IP Library › Granted Patent US 12,750,366
Granted Patent B2
US 12,750,366 · App. 18/746,510 · Granted Sep 29, 2026

Systems and methods for extensible, modular, and hierarchical step-up authentication

Inventors: Rahul Singh (Mohali, IN); Manish Jasyal (Mohali, IN); Murtuza Attarwala (Sunnyvale, CA); Wei Wang (Burnaby, CA)
Assignee: Zscaler, Inc.
H04L63/10H04L9/0872H04L63/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,750,366
App. No.
18/746,510
Granted
Sep 29, 2026
Kind
B2
Abstract

Systems and methods for a hierarchical step-up authentication mechanism include monitoring access to one or more private applications; responsive to a request to access the one or more private applications, determining an Authentication Level (AL) of a user associated with the request, wherein determining the AL of the user comprises referencing one or more AL trees; and responsive to determining an AL of the user, performing one or more actions based thereon, wherein the one or more actions comprises one of allowing access to the one or more private applications and denying access to the one or more private applications.

Claims (28)

1 . A method comprising steps of:

monitoring access to one or more private applications;

responsive to a request to access the one or more private applications, determining an Authentication Level (AL) of a user associated with the request, wherein determining the AL of the user comprises referencing one or more AL trees, each of the one or more AL trees comprising a plurality of ALs arranged in a parent-child hierarchy, each AL of the plurality of ALs representing an authentication strength tier for authentication of the user, wherein a parent AL in the parent-child hierarchy represents a higher authentication strength tier than any child AL descending therefrom, and wherein the user having authenticated to a given AL is granted access commensurate with the given AL and each child AL descending from the given AL; and

responsive to determining an AL of the user, performing one or more actions based thereon, wherein the one or more actions comprises one of allowing access to the one or more private applications and denying access to the one or more private applications.

2 . The method of claim 1 , wherein referencing one or more AL trees is based on any of a geographic location of the user and an application segment associated with the one or more private applications.

3 . The method of claim 1 , wherein access to each of the one or more private applications is based on an AL required by each of the one or more private applications.

4 . The method of claim 3 , wherein responsive to determining the AL of the user is a lower AL than that required by the one or more private applications, the one or more actions comprise prompting the user to authenticate to a required AL based on the one or more private applications.

5 . The method of claim 1 , wherein each of the one or more AL trees comprises one or more parent ALs and one or more child ALs.

6 . The method of claim 5 , wherein each of the one or more parent ALs and one or more child ALs has a timeout period associated therewith, and wherein the timeout period of each parent AL is shorter than the timeout period of each child AL descending therefrom.

7 . The method of claim 6 , wherein the steps comprise:

responsive to the timeout period of the AL of the user expiring, automatically demoting the AL of the user to a child AL of the AL of the user.

8 . The method of claim 6 , wherein the determining comprises determining the AL of the user is a higher AL than an AL required by the one or more private applications, and wherein the steps comprise allowing access to the one or more private applications based thereon.

9 . The method of claim 8 , wherein responsive to a timeout period of the AL of the user expiring, continuing a session for the user based on a child AL of the AL of the user being at or above an AL required by the one or more private applications.

10 . The method of claim 1 , wherein responsive to determining the AL of the user, the one or more actions comprise allowing access to one or more applications requiring a lower AL than the AL of the user.

11 . A non-transitory computer-readable medium comprising instructions that, when executed, cause one or more processors to perform steps of:

monitoring access to one or more private applications;

responsive to a request to access the one or more private applications, determining an Authentication Level (AL) of a user associated with the request, wherein determining the AL of the user comprises referencing one or more AL trees, each of the one or more AL trees comprising a plurality of ALs arranged in a parent-child hierarchy, each AL of the plurality of ALs representing an authentication strength tier for authentication of the user, wherein a parent AL in the parent-child hierarchy represents a higher authentication strength tier than any child AL descending therefrom, and wherein the user having authenticated to a given AL is granted access commensurate with the given AL and each child AL descending from the given AL; and

responsive to determining an AL of the user, performing one or more actions based thereon, wherein the one or more actions comprises one of allowing access to the one or more private applications and denying access to the one or more private applications.

