IP Library Granted Patent US 11,888,851
Granted Patent B2
US 11,888,851 · App. 17/867,355 · Granted Jan 30, 2024

Identity proxy and access gateway

Inventors: James Howard Royal (Austin, TX); Samuel Douglas Rhea (Lisbon, PT)
Assignee: CLOUDFLARE, INC.
H04L63/0884H04L63/0281H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,888,851
App. No.
17/867,355
Granted
Jan 30, 2024
Kind
B2
Abstract

A server transmits to a third-party application a request for a resource that is received from a client. The server receives an authentication request from the client device that has been generated by the third-party application. The server transmits an identity provider selection page to the client device that allows the client device to select an identity provider. The server causes the client device to transmit a second authentication request to a selected identity provider. The server receives an authentication response that was generated by the identity provider that includes the identity of the user. The server enforces access rule(s) including identity-based rule(s) and/or non-identity based rule(s). If the user is permitted to access the third-party application, the server causes an authentication response to be transmitted from the client device to the third-party application that indicates the user has successfully authenticated.

Claims (73)

1. A method implemented in an identity proxy and access gateway, comprising:

receiving a first authentication request from a client device that has been generated by a third-party application in response to a first access request from the client device to the third-party application requesting access to a resource at the third-party application, wherein the first authentication request is requesting an authentication of a user that is attempting to access the third-party application, and wherein the identity proxy and access gateway is configured as a first identity provider of the third-party application;

transmitting an identity provider selection page to the client device, the identity provider selection page including one or more identity provider options for the user to select for authentication;

receiving, from the client device, a selection of one of the one or more identity provider options; causing the client device to transmit a second authentication request to a second identity provider corresponding to the selected one of the one or more identity provider options;

receiving, from the client device, a first authentication response that was generated by the second identity provider that indicates the user has successfully authenticated to the second identity provider;

enforcing a first set of one or more access rules to determine whether the user is permitted to access the third-party application, wherein the first set of one or more access rules is enforced independently from any rules enforced at the second identity provider;

determining, from the enforcing of the first set of one or more access rules, that the user is permitted to access the third-party application, and responsive to this determination, generating a second authentication response that-indicates the user has successfully authenticated; and

transmitting the second authentication response to the client device, wherein the second authentication response is caused to be transmitted to the third-party application that indicates the user has successfully authenticated.

2. The method of claim 1 , wherein the first set of one or more access rules includes one or more identity-based rules and one or more non-identity based rules.

3. The method of claim 1 , wherein transmitting the identity provider selection page to the client device further comprises:

enforcing a second set of one or more access rules including one or more non-identity based rules to determine whether to proceed with the first authentication request; and

transmitting the identity provider selection page to the client device when the one or more non-identity based rules are satisfied.

4. The method of claim 3 , wherein enforcing the second set of one or more access rules including the one or more non-identity based rules to determine whether to proceed with the first authentication request further comprises:

accessing an endpoint protection provider to determine a posture of the client device; and

determining one or more non-identity based parameters based on the request.

5. The method of claim 1 , wherein causing the client device to transmit the second authentication request to the second identity provider corresponding to the selected one of the one or more identity provider options further comprises:

generating the second authentication request to the second identity provider; and

redirecting the client device to transmit the second authentication request to the second identity provider.

6. The method of claim 1 , further comprising:

generating a signed token, the signed token including information indicating the user has successfully authenticated to the second identity provider and user information; and

providing the signed token to the client device in the second authentication response.

7. The method of claim 6 , further comprising:

transmitting the signed token to the third-party application.

8. A non-transitory machine-readable storage medium that provides instructions that, if executed by a processor of an identity proxy and access gateway, will cause said processor to perform operations comprising:

receiving a first authentication request from a client device that has been generated by a third-party application in response to a first access request from the client device to the third-party application requesting access to a resource at the third-party application, wherein the first authentication request is requesting an authentication of a user that is attempting to access the third-party application, and wherein the identity proxy and access gateway is configured as a first identity provider of the third-party application;

transmitting an identity provider selection page to the client device, the identity provider selection page including one or more identity provider options for the user to select for authentication;

receiving, from the client device, a selection of one of the one or more identity provider options;

causing the client device to transmit a second authentication request to a second identity provider corresponding to the selected one of the one or more identity provider options;

receiving, from the client device, a first authentication response that was generated by the second identity provider that indicates the user has successfully authenticated to the second identity provider;

enforcing a first set of one or more access rules to determine whether the user is permitted to access the third-party application, wherein the first set of one or more access rules is enforced independently from any rules enforced at the second identity provider;

determining, from the enforcing of the first set of one or more access rules, that the user is permitted to access the third-party application, and responsive to this determination, generating a second authentication response that-indicates the user has successfully authenticated; and

transmitting the second authentication response to the client device, wherein the second authentication response is caused to be transmitted to the third-party application that indicates the user has successfully authenticated.

