- 专利标题: Conditionally-deferred authentication steps for tiered authentication
-
申请号: US16836813申请日: 2020-03-31
-
公开(公告)号: US11483312B2公开(公告)日: 2022-10-25
- 发明人: Hyunsuk Han , Mahesh Acharya
- 申请人: LendingClub Corporation
- 申请人地址: US CA San Francisco
- 专利权人: LendingClub Corporation
- 当前专利权人: LendingClub Corporation
- 当前专利权人地址: US CA San Francisco
- 代理机构: Hickman Becker Bingham Ledesma LLP
- 主分类号: H04L29/06
- IPC分类号: H04L29/06 ; H04L9/40
摘要:
Techniques are described herein for using special session identifiers to defer additional authentication steps (AAS) for at least some restricted application actions. A client session is associated with a special session identifier that is mapped to an authentication tier (AT) achieved for the session based on the satisfied authentication steps. Web servers that are enabled for AAS deferral include context information, which identifies a requested action, with session verification requests to an authentication service. The authentication service determines that AAS is required to perform an action when (a) the AT associated with the action is a higher-security tier than the AT associated with the session, or (b) the session is associated with an AT that is lower than the highest-security AT and there is no context information accompanying the request for session validation, in which case the authentication service assumes that the highest-security AT is required to perform the request.
公开/授权文献
信息查询