IP Library Patent Application 18922832
Patent Application
App. No. 18/922,832

STRONG HEADLESS AUTHENTICATION WITHOUT USER INVOLVEMENT

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/922,832
Abstract

A service installed on a user's device identifies a user that has logged into an account associated with an organization that has provided the service for installment. When the service determines that the user has successfully authenticated with an identity provider used by the organization, the service determines information about the session with the identity provider that was created to strongly authenticate the user. The service sends an authentication request to the identity provider as part of the same session with the identity provider that was created when the user was strongly authenticated. The authentication request generated by the service includes a parameter value for configuring authentication without user involvement, such as a parameter value for configuring passive or no prompt authentication. The user thus can be strongly authenticated to the service.

Claims (32)

1 . A method comprising:

authenticating a user with strong authentication to a first service with headless authentication, wherein authenticating the user comprises,

determining an identity of the user based on determining that the user has logged into an account with a service provider, wherein determining the identity of the user is based at least partly on an identity provider used by the service provider;

determining that the user has been authenticated by the identity provider based on determining that a first session with the identity provider has been created for the user; and

sending a modified authentication request to the identity provider as part of the first session to authenticate the user to the first service, wherein the modified authentication request comprises a parameter value that is for configuring authentication without user involvement.

2 . The method of claim 1 further comprising generating the modified authentication request based at least partly on a communication protocol or standard used by the identity provider, and wherein generating the modified authentication request comprises generating an authentication request and modifying the authentication request with the parameter value, wherein the parameter value comprises a first parameter value specifying passive authentication or with a second parameter value specifying no prompt.

3 . The method of claim 1 , wherein determining that the user has logged into the service provider comprises determining that the user has logged into a single sign-on (SSO) service.

4 . The method of claim 1 , wherein determining that the first session with the identity provider has been created comprises determining that at least one of a first cookie and session information corresponding to the first session has been stored on a device for which the first session was created.

5 . The method of claim 1 , further comprising determining if an age of the first session satisfies a freshness criterion, wherein sending the modified authentication request is based on determining that the age of the first session satisfies the freshness criterion.

6 . The method of claim 1 , wherein determining the identity of the user comprises determining a username of the user.

7 . The method of claim 1 , wherein authenticating the user to the first service comprises authenticating the user to a browser extension or an agent.

8 . The method of claim 1 , further comprising obtaining configuration data that identifies the identity provider and a user principal name (UPN) suffix and verifying that the identity of the user indicates the UPN suffix indicated in the configuration data, wherein sending the modified authentication request is based on verifying that the identity of the user indicates the UPN suffix.

9 . One or more non-transitory machine-readable media having program code stored thereon, the program code comprising instructions to:

determine an identity of a user that has logged into an account with a service provider based at least partly on an identity provider used by the service provider;

based on a determination that a first session with the identity provider has been created for the user, determine that the user has been authenticated by the identity provider; and

authenticate the user to a first service without involvement of the user, wherein the instructions to authenticate the user to the first service without involvement of the user comprise instructions to send an authentication request comprising a parameter value for configuring authentication without user involvement to the identity provider as part of the first session.

10 . The non-transitory machine-readable media of claim 9 , wherein the program code further comprises instructions to generate the authentication request based at least partly on a communication protocol or standard used by the identity provider, and wherein the parameter value comprises a first parameter value specifying passive authentication or a second parameter value specifying no prompt.

11 . The non-transitory machine-readable media of claim 9 , wherein the instructions to determine that the first session has been created comprise instructions to determine that at least one of a first cookie and session information corresponding to the first session has been stored on a device for which the first session was created.

12 . The non-transitory machine-readable media of claim 9 , wherein the program code further comprises instructions to determine whether an age of the first session is below a threshold, wherein the instructions to authenticate the user comprise instructions to authenticate the user based on a determination that the age of the first session is below the threshold.

13 . The non-transitory machine-readable media of claim 9 , wherein the instructions to determine the identity of the user comprise instruction to determine a username of the user.

14 . The non-transitory machine-readable media of claim 13 , wherein the program code further comprises instructions to verify that the username of the user indicates a first user principal name (UPN) suffix specified in configuration data that was previously obtained, and wherein the instructions to authenticate the user to the first service comprise instructions to authenticate the user based on verification that the username indicates the first UPN suffix.

15 . An apparatus comprising:

a processor; and

a machine-readable medium having instructions stored thereon that are executable by the processor to cause the apparatus to,

identify a user that has logged into an account with a service provider based at least partly on an identity provider used by the service provider;

determine that a first session with the identity provider has been created for the user and that the user has been authenticated by the identity provider; and

authenticate the user to a first service without involvement of the user, wherein the instructions to authenticate the user to the first service without involvement of the user comprise instructions to send an authentication request that comprises a first value specifying authentication without user involvement to the identity provider as part of the first session.

16 . The apparatus of claim 15 , further comprising instructions executable by the processor to cause the apparatus to generate the authentication request based at least partly on a communication protocol or standard used by the identity provider.

17 . The apparatus of claim 16 , wherein the instructions executable by the processor to cause the apparatus to generate the authentication request comprise instructions executable by the processor to cause the apparatus to include the first value in the authentication request as a parameter value, wherein the first value specifies passive authentication or authentication with no prompt.

18 . The apparatus of claim 15 , wherein the instructions executable by the processor to cause the apparatus to determine that the first session has been created comprise instructions executable by the processor to cause the apparatus to determine that at least one of a first cookie and session information corresponding to the first session have been stored.

19 . The apparatus of claim 15 , wherein the instructions executable by the processor to cause the apparatus to authenticate the user to a first service comprise instructions executable by the processor to cause the apparatus to authenticate to a browser extension or an agent.

20 . The apparatus of claim 15 , wherein the instructions executable by the processor to cause the apparatus to identify the user comprise instructions executable by the processor to cause the apparatus to determine a username of the user.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 24, 2025
From: TALON CYBER SECURITY LTD.
To: PALO ALTO NETWORKS, INC.
Reel/Frame 069993/0831 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 24, 2024
From: SHALTIEL, NATAN; NAVEH, MEITAR; BAR ON, GUY; BEN-NOON, OFER
To: TALON CYBER SECURITY LTD.
Reel/Frame 069002/0010 →