IP Library Granted Patent US 12,273,382
Granted Patent B2
US 12,273,382 · App. 16/224,398 · Granted Apr 8, 2025

Multi-factor authentication

Inventors: Karl Ackerman (Topsfield, MA); John Edward Tyrone Shaw (Oxford, GB); Craig Paradis (Bolton, MA); Andrew J. Thomas (Oxfordshire, GB); Kenneth D. Ray (Seattle, WA)
Assignee: Sophos Limited
H04L63/1483G06F11/00G06F21/40G06F21/43G06F21/44G06F21/45G06F21/554G06F21/566G06F21/57G06F21/64H04L9/3213H04L41/0631H04L41/142H04L43/10H04L51/212H04L63/02H04L63/0209H04L63/0227H04L63/0236H04L63/0254H04L63/0428H04L63/08H04L63/0807H04L63/10H04L63/14H04L63/1408H04L63/1416H04L63/1425H04L63/1441H04L63/1466H04L63/1491H04L63/164H04L63/20H04L67/104
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,273,382
App. No.
16/224,398
Granted
Apr 8, 2025
Kind
B2
Abstract

Security is improved by adding a security heartbeat for and endpoint as a factor in a multi-factor authentication system. The security heartbeat may be used directly as an authentication factor, e.g., where the heartbeat provides a reliable and verifiable indication of identity, or the security heartbeat may be used as a gating input for some other verification method, e.g., where a text message with a temporary security code can only be transmitted to a user when the user's endpoint is providing a secure heartbeat.

Claims (49)

1. A computer program product comprising a non-transitory computer-readable medium embodying computer-executable code that, when executing on an authentication service accessible through a data network, causes the authentication service to perform steps comprising:

receiving a heartbeat from an endpoint through a data network, wherein the heartbeat indicates compliance of the endpoint with a security policy for an enterprise network associated with the endpoint, and wherein the heartbeat is cryptographically secured by the endpoint to permit verification of a source of the heartbeat with reference to a trusted third party;

receiving a request from the endpoint for an authentication token suitable for authenticating a user of the endpoint to a secure service accessible by the endpoint through the data network;

requesting a verification of the compliance of the endpoint with the security policy by verifying the heartbeat from the endpoint with reference to the trusted third party;

in response to receiving the request from the endpoint, and in response to using the compliance of the endpoint with the security policy as a security factor by verifying the heartbeat with reference to the trusted third party, providing the authentication token requested by the endpoint for authenticating to a remote service by performing steps comprising:

generating the authentication token requested by the endpoint;

generating verification information for use by an access control system in verifying the authentication token;

transmitting the verification information for verifying the authentication token to the access control system for accessing the secure service; and

returning the authentication token to the endpoint, wherein the authentication token is one of a plurality of authentication factors used in authenticating the user of the endpoint to the secure service with a multi-factor authentication system based at least in part on compliance of the endpoint with the security policy; and

in response to receiving the request from the endpoint, and in response to the endpoint not being in compliance with the security policy, not providing the authentication token to the remote service.

2. A method comprising:

receiving a heartbeat from an endpoint that is cryptographically secured, wherein the heartbeat indicates compliance of the endpoint with a security policy of an enterprise network associated with the endpoint;

receiving a request for authentication data for the endpoint;

requesting a verification of the compliance of the endpoint with the security policy by verifying the heartbeat from the endpoint with reference to a trusted third party;

in response to receiving the request from the endpoint, and in response to using the compliance of the endpoint with the security policy as a security factor by verifying the heartbeat with reference to the trusted third party, providing the authentication data requested by the endpoint for authenticating to a remote service by performing steps comprising:

generating the authentication data requested for the endpoint;

generating verification information for use by an access control system in verifying the authentication data;

transmitting the verification information for verifying the authentication data to the access control system; and

transmitting the authentication data to a recipient in response to the request, wherein the authentication data is used in authenticating to a secure service based at least in part on a state of compliance of the endpoint with the security policy; and

in response to receiving the request from the endpoint, and in response to the endpoint not being in compliance with the security policy, withholding authentication data from the recipient.

3. The method of claim 2 wherein content of the heartbeat is encrypted.

4. The method of claim 2 wherein the heartbeat is cryptographically signed.

5. The method of claim 2 wherein the request is received from the endpoint.

6. The method of claim 2 wherein the request is received from a hardware token.

7. The method of claim 2 wherein the request is received from a computing device other than the endpoint.

8. The method of claim 2 wherein compliance of the endpoint with the security policy includes a health status of at least one of a file on the endpoint, and a process executing on the endpoint.

