US 11,888,839 B1
Continuous authentication through orchestration and risk calculation post-authentication system and method
Shahrokh Shahidzadeh, Portland, OR (US); Nadal Shahidzadeh, Portland, OR (US); Christopher Clifford, Portland, OR (US); Haitham Akkary, Portland, OR (US); and Seyedamir Karimikho, Surrey (CA)
Assigned to SecureAuth Corporation, Irvine, CA (US)
Filed by SecureAuth Corporation, Irvine, CA (US)
Filed on Jan. 9, 2023, as Appl. No. 18/094,787.
Application 18/094,787 is a continuation of application No. 17/201,893, filed on Mar. 15, 2021, granted, now 11,552,940.
Application 17/201,893 is a continuation of application No. 17/112,913, filed on Dec. 4, 2020, granted, now 10,951,606.
Claims priority of provisional application 62/943,767, filed on Dec. 4, 2019.
Int. Cl. H04L 29/06 (2006.01); H04L 9/40 (2022.01); H04W 4/14 (2009.01); H04W 4/029 (2018.01); G06F 21/45 (2013.01)
CPC H04L 63/0815 (2013.01) [H04L 63/0807 (2013.01); H04W 4/029 (2018.02); H04W 4/14 (2013.01)] 9 Claims
OG exemplary drawing
 
1. A method for secure authentication of a user entity identity comprising:
a primary identity provider allows a user entity through a client device to enable a single sign on to a plurality of services; the primary identity provider collects the contextual and behavioral information of the user entity and the client device for access to at least one service of the plurality of services; delegates login and authentication process including a risk based multi-factor authentication to a third party Identity provider; the primary identity provider sends the contextual and behavioral information including at least one service identifier, a user identification, the client device, client device browser health, location, time, network, client device and client device browser fingerprint, network and other attributes to the third party identity provider so the third party identity provider with its discrete risk engine; and conducts policy orchestration upon detection of anomaly of the at least one service and takes a predetermined action per policy and risk such as terminate the specific service and session or step up authorization using a new discrete multi-factor authorization.