IP Library Granted Patent US 11,323,441
Granted Patent B2
US 11,323,441 · App. 16/934,223 · Granted May 3, 2022

System and method for proxying federated authentication protocols

Inventors: Jon Oberheide (Ann Arbor, MI); Douglas Song (Ann Arbor, MI)
Assignee: CISCO TECHNOLOGY, INC.
H04L63/0884H04L63/0815
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,323,441
App. No.
16/934,223
Granted
May 3, 2022
Kind
B2
Abstract

A system and method that include receiving a service provider identity request through a protocol; transmitting a proxy identity request to a configured identity provider; receiving an identity assertion; determining a proxy identity assertion based on the identity assertion; and transmitting the proxy identity assertion to the service provider.

Claims (57)

1. A computer-implemented method comprising:

at one or more instances of a federated authentication proxy on a server:

receiving a service provider identity request from a service provider;

transmitting a proxy identity request based on the service provider identity request to a configured identity provider;

receiving an identity request assertion from the configured identity provider;

performing a second layer of authentication of the service provider identity request;

determining a proxy identity assertion based on the identity request assertion and results of the second layer of authentication; and

transmitting the proxy identity assertion to the service provider as a response to the service provider identity request.

2. The computer-implemented method of claim 1 , wherein:

the determining the proxy identity assertion includes determining that the service provider identity request is valid when the identity request assertion indicates that the service provider identity request is valid and the second layer of authentication of the service provider identity request is successful.

3. The computer-implemented method of claim 2 , wherein:

the determining the proxy identity assertion includes determining that the service provider identity request is not valid when either the identity request assertion indicates the service provider identity request is not valid or the second layer of authentication of the service provider identity request is unsuccessful.

4. The computer-implemented method of claim 1 , further comprising:

emulating a service provider in a first instance of the federated authentication proxy when receiving the service provider identity request and determining the proxy identity assertion; and

emulating an identity provider in a second instance of the federated authentication proxy when transmitting to and receiving from the configured identity provider.

5. The computer-implemented method of claim 4 , further comprising:

in association with a managing account, configuring the first instance and the second instance of the federated authentication proxy; and

prior to the transmitting the proxy identity request, selecting the second instance according to an identifier of the managing account from the first instance.

6. The computer-implemented method of claim 4 , wherein the first instance and the second instance of the federated authentication proxy are implemented using a security assertion markup language protocol (SAML).

7. The computer-implemented method of claim 4 , wherein the first instance and the second instance of the federated authentication proxy are implemented using an OpenID Connect protocol.

8. An apparatus comprising:

a non-transitory computer readable medium configured to store instructions; and

a processor configured to execute the instructions to implement one or more instances of a federated authentication proxy on a server and to perform:

receiving a service provider identity request from a service provider;

transmitting a proxy identity request based on the service provider identity request to a configured identity provider;

receiving an identity request assertion from the configured identity provider;

performing a second layer of authentication of the service provider identity request;

determining a proxy identity assertion based on the identity request assertion and results of the second layer of authentication; and

transmitting the proxy identity assertion to the service provider as a response to the service provider identity request.

9. The apparatus of claim 8 , wherein the processor is configured to perform the determining the proxy identity assertion by determining that the service provider identity request is valid when the identity request assertion indicates that the service provider identity request is valid and the second layer of authentication of the service provider identity request is successful.

10. The apparatus of claim 9 , wherein the processor is further configured to perform the determining the proxy identity assertion by determining that the service provider identity request is not valid when either the identity request assertion indicates the service provider identity request is not valid or the second layer of authentication of the service provider identity request is unsuccessful.

11. The apparatus of claim 8 , wherein the processor is further configured to perform:

emulating a service provider in a first instance of the federated authentication proxy when receiving the service provider identity request and determining the proxy identity assertion; and

emulating an identity provider in a second instance of the federated authentication proxy when transmitting to and receiving from the configured identity provider.

12. The apparatus of claim 11 , wherein the processor is further configured to perform:

in association with a managing account, configuring the first instance of the federated authentication proxy and the second instance of the federated authentication proxy; and

prior to the transmitting the proxy identity request, selecting the second instance according to an identifier of the managing account from the first instance.

13. The apparatus of claim 11 , wherein the processor is configured to implement the first instance and the second instance of the federated authentication proxy using a security assertion markup language protocol (SAML).

14. The apparatus of claim 11 , wherein the processor is configured to implement the first instance and the second instance of the federated authentication proxy using an OpenID Connect protocol.

15. A non-transitory computer readable medium storing instructions that, when executed by a processor of a proxy server, cause the processor to implement one or more instances of a federated authentication proxy and to perform:

receiving a service provider identity request from a service provider;

transmitting a proxy identity request based on the service provider identity request to a configured identity provider;

receiving an identity request assertion from the configured identity provider;

performing a second layer of authentication of the service provider identity request;

determining a proxy identity assertion based on the identity request assertion and results of the second layer of authentication; and

transmitting the proxy identity assertion to the service provider as a response to the service provider identity request.

16. The non-transitory computer readable medium of claim 15 , wherein the instructions to cause the processor to perform the determining include instructions to cause the processor to perform:

determining that the service provider identity request is valid when the identity request assertion indicates that the service provider identity request is valid and the second layer of authentication of the service provider identity request is successful.

17. The non-transitory computer readable medium of claim 16 , wherein the instructions to cause the processor to perform the determining further include instructions to cause the processor to perform:

determining that the service provider identity request is not valid when either the identity request assertion indicates the service provider identity request is not valid or the second layer of authentication of the service provider identity request is unsuccessful.

18. The non-transitory computer readable medium of claim 15 , further comprising instructions to cause the processor to perform:

emulating a service provider in a first instance of the federated authentication proxy when receiving the service provider identity request and determining the proxy identity assertion; and

emulating an identity provider in a second instance of the federated authentication proxy when transmitting to and receiving from the configured identity provider.

19. The non-transitory computer readable medium of claim 18 , further comprising instructions to cause the processor to perform:

in association with a managing account, configuring the first instance of the federated authentication proxy and the second instance of the federated authentication proxy; and

prior to the transmitting the proxy identity request, selecting the second instance according to an identifier of the managing account from the first instance.

20. The non-transitory computer readable medium of claim 18 , wherein the first instance and the second instance of the federated authentication proxy are implemented using a security assertion markup language protocol (SAML).

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 11, 2021
From: DUO SECURITY LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 056208/0504 →
CHANGE OF NAME Recorded May 11, 2021
From: DUO SECURITY, INC.
To: DUO SECURITY LLC
Reel/Frame 056210/0008 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 21, 2020
From: OBERHEIDE, JON; SONG, DOUGLAS
To: DUO SECURITY, INC.
Reel/Frame 053268/0255 →
Continuity (6)
Continuation 16228578 · Dec 20, 2018
Continuation 15286993 · Oct 6, 2016
Continuation 14517078 · Oct 17, 2014
Continuation 14188449 · Feb 24, 2014
Provisional Application 61768233 · Feb 22, 2013
Related Publication 20200351268A1 · Nov 5, 2020