9. The method of claim 2 further comprising digitally signing the authentication data.

10. The method of claim 2 further comprising encrypting the authentication data.

11. The method of claim 2 wherein the recipient includes the endpoint.

12. The method of claim 2 wherein the recipient includes a mobile device.

13. The method of claim 2 further comprising locally comparing the authentication data to an expected response at the recipient.

14. The method of claim 2 wherein transmitting the authentication data includes transmitting at least one of a text message to a mobile device of a user of the endpoint or an electronic mail message to an electronic mail account of the user of the endpoint.

15. The method of claim 2 wherein receiving the request for authentication data includes receiving the request at one or more of a cloud service, a firewall or a gateway.

16. The method of claim 2 , wherein the verification information includes cryptographic information.

17. The computer program product of claim 1 , wherein not providing the authentication token to the remote service includes at least one of generating a defective token or withholding authentication data.

18. A security appliance for providing an authentication token, the security appliance comprising:

a network interface configured to couple the security appliance in a communicating relationship with a data network;

a memory; and

a processor configured by computer code stored in the memory to perform the steps of:

receiving a heartbeat from an endpoint indicating compliance of the endpoint with a security policy for an enterprise network, wherein the heartbeat is cryptographically secured through the network interface,

receiving a request for an authentication token for the endpoint through the network interface,

requesting a verification of the compliance of the endpoint with the security policy by verifying the heartbeat from the endpoint with reference to a trusted third party, and

in response to receiving the request from the endpoint, and in response to using the compliance of the endpoint with the security policy as a security factor by verifying the heartbeat with reference to the trusted third party, providing the authentication token requested by the endpoint for authenticating to a remote service by performing steps comprising:

generating the authentication token requested for the endpoint,

generating verification information for use by an access control system in verifying the authentication token,

transmitting the verification information for verifying the authentication token to the access control system for accessing a secure service, and

transmitting the authentication token to a recipient in response to the request, wherein the authentication token is used in authenticating to a secure service based on the compliance of the endpoint with the security policy.

19. The security appliance of claim 18 , wherein the security appliance is a cloud service for supporting multi-factor authentication based on the heartbeat.

