first authentication management client application is supported in response to the first authentication request;and determining, in the at least one computing device, whether the second authentication management client application is supported in response to the second authentication request. The method of claim 9, further comprising: obtaining, in the at least one computing device, a request to change the first security credential for the first user account after authentication, the CA 2974536 2017-07-21 request to change the first security credential originating automatically in the first authentication management client application;and establishing, in the at least one computing device, a new security credential for the first user account in response to the request to change the first security credential.