9. The non-transitory machine-readable storage medium of claim 8 , wherein the first set of one or more access rules includes one or more identity-based rules and one or more non-identity based rules.

10. The non-transitory machine-readable storage medium of claim 8 , wherein transmitting the identity provider selection page to the client device further causes said processor to perform operations comprising:

enforcing a second set of one or more access rules including one or more non-identity based rules to determine whether to proceed with the first authentication request; and

transmitting the identity provider selection page to the client device when the one or more non-identity based rules are satisfied.

11. The non-transitory machine-readable storage medium of claim 10 , wherein enforcing the second set of one or more access rules including the one or more non-identity based rules to determine whether to proceed with the first authentication request further causes said processor to perform operations comprising:

accessing an endpoint protection provider to determine a posture of the client device; and

determining one or more non-identity based parameters based on the request.

12. The non-transitory machine-readable storage medium of claim 8 , wherein causing the client device to transmit the second authentication request to the second identity provider corresponding to the selected one of the one or more identity provider options further causes said processor to perform operations comprising:

generating the second authentication request to the second identity provider; and

redirecting the client device to transmit the second authentication request to the second identity provider.

13. The non-transitory machine-readable storage medium of claim 8 , wherein the operations further comprise:

generating a signed token, the signed token including information indicating the user has successfully authenticated to the second identity provider and user information; and

providing the signed token to the client device in the second authentication response.

14. The non-transitory machine-readable storage medium of claim 13 , wherein the operations further comprise:

transmitting the signed token to the third-party application.

15. An apparatus, comprising:

a processor; and

a non-transitory machine-readable storage medium that provides instructions that, if executed by the processor, will cause an identity proxy and access gateway to perform operations comprising:

receive a first authentication request from a client device that has been generated by a third-party application in response to a first access request from the client device to the third-party application requesting access to a resource at the third-party application, wherein the first authentication request is requesting an authentication of a user that is attempting to access the third-party application, and wherein the identity proxy and access gateway is configured as a first identity provider of the third-party application;

transmit an identity provider selection page to the client device, the identity provider selection page including one or more identity provider options for the user to select for authentication;

receive, from the client device, a selection of one of the one or more identity provider options;

cause the client device to transmit a second authentication request to a second identity provider corresponding to the selected one of the one or more identity provider options;

receive, from the client device, a first authentication response that was generated by the second identity provider that indicates the user has successfully authenticated to the second identity provider;

enforce a first set of one or more access rules to determine whether the user is permitted to access the third-party application, wherein the first set of one or more access rules is enforced independently from any rules enforced at the second identity provider;

determine, from the enforcing of the first set of one or more access rules, that the user is permitted to access the third-party application, and responsive to this determination, generate a second authentication response that indicates the user has successfully authenticated; and

transmit the second authentication response to the client device, wherein the second authentication response is caused to be transmitted to the third-party application that indicates the user has successfully authenticated.

16. The apparatus of claim 15 , wherein the first set of one or more access rules includes one or more identity-based rules and one or more non-identity based rules.

17. The apparatus of claim 15 , wherein transmitting the identity provider selection page to the client device further causes said processor to perform operations comprising:

enforcing a second set of one or more access rules including one or more non-identity based rules to determine whether to proceed with the first authentication request; and

transmitting the identity provider selection page to the client device when the one or more non-identity based rules are satisfied.

18. The apparatus of claim 17 , wherein enforcing the second set of one or more access rules including the one or more non-identity based rules to determine whether to proceed with the first authentication request further causes said processor to perform operations comprising:

accessing an endpoint protection provider to determine a posture of the client device; and

determining one or more non-identity based parameters based on the request.

19. The apparatus of claim 15 , wherein causing the client device to transmit the second authentication request to the second identity provider corresponding to the selected one of the one or more identity provider options further causes said processor to perform operations comprising:

generating the second authentication request to the second identity provider; and

redirecting the client device to transmit the second authentication request to the second identity provider.

20. The apparatus of claim 15 , wherein the operations further comprise:

generating a signed token, the signed token including information indicating the user has successfully authenticated to the second identity provider and user information; and

providing the signed token to the client device in the second authentication response.

21. The apparatus of claim 20 , wherein the operations further comprise:

transmitting the signed token to the third-party application.

Assignments (2)
SECURITY INTEREST Recorded May 20, 2024
From: CLOUDFLARE, INC.
To: CITIBANK, N.A.
Reel/Frame 067472/0246 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 28, 2022
From: ROYAL, JAMES HOWARD; RHEA, SAMUEL DOUGLAS
To: CLOUDFLARE, INC.
Reel/Frame 061248/0166 →
Continuity (2)
Continuation 17500159 · Oct 13, 2021
Related Publication 20230110111A1 · Apr 13, 2023