20. The security appliance of claim 18 , wherein the security appliance is a gateway for an enterprise network.

Assignments (4)
RELEASE OF SECURITY INTEREST IN PATENTS AT R/F 053476/0681 Recorded Mar 9, 2021
From: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
To: SOPHOS LIMITED
Reel/Frame 056469/0815 →
PATENT SECURITY AGREEMENT FIRST LIEN Recorded Jul 6, 2020
From: SOPHOS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 053124/0350 →
PATENT SECURITY AGREEMENT SECOND LIEN Recorded Jul 6, 2020
From: SOPHOS LIMITED
To: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 053476/0681 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 11, 2019
From: ACKERMAN, KARL; SHAW, JOHN EDWARD TYRONE; PARADIS, CRAIG; THOMAS, ANDREW J.; RAY, KENNETH D.
To: SOPHOS LIMITED
Reel/Frame 050344/0825 →
Continuity (2)
Continuation PCTUS2016040397 · Jun 30, 2016
Related Publication 20190123904A1 · Apr 25, 2019
References Cited (116)
US 7233989B2 · Srivastava et al. · 2007 [cited by applicant]
US 7516488B1 · Croall et al. · 2009 [cited by applicant]
US 7900251B1 · Cheriton · 2011 [cited by applicant]
US 8042147B2 · Byres et al. · 2011 [cited by applicant]
US 8181244B2 · Boney · 2012 [cited by applicant]
US 8201243B2 · Boney · 2012 [cited by applicant]
US 8312540B1 · Kahn et al. · 2012 [cited by applicant]
US 8418250B2 · Morris et al. · 2013 [cited by applicant]
US 8458462B1 · Hanna et al. · 2013 [cited by applicant]
US 8719932B2 · Boney · 2014 [cited by applicant]
US 8726389B2 · Morris et al. · 2014 [cited by applicant]
US 8763123B2 · Morris et al. · 2014 [cited by applicant]
US 8850567B1 · Hsieh et al. · 2014 [cited by applicant]
US 8856505B2 · Schneider · 2014 [cited by applicant]
US 9124636B1 · Rathor · 2015 [cited by applicant]
US 9413721B2 · Morris et al. · 2016 [cited by applicant]
US 9467475B2 · Faltyn · 2016 [cited by examiner]
US 9578045B2 · Jaroch et al. · 2017 [cited by applicant]
US 10051001B1 · Ashley et al. · 2018 [cited by applicant]
US 10091235B1 · Kushwaha et al. · 2018 [cited by applicant]
US 10158480B1 · Winklevoss et al. · 2018 [cited by applicant]
US 10257224B2 · Jaroch et al. · 2019 [cited by applicant]
US 10601865B1 · Mesdaq et al. · 2020 [cited by applicant]
US 20020059528A1 · Dapp · 2002 [cited by applicant]
US 20020138582A1 · Chandra et al. · 2002 [cited by applicant]
US 20030158921A1 · Hare et al. · 2003 [cited by applicant]
US 20030177389A1 · Albert et al. · 2003 [cited by applicant]
US 20050171872A1 · Burch et al. · 2005 [cited by applicant]
US 20060062141A1 · Oran et al. · 2006 [cited by applicant]
US 20060101515A1 · Amoroso et al. · 2006 [cited by applicant]
US 20070073631A1 · Hinchey et al. · 2007 [cited by applicant]
US 20070079379A1 · Sprosts et al. · 2007 [cited by applicant]
US 20070094325A1 · Ih et al. · 2007 [cited by applicant]
US 20070192855A1 · Hulten et al. · 2007 [cited by applicant]
US 20070199054A1 · Florencio et al. · 2007 [cited by applicant]
US 20080082662A1 · Dandliker et al. · 2008 [cited by applicant]
US 20080140795A1 · He et al. · 2008 [cited by applicant]
US 20080289013A1 · Burch et al. · 2008 [cited by applicant]
US 20090089859A1 · Cook et al. · 2009 [cited by applicant]
US 20090178132A1 · Hudis et al. · 2009 [cited by applicant]
US 20090228780A1 · Mcgeehan · 2009 [cited by applicant]
US 20100306845A1 · Vaithilingam et al. · 2010 [cited by applicant]
US 20100327054A1 · Hammad · 2010 [cited by examiner]
US 20110209196A1 · Kennedy · 2011 [cited by applicant]
US 20110296231A1 · Dake · 2011 [cited by applicant]
US 20110307947A1 · Kariv · 2011 [cited by examiner]
US 20110314546A1 · Aziz et al. · 2011 [cited by applicant]
US 20120151558A1 · Byres et al. · 2012 [cited by applicant]
US 20120222114A1 · Shanbhogue · 2012 [cited by applicant]
US 20120240185A1 · Kapoor et al. · 2012 [cited by applicant]
US 20120240224A1 · Payne et al. · 2012 [cited by applicant]
US 20120324245A1 · Sinha et al. · 2012 [cited by applicant]
US 20130339736A1 · Nayshtut · 2013 [cited by examiner]
US 20140096229A1 · Burns et al. · 2014 [cited by applicant]
US 20140129920A1 · Sheretov et al. · 2014 [cited by applicant]
US 20140269341A1 · Gunasekara et al. · 2014 [cited by applicant]
US 20150113600A1 · Dulkin et al. · 2015 [cited by applicant]
US 20150121529A1 · Quinlan et al. · 2015 [cited by applicant]
US 20150312268A1 · Ray et al. · 2015 [cited by applicant]
US 20160072838A1 · Kolton et al. · 2016 [cited by applicant]
US 20160088000A1 · Siva Kumar et al. · 2016 [cited by applicant]
US 20160164855A1 · Johansson · 2016 [cited by examiner]
US 20160188801A1 · Tse · 2016 [cited by examiner]
US 20160381023A1 · Dulce et al. · 2016 [cited by applicant]
US 20170026840A1 · Eyal · 2017 [cited by examiner]
US 20170046506A1 · Fujii et al. · 2017 [cited by applicant]
US 20170048258A1 · Khalil et al. · 2017 [cited by applicant]
US 20170063947A1 · Ziskin · 2017 [cited by examiner]
