发明名称 Using Third Party Information To Improve Predictive Strength for Authentications
摘要 Embodiments of the present invention are directed to methods and systems for utilizing the history of previous authentications and authorizations related to third party computers, as factors in determining whether a current request for accessing a resource should be authorized. A processor server computer, in determining whether to authorize access to the resource, may generate and send a query message to one or more of the third party computers to obtain authorization activity that the third party computers may have regarding a user and/or a device associated with the request. The processor server computer may use the authorization activity from the third party computers in determining whether the request is an authentic request and that the request should be authorized.
申请公布号 US2016127374(A1) 申请公布日期 2016.05.05
申请号 US201514934063 申请日期 2015.11.05
申请人 O'Connell Craig;Srivastava Aditya;Wong Kevin 发明人 O'Connell Craig;Srivastava Aditya;Wong Kevin
分类号 H04L29/06;G06F17/30;G06F17/27;H04L29/08 主分类号 H04L29/06
代理机构 代理人
主权项 1. A method comprising: receiving, by a server computer from a first electronic device, a request for authorization to access a resource, the request including request identification data to be used in determining whether to provide the access to the resource, the request identification data including one or more request identifiers; determining, by the server computer, that at least one of the request identifiers in the request corresponds to a profile, the profile including one or more profile identifiers; retrieving, by the server computer, a query template that includes a plurality of identifier tags, the query template including an API for requesting information about the identifier tags, wherein each identifier tag corresponds to a different type of identifier; generating, by the server computer, a query message using the query template by inserting at least one of the request identifiers and the profile identifiers into the query template in association with the corresponding identifier tags; sending, by the server computer over a network, the query message to a plurality of third party servers that implement the API; receiving, by the server computer, a plurality of query responses from the plurality of third party servers, the query responses including one or more authorization activity entries for each of one or more of the identifier tags; for each of a plurality of the authorization activity entries: retrieving, by the server computer, an activity value from the authorization activity entry,assigning, by the server computer, a weight to the activity value to obtain a weighted value, andapplying, by the server computer, the weighted value to an authorization model; determining, by the server computer, an authorization response based on a result of the authorization model; and sending, by the server computer to the first electronic device, the authorization response instructing the first electronic device as to whether to grant access to the resource.
地址 San Mateo CA US