×

Intercept-based multifactor authentication enrollment of clients as a network service

  • US 10,701,056 B2
  • Filed: 01/18/2019
  • Issued: 06/30/2020
  • Est. Priority Date: 09/30/2016
  • Status: Active Grant
First Claim
Patent Images

1. A system, comprising:

  • a processor configured to;

    monitor a session at a firewall;

    intercept a request for access to a resource while monitoring the session at the firewall;

    determine that a user associated with the session is not enrolled for multifactor authentication;

    trigger a workflow for a multifactor authentication client enrollment service provided by the firewall to initiate enrollment of the user for the multifactor authentication if the resource is associated with an authentication profile for multifactor authentication; and

    allow access to the resource prior to completing the enrollment of the user for the multifactor authentication, wherein the user is allowed access to the resource for a predetermined grace period of time prior to being required to complete the enrollment of the user for the multifactor authentication; and

    register each authentication factor of the multifactor authentication only one time per user using the multifactor authentication client enrollment service, independent of a number of applications or resources protected by the multifactor authentication, wherein the firewall enforces an authentication policy that includes one or more multifactor authentication rules for the resource and one or more distinct multifactor authentication rules for another resource; and

    a memory coupled to the processor and configured to provide the processor with instructions.

View all claims
  • 0 Assignments
Timeline View
Assignment View
    ×
    ×