US 20170214712A1 · Maxwell et al. · 2017 [cited by applicant]
US 20170237753A1 · Manning Dawson · 2017 [cited by applicant]
US 20180288079A1 · Muddu et al. · 2018 [cited by applicant]
US 20180332033A1 · Lakhani · 2018 [cited by examiner]
US 20180332079A1 · Ashley et al. · 2018 [cited by applicant]
US 20190065747A1 · Gomes de Oliveira · 2019 [cited by examiner]
US 20190124042A1 · Thomas et al. · 2019 [cited by applicant]
US 20190124047A1 · Thomas et al. · 2019 [cited by applicant]
US 20190124097A1 · Thomas et al. · 2019 [cited by applicant]
US 20190124098A1 · Thomas et al. · 2019 [cited by applicant]
US 20190124112A1 · Thomas et al. · 2019 [cited by applicant]
US 20190149574A1 · Thomas et al. · 2019 [cited by applicant]
US 20230208879A1 · Thomas et al. · 2023 [cited by applicant]
US 20240214420A1 · Thomas et al. · 2024 [cited by applicant]
WO WO2018004600 · 2018 [cited by applicant]
USPTO, “U.S. Appl. No. 16/224,319 Non-Final Office Action mailed Nov. 7, 2019”, 14 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 16/224,291 Non-Final Office Action mailed Oct. 7, 2020”, 9 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 16/224,319 Final Office Action mailed Sep. 4, 2020”, 15 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 16/224,352 Non-Final Office Action mailed Dec. 1, 2020”, 25 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 16/224,448 Non-Final Office Action mailed Aug. 21, 2020”, 13 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 16/224,218 Non-Final Office Action mailed Aug. 14, 2020”, 19 pages. [cited by applicant]
IPO, “UK Application No. 1901182.4 Search Report mailed Jul. 25, 2019”, 4 pages. [cited by applicant]
WIPO, “PCT Application No. PCT/US16/40397 International Preliminary Report on Patentability mailed Jan. 11, 2019”, 9 pages. [cited by applicant]
ISA, “PCT Application No. PCT/US16/40397 International Search Report and Written Opinion mailed Nov. 7, 2016”, 13 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 16/224,319 Non-Final Office Action mailed May 1, 2020” , 13 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 16/224,218 Final Office Action mailed Jan. 8, 2021”, 21 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 16/224,258 Non-Final Office Action mailed Jan. 6, 2021”, 9 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 16/224,319 Notice of Allowance mailed Jan. 25, 2021”, 9 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 16/224,448 Final Office Action mailed Jan. 21, 2021”, 17 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 16/224,218 Non-Final Office Action mailed May 17, 2021”, 22 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 16/224,352 Final Office Action mailed Apr. 9, 2021”, 23 pages. [cited by applicant]
IPO, “UK Application No. 1900949.7 First Examination Report mailed May 24, 2021”, 6 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 16/224,258 Notice of Allowance mailed Oct. 27, 2021”, 7 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 16/224,352 Non-Final Office Action mailed Oct. 5, 2021”, 23 pages. [cited by applicant]
Memon, et al., “Autonomous fault detection and recovery system in large-scale networks”, 2016 13th International Computer Conference on Wavelet Active Media Technology and Information Processing (ICCWAMTIP) Year: 2016 C… [cited by applicant]
Gao, et al., “Network Coding Based BSM Broadcasting at Road Intersection in V2V Communication”, 2016 IEEE 84th Vehicular Technology Conference (VTC-Fall) Year: 2016 | Conference Paper | Publisher: IEEE 2016 , 5 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 16/224,218 Notice of Allowance mailed Jul. 30, 2021”, 10 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 16/224,448 Non-Final Office Action mailed Aug. 10, 2021”, 19 pages. [cited by applicant]
UKIPO, “UK Application No. 1900949.7 Examination Report mailed Sep. 3, 2021”, 4 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 16/224,352 Final Office Action mailed Mar. 18, 2022”, 24 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 16/224,448 Final Office Action mailed Feb. 17, 2022”, 19 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 16/224,352 Notice of Allowance mailed Oct. 13, 2022”, 13 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 16/224,352 Notice of Allowance mailed Dec. 9, 2022”, 13 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 17/667,111 Non-Final Office Action mailed Dec. 14, 2022”, 7 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 16/224,448 Notice of Allowance mailed Mar. 16, 2023”, 11 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 17/667,111 Notice of Allowance mailed Mar. 15, 2023”, 8 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 18/177,434 Non-Final Office Action mailed Apr. 22, 2024”, 28 pages. [cited by applicant]
USPTO, “U.S. Appl. No. 18/364,902 Non-Final Office Action mailed Apr. 25, 2024”, 14 pages. [cited by applicant]
Cited By (1)
US 12,401,611