IP Library Granted Patent US 9,361,451
Granted Patent B2
US 9,361,451 · App. 14/271,258 · Granted Jun 7, 2016

System and method for enforcing a policy for an authenticator device

Inventors: Jonathan Oberheide (Ann Arbor, MI); Dug Song (Ann Arbor, MI); Adam Goodman (Ann Arbor, MI)
Assignee: Duo Security, Inc.
G06F21/45G06F21/34
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,361,451
App. No.
14/271,258
Granted
Jun 7, 2016
Kind
B2
Abstract

A system and method including defining at least one device authentication policy; at a policy engine, initializing authentication policy processing for an authenticator device; collecting device status assessment; evaluating policy compliance of the device status assessment to an associated defined device authentication policy; and enforcing use of the authenticator device according to the policy compliance.

Claims (26)

1. A method for authentication on an electronic authenticator device comprising:

defining at least one authenticator device authentication policy;

collecting an authenticator device status assessment;

evaluating policy compliance of the authenticator device status assessment to an associated defined authenticator device authentication policy; and

enforcing use of the authenticator device according to the policy compliance comprising:

if the policy compliance indicates the authenticator device status assessment is in compliance with the authenticator device authentication policy, allowing the authenticator device to be used as an authentication factor; and

if the policy compliance indicates the authenticator device status assessment is not in compliance with the authenticator device authentication policy, preventing the authenticator device from being used as an authentication factor.

2. The method of claim 1 , wherein upon receiving an authentication policy request at a policy engine, initializing authentication policy processing for an authenticator device.

3. The method of claim 1 , wherein collecting authenticator device status assessment includes collecting at least one application version number of an application on the authenticator device.

4. The method of claim 3 , wherein collecting authenticator device status assessment is performed at an authenticator on the authenticator device, and further comprises, the authenticator communicating the device status assessment to a policy engine.

5. The method of claim 1 , wherein collecting authenticator device status assessment includes collecting a vulnerability assessment.

6. The method of claim 5 , wherein collecting a vulnerability assessment includes identifying a vulnerability assessment from an object identifier for an operative object of the authenticator device.

7. The method of claim 5 , further comprising periodically collecting a vulnerability assessment and generating a historical view of the device status as part of the authenticator device status assessment used in evaluating policy compliance.

8. The method of claim 1 , wherein the at least one authenticator device authentication policy is defined through an administrator user interface.

9. The method of claim 8 , wherein a plurality of different authenticator device authentication policies are defined for a plurality of different accounts of an authentication system; and a policy engine selects the authenticator device authentication policy for evaluation according to a mapping between the authenticator device and an account.

10. The method of claim 1 , wherein a policy engine is integrated with an authentication system in a cloud computing environment.

11. The method of claim 1 , wherein allowing the authenticator device to be used as an authentication factor comprises allowing the authenticator device to facilitate transferring a passcode; and preventing the authenticator device from being used as an authentication factor comprises preventing the authenticator device from facilitating transfer of the passcode.

12. The method of claim 11 , wherein enforcing use of the authenticator device further includes facilitating an authenticator device update to comply with the associated authenticator device authentication policy.

13. The method of claim 12 , further comprising upon completing the authenticator device update, evaluating policy compliance and enforcing use of the authenticator device for at least a second time.

14. The method of claim 11 , wherein allowing the authenticator device to be used as an authentication factor and preventing the authenticator device from being used as an authentication factor are executed on the authenticator device.

15. The method of claim 11 , wherein allowing the authenticator device to be used as an authentication factor and preventing the authenticator device from being used as an authentication factor are executed in a cloud-based authentication system.

16. The method of claim 11 , further comprising at an authenticator of the authenticator device, receiving the passcode; wherein allowing the authenticator device to be used as an authentication factor comprises displaying the passcode; and wherein preventing the authenticator device from being used as an authentication factor comprises not displaying the passcode.

17. The method of claim 11 , further comprising at an authenticator of the authenticator device receiving the passcode; and wherein preventing the authenticator device from being used as an authentication factor comprises invalidating the passcode for authentication.

18. The method of claim 1 , wherein preventing the authenticator device from being used as an authentication factor comprises transmitting a message to an authentication system, the message instructing the authentication system to not accept authentication from the authenticator device.

19. The method of claim 1 , further comprising at a policy engine, initializing authentication policy processing for an authenticator device.

20. The method of claim 1 , wherein allowing the authenticator device to be used as an authentication factor comprises allowing the authenticator device to be used as a secondary authentication factor during or after authentication by a primary authentication factor; wherein the primary authentication factor is distinct from the secondary authentication factor.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 11, 2021
From: DUO SECURITY LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 056208/0504 →
CHANGE OF NAME Recorded May 11, 2021
From: DUO SECURITY, INC.
To: DUO SECURITY LLC
Reel/Frame 056210/0008 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 10, 2018
From: OBERHEIDE, JONATHAN; SONG, DUG; GOODMAN, ADAM
To: DUO SECURITY, INC.
Reel/Frame 046826/0298 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 10, 2018
From: OBERHEIDE, JONATHAN; SONG, DUG; GOODMAN, ADAM
To: DUO SECURITY, INC.
Reel/Frame 046826/0341 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 6, 2014
From: OBERHEIDE, JONATHAN; SONG, DUG; GOODMAN, ADAM
To: DUO SECURITY, INC.
Reel/Frame 032834/0381 →
Continuity (3)
Continuation 13647166 · Oct 8, 2012
Provisional Application 61544273 · Oct 7, 2011
Related Publication 20140245379A1 · Aug 28, 2014