12 . The non-transitory computer-readable medium of claim 11 , wherein referencing one or more AL trees is based on any of a geographic location of the user and an application segment associated with the one or more private applications.

13 . The non-transitory computer-readable medium of claim 11 , wherein access to each of the one or more private applications is based on an AL required by each of the one or more private applications.

14 . The non-transitory computer-readable medium of claim 13 , wherein responsive to determining the AL of the user is a lower AL than that required by the one or more private applications, the one or more actions comprise prompting the user to authenticate to a required AL based on the one or more private applications.

15 . The non-transitory computer-readable medium of claim 11 , wherein each of the one or more AL trees comprises one or more parent ALs and one or more child ALs.

16 . The non-transitory computer-readable medium of claim 15 , wherein each of the one or more parent ALs and one or more child ALs has a timeout period associated therewith, and wherein the timeout period of each parent AL is shorter than the timeout period of each child AL descending therefrom.

17 . The non-transitory computer-readable medium of claim 16 , wherein the steps comprise:

responsive to the timeout period of the AL of the user expiring, automatically demoting the AL of the user to a child AL of the AL of the user.

18 . The non-transitory computer-readable medium of claim 16 , wherein the determining comprises determining the AL of the user is a higher AL than an AL required by the one or more private applications, and wherein the steps comprise allowing access to the one or more private applications based thereon.

19 . The non-transitory computer-readable medium of claim 18 , wherein responsive to a timeout period of the AL of the user expiring, continuing a session for the user based on a child AL of the AL of the user being at or above an AL required by the one or more private applications.

20 . The non-transitory computer-readable medium of claim 11 , wherein responsive to determining the AL of the user, the one or more actions comprise allowing access to one or more applications requiring a lower AL than the AL of the user.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 18, 2024
From: SINGH, RAHUL; JASYAL, MANISH; ATTARWALA, MURTUZA; WANG, WEI
To: ZSCALER, INC.
Reel/Frame 067756/0659 →
Continuity (1)
Related Publication 20240372860A1 · Nov 7, 2024
References Cited (25)
US 7023793B2 · Khambatkone et al. · 2006 [cited by applicant]
US 7283462B1 · Attarwala et al. · 2007 [cited by applicant]
US 7525981B2 · Attarwala et al. · 2009 [cited by applicant]
US 8576841B2 · Ramaraj et al. · 2013 [cited by applicant]
US 8873554B2 · Baban et al. · 2014 [cited by applicant]
US 8948174B2 · Szyszko et al. · 2015 [cited by applicant]
US 8949413B2 · Ramaraj et al. · 2015 [cited by applicant]
US 10412122B1 · Olofsson et al. · 2019 [cited by applicant]
US 10439950B2 · Hemige et al. · 2019 [cited by applicant]
US 11057281B2 · Attarwala · 2021 [cited by applicant]
US 11201817B2 · Aranha et al. · 2021 [cited by applicant]
US 11658898B2 · Shah et al. · 2023 [cited by applicant]
US 11943107B2 · Shah et al. · 2024 [cited by applicant]
US 20070297326A1 · Attarwala et al. · 2007 [cited by applicant]
US 20110228793A1 · Bajaj et al. · 2011 [cited by applicant]
US 20110268115A1 · Attarwala et al. · 2011 [cited by applicant]
US 20180034641A1 · Tiwari · 2018 [cited by examiner]
US 20190036770A1 · Bhau et al. · 2019 [cited by applicant]
US 20190036814A1 · Aranha et al. · 2019 [cited by applicant]
US 20190036842A1 · Aranha et al. · 2019 [cited by applicant]
US 20190141019A1 · Kariyanahalli et al. · 2019 [cited by applicant]
US 20190253457A1 · Koul · 2019 [cited by examiner]
US 20210136066A1 · Llamas Virgen · 2021 [cited by examiner]
US 20230090829A1 · Raza et al. · 2023 [cited by applicant]
US 20230281290A1 · Mahaffey · 2023 [cited by examiner]