IP Library Granted Patent US 9,781,096
Granted Patent B2
US 9,781,096 · App. 15/192,682 · Granted Oct 3, 2017

System and method for out-of-band application authentication

Inventors: Yair Sade (Herzelia, IL); Andrey Dulkin (Herzelia, IL)
Assignee: Cyber-Ark Software Ltd.
H04L63/08G06F21/42G06F21/44G06F21/52H04L63/10H04L67/42
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,781,096
App. No.
15/192,682
Granted
Oct 3, 2017
Kind
B2
Abstract

Application-to-Application authentication features using a second communication channel for out-of-band authentication separate from a communication channel of a request from a client to a server. Authentication information is associated with a component of the system such as the request or the client application, while being collected independent of interaction with the client application initiating the request. Implementations provide improved security over existing solutions using in-band or other means of collecting authentication information.

Claims (63)

1. A network server comprising:

at least one processor configured to:

receive from a client machine, via a first communications channel between the network server and the client machine, a request by a client application executed at the client machine to access a network resource;

based on the request, establish a second communications channel between the network server and the client machine, wherein the second communications channel is out-of-band with respect to the first communications channel;

receive from the client machine, via the second communications channel, authentication information specific to the client application for authenticating the client application, wherein the authentication information includes information indicating at least one distinguishing characteristic of the client application and is collected independently of and without interaction with the client application, wherein the distinguishing characteristic is computed based on a unique attribute of the client application; and

based on the authentication information, determine whether to validate the request and provide the client application access to the network resource.

2. The network server of claim 1 , wherein the request includes credentials associated with the client machine.

3. The network server of claim 1 , wherein establishing the second communications channel comprises establishing the second communications channel between the network server and an authentication agent executed at the client machine, the authentication agent being distinct from the client application.

4. The network server of claim 3 , wherein receiving the authentication information comprises receiving authentication information collected by the authentication agent.

5. The network server of claim 1 , wherein receiving the authentication information comprises:

querying the client machine for the authentication information via the second communications channel; and

in response to querying the client machine, receiving the authentication information.

6. The network server of claim 1 , wherein the second communications channel being out-of-band with respect to the first communications channel comprises:

the first communications channel being established between the network server and a first port at the client machine;

the second communications channel being established between the network server and a second port at the client machine; and

the first port is different than the second port.

7. The network server of claim 1 , wherein:

determining whether to validate the request and provide the client application access to the network resource comprises determining whether the at least one distinguishing characteristic has changed.

8. The network server of claim 1 , wherein the second communications channel comprises a secure communications channel.

9. The network server of claim 1 , wherein the network resource comprises a database.

10. The network server of claim 1 , wherein establishing the second communications channel based on the request comprises:

performing a preliminary request validation on the request; and

establishing the second communications channel based on the preliminary request validation.

11. A non-transitory computer readable medium including instructions that, when executed by at least one processor, cause the at least one processor to perform operations comprising:

receiving at a network server from a client machine, via a first communications channel between the network server and the client machine, a request by a client application executed at the client machine to access a network resource;

based on the request, establishing a second communications channel between the network server and the client machine, wherein the second communications channel is out-of-band with respect to the first communications channel;

receiving from the client machine, via the second communications channel, authentication information specific to the client application for authenticating the client application, wherein the authentication information includes information indicating at least one distinguishing characteristics of the client application and is collected independently of and without interaction with the client application, wherein the distinguishing characteristic is computed based on a unique attribute of the client application; and

based on the authentication information, determining whether to validate the request and provide the client application access to the network resource.

12. The non-transitory computer readable medium of claim 11 , wherein the request includes credentials associated with the client machine.

13. The non-transitory computer readable medium of claim 11 , wherein establishing the second communications channel comprises establishing the second communications channel between the network server and an authentication agent executed at the client machine, the authentication agent being distinct from the client application.

14. The non-transitory computer readable medium of claim 13 , wherein establishing the second communications channel further comprises deploying the authentication agent to the client machine.

15. The non-transitory computer readable medium of claim 11 , wherein receiving the authentication information comprises:

querying the client machine for the authentication information via the second communications channel; and

in response to querying the client machine, receiving the authentication information.

16. The non-transitory computer readable medium of claim 11 , wherein the second communications channel being out-of-band with respect to the first communications channel comprises:

the first communications channel being established between the network server and a first port at the client machine;

the second communications channel being established between the network server and a second port at the client machine; and

the first port is different than the second port.

17. The non-transitory computer readable medium of claim 11 , wherein:

determining whether to validate the request and provide the client application access to the network resource comprises determining whether the at least one characteristic has changed.

18. The non-transitory computer readable medium of claim 11 , wherein the second communications channel comprises a secure communications channel.

19. The non-transitory computer readable medium of claim 11 , wherein the network resource comprises a database.

20. The non-transitory computer readable medium of claim 11 , wherein establishing the second communications channel based on the request comprises:

performing a preliminary request validation on the request; and

establishing the second communications channel based on the preliminary request validation.

21. A computer-implemented method comprising:

receiving at a network server from a client machine, via a first communications channel between the network server and the client machine, a request by a client application executed at the client machine to access a network resource;

based on the request, establishing a second communications channel between the network server and the client machine, wherein the second communications channel is out-of-band with respect to the first communications channel;

receiving from the client machine, via the second communications channel, authentication information specific to the client application for authenticating the client application, wherein the authentication information includes information indicating at least one distinguishing characteristic of the client application and is collected independently of and without interaction with the client application, wherein the distinguishing characteristic is computed based on a unique attribute of the client application; and

based on the authentication information, determining whether to validate the request and provide the client application access to the network resource.

22. The computer-implemented method of claim 21 , wherein the request includes credentials associated with the client machine.

23. The computer-implemented method of claim 21 , wherein establishing the second communications channel comprises establishing the second communications channel between the network server and an authentication agent executed at the client machine, the authentication agent being distinct from the client application.

24. The computer-implemented method of claim 21 , wherein receiving the authentication information comprises:

querying the client machine for the authentication information via the second communications channel; and

in response to querying the client machine, receiving the authentication information.

25. The computer-implemented method of claim 21 , wherein the second communications channel being out-of-band with respect to the first communications channel comprises:

the first communications channel being established between the network server and a first port at the client machine;

the second communications channel being established between the network server and a second port at the client machine; and

the first port is different than the second port.

26. The computer-implemented method of claim 21 , wherein:

determining whether to validate the request and provide the client application access to the network resource comprises determining whether the at least one characteristic has changed.

27. The network server of claim 5 , wherein querying the client machine comprises querying an operating system of the client machine for the authentication information via the second communications channel.

28. The network server of claim 7 , wherein the at least one distinguishing characteristic includes at least one of: (i) a size of a file or directory of the client application, (ii) a result of a hash-function calculation on a component of the client application, and (iii) a result of a hash-function calculation on an executable file of the client application.

Assignments (2)
CHANGE OF NAME Recorded Oct 17, 2017
From: CYBER-ARK SOFTWARE LTD.
To: CYBERARK SOFTWARE LTD.
Reel/Frame 044218/0539 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 31, 2017
From: SADE, YAIR; DULKIN, ANDREY
To: CYBER-ARK SOFTWARE LTD.
Reel/Frame 043741/0576 →
Continuity (3)
Continuation 13911103 · Jun 6, 2013
Provisional Application 61668044 · Jul 5, 2012
Related Publication 20160308849A1 · Oct 20, 2016