IP Library Granted Patent US 11,012,433
Granted Patent B2
US 11,012,433 · App. 16/828,426 · Granted May 18, 2021

Method and system for modifying network connection access rules using multi-factor authentication (MFA)

Inventors: Benny Lakunishok (Holon, IL); Gil David (Zichron Yaakov, IL); Yossef Jossef Harush (Bat Yam, IL)
Assignee: ZERO NETWORKS LTD.
H04L63/08G06F21/44G06F21/62G06F21/30G06F21/31H04L63/029H04L63/0838
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,012,433
App. No.
16/828,426
Granted
May 18, 2021
Kind
B2
Abstract

A method and a system for modifying network connection access rules using multi factor authentication (MFA) are provided herein. The method may include the following steps: receiving, at a computer network, an access request from a client device; retrieving a user identification data associated with said client device; presenting a message over said client device, wherein the message contains details associated with said access request; responsive to the user confirmation of said details, initiating an MFA process, wherein the MFA process comprises presenting an authentication message over the client device; and only in a case that the user has been authenticated by the MFA process, establishing the requested connection access.

Claims (14)

1. A method comprising:

receiving, at a service, a connection request directed at one of a plurality of target computers at a computer network, from one of a plurality of source computers at said computer network associated with a user, wherein the one of the plurality of source computers is blocked for network access to the one of the plurality of target computers by network security rules at said one of the plurality of target computers, wherein the network security rules are controlled by said service which is implemented as a server at said computer network, said server having privileges to remotely manage network security rules of each one of the plurality of source computers and of each one of the plurality of target computers;

presenting the user with a message containing a request to authenticate via a multi factor authentication (MFA) process; and

granting the one of the plurality of source computers network access to the one of the plurality of target computers, only in a case that the user has been authenticated by the MFA process, wherein said granting of the network access is done by said service connecting to the one of the plurality of target computers and by modifying said network security rules at said one of the plurality of target computers, to allow the connection to the one of the plurality of target computers.

2. The method according to claim 1 , wherein the one of the plurality of source computers is from among a part of the plurality of source computers all blocked for network access to the one of the plurality of target computers.

3. A system comprising:

a plurality of source computers;

a plurality of target computers; and

a service which receives, a connection request directed at one of a plurality of target computers at a computer network, from one of a plurality of source computers at said computer network associated with a user, wherein said one of the plurality of source computers is blocked for network access to said one of the plurality of target computers, by network security rules at said one of the plurality of target computers, wherein the network security rules are controlled by said service which is implemented as a server at said computer network, said server having privileges to remotely manage network security rules of each one of the plurality of source computers and of each one of the plurality of target computers,

wherein the service presents the user with a message containing a request to authenticate via a multi factor authentication (MFA) process, and

wherein the service grants the one of the plurality of source computers network access to the one of the plurality of target computers, only in a case that the user has been authenticated by the MFA process, wherein said network access is granted by the service by connecting to the one of the plurality of target computers and by modifying said network security rules at said one of the plurality of target computers to allow the connection to said one of the plurality of target computers.

4. The system according to claim 3 , wherein the one of the plurality of source computers is from among a part of the plurality of source computers all blocked for network access to the one of the plurality of target computers.

5. The method according to claim 1 , further comprising learning an access behavior of said user indicative of an access requests pattern from at least one of the plurality of source computers to at least one of the plurality of target computers, and conditioning said blocking and said presenting of the user with a message containing a request to identify via (MFA) process, based upon said access behavior.

6. The system according to claim 3 , wherein said service is configured to learn an access behavior of said user indicative of an access requests pattern from at least one of the plurality of source computers to at least one of the plurality of target computers, and condition said blocking and said presenting of the user with a message containing a request to identify via (MFA) process, based upon said access behavior.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 1, 2020
From: LAKUNISHOK, BENNY; DAVID, GIL; HARUSH, YOSSEF JOSSEF
To: ZERO NETWORKS LTD.
Reel/Frame 052279/0141 →
Continuity (2)
Provisional Application 62822903 · Mar 24, 2019
Related Publication 20200304484A1 · Sep 24, 2020
Cited By (1)
US 12,587,534