IP Library Granted Patent US 12,095,785
Granted Patent B2
US 12,095,785 · App. 18/496,859 · Granted Sep 17, 2024

System and methods for detecting SAML forgery or manipulation attacks

Inventors: Jason Crabtree (Vienna, VA); Richard Kelley (Woodbridge, VA); Angadbir Singh Salaria (Herndon, VA); Andrew Sellers (Monument, CO); Farooq Israr Ahmed Shaikh (Reston, VA); Randy Clayton (Frederick, MD); Luka Jurukovski (Arlington, VA)
Assignee: QOMPLX
H04L63/1416H04L63/0876H04L63/1425H04L63/1466
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,095,785
App. No.
18/496,859
Granted
Sep 17, 2024
Kind
B2
Abstract

A system and methods for detecting and mitigating SAML forgery and manipulation attacks against services is provided, comprising a policy manager configured to observe a new authentication object generated by an identity provider, and retrieve the new authentication object; and a hashing engine configured to create a unique identifier for each valid authentication session; wherein subsequent access requests accompanied by authentication objects are validated by checking for a valid unique identifier.

Claims (32)

1. A system for detecting Security Assertion Markup Language (SAML) forgery or manipulation attacks, comprising:

a computing system comprising a memory and a processor;

a policy manager subsystem comprising a first plurality of programming instructions stored in the memory which, when operating on the processor, causes the computing system to:

receive a plurality of network packets comprising a first authentication object for a user of a service, the first authentication object comprising a first identification string known to be generated by an identity provider associated with the service;

generate a unique identifier for the first authentication object;

provide the unique identifier to the identity provider from which the first authentication object was generated for inclusion in additional authentication objects issued to the user;

receive a request for access to the service by the user accompanied by a second authentication object comprising a second identification string;

compare a value of the second identification string of the second authentication object against a value of the second identification string of the stored record of the first authentication object;

check the second authentication object for the unique identifier; and

generate an authentication failure if the unique identifier is missing or invalid; and

a hashing subsystem comprising a second plurality of programming instructions stored in the memory of, and operating on the processor of, the computing system, wherein the second plurality of programmable instructions, when operating on the processor, cause the computing system to:

receive authentication objects from the policy manager;

calculate unique identifiers for authentication objects received by performing a plurality of calculations and transformations on each received authentication object; and

return the unique identifiers for authentication objects received to the policy manager.

2. The system of claim 1 , wherein the policy manager is operated by the identity provider.

3. The system of claim 1 , wherein the policy manager is operated by a client device communicating with the identity provider over a network.

4. The system of claim 1 , wherein the policy manager is operated by a third-party service communicating with the identity provider, endpoint, service, or networking devices over a network.

5. A method for detecting Security Assertion Markup Language (SAML) forgery or manipulation attacks, comprising:

using a policy manager operating on a computing system comprising a memory and a processor to:

receive a plurality of network packets comprising a first authentication object for a user of a service, the first authentication object comprising a first identification string known to be generated by an identity provider associated with the service;

generate a unique identifier for the first authentication object;

provide the unique identifier to the identity provider from which the first authentication object was generated for inclusion in additional authentication objects issued to the user;

receive a request for access to the service by the user accompanied by a second authentication object comprising a second identification string;

compare a value of the second identification string of the second authentication object against a value of the second identification string of the first authentication object;

check the second authentication object for the unique identifier;

generate an authentication failure if the unique identifier is missing or invalid; using a hashing subsystem operating on the computing system to:

receive authentication objects from the policy manager;

calculate unique identifiers for authentication objects received by performing a plurality of calculations and transformations on each authentication object received; and

return the unique identifiers for authentication objects received to the policy manager.

6. The method of claim 5 , wherein the policy manager is operated by the identity provider.

7. The method of claim 5 , wherein the policy manager is operated by a client device communicating with the identity provider over a network.

8. The method of claim 5 , wherein the policy manager is operated by a third-party service communicating with the identity provider, endpoint, service, or networking devices over a network.

Assignments (3)
CHANGE OF NAME Recorded Apr 16, 2024
From: QPX LLC
To: QOMPLX LLC
Reel/Frame 067129/0159 →
PATENT ASSIGNMENT AGREEMENT TO ASSET PURCHASE AGREEMENT Recorded Feb 20, 2024
From: QOMPLX, INC.
To: QPX LLC
Reel/Frame 066632/0200 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 12, 2024
From: CLAYTON, RANDY; CRABTREE, JASON; JURUKOVSKI, LUKA; KELLEY, RICHARD; SALARAI, ANGADBIR SINGH; SELLERS, ANDREW; SHAIKH, FAROOQ ISRAR AHMED
To: QOMPLX, INC.
Reel/Frame 066445/0740 →
Continuity (18)
Continuation 17975548 · Oct 27, 2022
Continuation 17163073 · Jan 29, 2021
Continuation In Part 15837845 · Dec 11, 2017
Continuation In Part 15825350 · Nov 29, 2017
Continuation In Part 15725274 · Oct 4, 2017
Continuation In Part 15655113 · Jul 20, 2017
Continuation In Part 15616427 · Jun 7, 2017
Continuation In Part 15237625 · Aug 15, 2016
Continuation In Part 15206195 · Jul 8, 2016
Continuation In Part 15186453 · Jun 18, 2016
Continuation In Part 15166158 · May 26, 2016
Continuation In Part 15141752 · Apr 28, 2016
Continuation In Part 15091563 · Apr 5, 2016
Continuation In Part 14986536 · Dec 31, 2015
Continuation In Part 14925974 · Oct 28, 2015
Continuation In Part 14925974 · Oct 28, 2015
Provisional Application 62596105 · Dec 7, 2017
Related Publication 20240064159A1 · Feb 22, 2024