CPC H04L 63/105 (2013.01) [H04L 63/083 (2013.01); H04L 63/108 (2013.01)] | 19 Claims |
1. A computer-executed method comprising:
generating a particular session identifier for a session of a client of an application;
wherein the application supports a plurality of authentication tiers;
wherein each authentication tier, of the plurality of authentication tiers, is associated with one or more respective authentication steps of a plurality of authentication steps;
wherein the plurality of authentication tiers includes (a) a higher-security authentication tier that allows first one or more restricted actions, and (b) a lower-security authentication tier that allows second one or more restricted actions;
authenticating the client to the higher-security authentication tier;
based on said authenticating the client to the higher-security authentication tier, maintaining, on a server device that remote from the client, authentication-tier data that identifies an authentication tier for the session by associating the particular session identifier with the higher-security authentication tier;
detecting an explicit request to downgrade the authentication tier associated with the particular session identifier;
in response to detecting the explicit request to downgrade, downgrading the authentication tier of the session by updating the authentication-tier data to associate the particular session identifier with the lower-security authentication tier;
wherein the method is performed by one or more computing devices.
|