Multi-factor authentication for managed applications using single sign-on technology
View Patent ↗Disclosed are various examples for facilitating multi-factor authentication for client applications that are configured to use single sign-on technology. An authentication request for a first client application executed in a client device is received by an identity provider. The identity provider then receives data generated by a single sign-on credential from the client device. The single sign-on credential is configured to be used by multiple client applications of the client device. The data generated by the single sign-on credential is verified by the identity provider. The identity provider requests one or more supplementary authentication factors from a second client application. The identity provider then receives the supplementary authentication factor(s) from the second client application and verifies the supplementary authentication factor(s). The identity provider generates an authentication token and sends the token to the first client application.
1. A non-transitory computer-readable medium embodying a program executable in at least one computing device, the program, when executed by the at least one computing device, being configured to cause the at least one computing device to at least:
receive an authentication request for a first client application executed in a client device;
receive data generated by a single sign-on credential from the client device as part of a single sign-on process, the single sign-on credential being configured to be used by a plurality of client applications of the client device;
verify the data generated by the single sign-on credential;
determine whether at least one supplementary authentication factor is required from a second client application by:
determining a version of an operating system of the client device; and
determining that the at least one second authentication factor should be requested when the version of the operating system corresponds to a particular operating system version;
when the at least one supplementary authentication factor is required, and prior to sending an authentication token to the first client application:
request the at least one supplementary authentication factor from the second client application;
receive the at least one supplementary authentication factor from the second client application; and
verify the at least one supplementary authentication factor prior to allowing the first client application to be authenticated in the single sign-on process;
in response to verifying the data generated by the single sign-on credential and verifying the at least one supplementary authentication factor from the second client application, generate the authentication token; and
send the authentication token to the first client application.
2. The non-transitory computer-readable medium of claim 1 , wherein the single sign-on credential comprises at least one of: a secure certificate or a Kerberos profile.
3. The non-transitory computer-readable medium of claim 1 , wherein the second client application is executed in the client device.
4. The non-transitory computer-readable medium of claim 1 , wherein the second client application is executed in a different client device.
5. The non-transitory computer-readable medium of claim 1 , wherein the first client application does not natively support authentication using the at least one supplemental authentication factor.
6. The non-transitory computer-readable medium of claim 1 , wherein the at least one supplementary authentication factor comprises at least one of: a one-time password, a smartcard, or a biometric identifier.
7. The non-transitory computer-readable medium of claim 1 , wherein the program, when executed by the at least one computing device, is further configured to cause the at least one computing device to:
send a response to the authentication request to the first client application, the response requesting authentication by the single sign-on credential, wherein the authentication request is redirected from a service provider for which authentication is desired.
8. A system, comprising:
at least one computing device; and
an identity provider service executable by the at least one computing device, the identity provider service configured to cause the at least one computing device to at least:
receive an authentication request for a first client application executed in a client device;
receive data generated by a single sign-on credential from the client device as part of a single sign-on process, the single sign-on credential being configured to be used by a plurality of client applications of the client device;
verify the data generated by the single sign-on credential;
determine whether at least one supplementary authentication factor is required from a second client application by:
determining a version of an operating system of the client device; and
determining that the at least one second authentication factor should be requested when the version of the operating system corresponds to a particular operating system version;
when the at least one supplementary authentication factor is required, and prior to sending an authentication token to the first client application;
request the at least one supplementary authentication factor from the second client application;
receive the at least one supplementary authentication factor from the second client application; and
verify the at least one supplementary authentication factor prior to allowing the first client application to be authenticated in the single sign-on process;
in response to verifying the data generated by the single sign-on credential and verifying the at least one supplementary authentication factor from the second client application, generate the authentication token; and
send the authentication token to the first client application.
9. The system of claim 8 , wherein the single sign-on credential comprises data generated by at least one of: a secure certificate or a Kerberos profile.
10. The system of claim 8 , wherein the authentication token is sent within a security assertion markup language (SAML) identity assertion.
11. The system of claim 8 , wherein the first client application does not natively support authentication using the at least one supplemental authentication factor.
12. The system of claim 8 , wherein the at least one supplementary authentication factor comprises at least one of: a one-time password, a smartcard, or a biometric identifier.
13. A method, comprising:
receiving an authentication request for a first client application executed in a client device;
receiving data generated by a single sign-on credential from the client device as part of a single sign-on process, the single sign-on credential being configured to be used by a plurality of client applications of the client device;
verifying the data generated by the single sign-on credential;
determining whether at least one supplementary authentication factor is required from a second client application by:
determining a version of an operating system of the client device; and
determining that the at least one second authentication factor should be requested when the version of the operating system corresponds to a particular operating system version;
when the at least one supplementary authentication factor is required, and prior to sending an authentication token to the first client application:
requesting the at least one supplementary authentication factor from the second client application;
receiving the at least one supplementary authentication factor from the second client application; and
verifying the at least one supplementary authentication factor prior to allowing the first client application to be authenticated in the single sign-on process;
in response to verifying the data generated by the single sign-on credential and verifying the at least one supplementary authentication factor from the second client application, generating the authentication token; and
sending the authentication token to the first client application.
14. The method of claim 13 , wherein the single sign-on credential comprises at least one of: a secure certificate or a Kerberos profile.
15. The method of claim 14 , wherein the first client application is configured to request a session token from a service provider using the authentication token.
16. The method of claim 13 , wherein the first client application does not natively support authentication using the at least one supplemental authentication factor.
17. The method of claim 13 , wherein the at least one supplementary authentication factor comprises at least one of: a one-time password, a smartcard, or a biometric identifier.
18. The method of claim 13 , further comprising:
sending a response to the authentication request to the first client application, the response requesting authentication by the single sign-on credential, wherein the authentication request is redirected from a service provider for which authentication is desired.
19. The method of claim 13 , wherein the at least one supplemental authentication factor is requested in response to the data generated by the single sign-on credential being verified.
20. The method of claim 13 , further comprising determining that the at least one supplemental authentication factor is necessary based at least in part on the first client application.