IP Library Patent Application 17966810
Patent Application
App. No. 17/966,810

DISTRIBUTED TWO-FACTOR AUTHENTICATION

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
17/966,810
Abstract

Some embodiments provide a method for distributed two-factor authentication in an enterprise network that includes multiple host computers. The method receives a data message destined for a particular security group in a set of security groups that are tagged for two-factor authentication. From a set of security rules defined for the set of security groups, the method identifies a particular security rule associated with the particular security group, the particular security rule specifying a two-factor authentication challenge for authenticating a source of the data message. The method presents the two-factor authentication challenge to the source of the data message to determine whether the source is allowed to access the particular security group.

Claims (57)

1 . A method for distributed two-factor authentication in an enterprise network, the enterprise network comprising a plurality of host computers, the method comprising:

receiving a data message destined for a particular security group in a set of security groups that are tagged for two-factor authentication;

from a set of security rules defined for the set of security groups, identifying a particular security rule associated with the particular security group, wherein the particular security rule specifies a two-factor authentication challenge for authenticating a source of the data message; and

presenting the two-factor authentication challenge to the source of the data message to determine whether the source is allowed to access the particular security group.

2 . The method of claim 1 , wherein the two-factor authentication challenge requires the source to provide a particular time-based one-time password (TOTP) that is (i) generated for the two-factor authentication challenge by a separate process and (ii) accessible to the source via the separate process, wherein:

when the source provides the particular TOTP, the data message is granted access to the particular security group; and

when the source provides a TOTP other than the particular TOTP, the data message is denied access to the particular security group.

3 . The method of claim 2 , wherein:

the particular TOTP is a first TOTP that is valid for a specified duration of time; and

after the specified duration of time, a second TOTP is generated by the separate process, wherein,

when the source provides the second TOTP, the data message is granted access to the particular security group; and

when the source provides a TOTP other than the second TOTP, the data message is denied access to the particular security group.

4 . The method of claim 1 , wherein before receiving the data message, the method comprises:

receiving a configuration for two-factor authentication to be enforced on data messages destined to security groups in the set of security groups;

using the received configuration to configure a local two-factor authentication engine; and

receiving the set of security rules (i) defined for the set of security groups tagged for two-factor authentication and (ii) to be enforced on data messages destined to security groups in the set of security groups.

5 . The method of claim 4 , wherein:

receiving the configuration for two-factor authentication comprises receiving the configuration from a network administrator of the enterprise network; and

receiving the set of security rules comprises receiving the set of security rules from the network administrator.

6 . The method of claim 4 , wherein:

the local two-factor authentication engine is one of a plurality of two-factor authentication engines in the enterprise network; and

each host computer in the plurality of host computers is associated with at least one two-factor authentication engine in the plurality of two-factor authentication engines.

7 . The method of claim 1 , wherein each security group in the set of security groups is defined for a particular set of critical resources identified as requiring two-factor authentication.

8 . The method of claim 1 , wherein the set of security rules comprise distributed firewall rules.

9 . The method of claim 1 , wherein:

the source comprises a mobile application implemented on a mobile device;

the two-factor authentication challenge comprises a requirement for the source to provide a time-based one-time password (TOTP); and

the TOTP comprises a QR code.

10 . The method of claim 9 , wherein the mobile application comprises a first mobile application, wherein the separate authentication process comprises a second mobile application implemented on the mobile device.

11 . The method of claim 1 , wherein receiving the data message destined for the particular security group comprises (i) receiving the data message and (ii) determining from a destination header of the data message that the data message is destined for the particular security group.

12 . The method of claim 1 , wherein identifying the particular security rule associated with the particular security group further comprises determining whether a set of header values of the data message match a set of attributes specified by the identified security rule, wherein:

when the set of header values are determined to match the specified set of attributes, the two-factor authentication challenge is presented to the source of the data message; and

when the set of header values are determined not to match the specified set of attributes, (i) the two-factor authentication challenge is not presented to the source of the data message and (ii) the data message is automatically denied access to the particular security group.

13 . A non-transitory machine readable medium storing a program for execution by a set of processing units, the program for implementing distributed two-factor authentication in an enterprise network that comprises a plurality of host computers, the program comprising sets of instructions for:

receiving a data message destined for a particular security group in a set of security groups that are tagged for two-factor authentication;

from a set of security rules defined for the set of security groups, identifying a particular security rule associated with the particular security group, wherein the particular security rule specifies a two-factor authentication challenge for authenticating a source of the data message; and

presenting the two-factor authentication challenge to the source of the data message to determine whether the source is allowed to access the particular security group.

14 . The non-transitory machine readable medium of claim 13 , wherein the two-factor authentication challenge requires the source to provide a particular time-based one-time password (TOTP) that is (i) generated for the two-factor authentication challenge by a separate process and (ii) accessible to the source via the separate process, wherein:

when the source provides the particular TOTP, the data message is granted access to the particular security group; and

when the source provides a TOTP other than the particular TOTP, the data message is denied access to the particular security group.

15 . The non-transitory machine readable medium of claim 14 , wherein:

the particular TOTP is a first TOTP that is valid for a specified duration of time; and

after the specified duration of time, a second TOTP is generated by the separate process, wherein,

when the source provides the second TOTP, the data message is granted access to the particular security group; and

when the source provides a TOTP other than the second TOTP, the data message is denied access to the particular security group.

16 . The non-transitory machine readable medium of claim 13 , wherein before receiving the data message, the program further comprises sets of instructions for:

receiving, from a network administrator of the enterprise network, a configuration for two-factor authentication to be enforced on data messages destined to security groups in the set of security groups;

using the received configuration to configure a local two-factor authentication engine; and

receiving, from the network administrator, the set of security rules (i) defined for the set of security groups tagged for two-factor authentication and (ii) to be enforced on data messages destined to security groups in the set of security groups.

17 . The non-transitory machine readable medium of claim 16 , wherein:

the local two-factor authentication engine is one of a plurality of two-factor authentication engines in the enterprise network; and

each host computer in the plurality of host computers is associated with at least one two-factor authentication engine in the plurality of two-factor authentication engines.

18 . The non-transitory machine readable medium of claim 13 , wherein each security group in the set of security groups is defined for a particular set of critical resources identified as requiring two-factor authentication.

19 . The non-transitory machine readable medium of claim 13 , wherein the set of security rules comprise distributed firewall rules.

20 . The non-transitory machine readable medium of claim 13 , wherein the set of instructions for identifying the particular security rule associated with the particular security group further comprises a set of instructions for determining whether a set of header values of the data message match a set of attributes specified by the identified security rule, wherein:

when the set of header values are determined to match the specified set of attributes, the two-factor authentication challenge is presented to the source of the data message; and

when the set of header values are determined not to match the specified set of attributes, (i) the two-factor authentication challenge is not presented to the source of the data message and (ii) the data message is automatically denied access to the particular security group.

Assignments (2)
CHANGE OF NAME Recorded Feb 27, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 066692/0103 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 22, 2023
From: RADHAKRISHNAN, CHIRAG
To: VMWARE, INC.
Reel/Frame 063066/0500 →