IP Library Granted Patent US 11,799,856
Granted Patent B2
US 11,799,856 · App. 17/194,000 · Granted Oct 24, 2023

Application identification

Inventors: David Steven Gross (Cincinnati, OH); Jennifer Lee Bammel (Dexter, MI); David William Matteson (Dexter, MI); Christopher Carl Cassell (Ann Arbor, MI); Kyle David Mills (Ann Arbor, MI)
Assignee: Cisco Technology, Inc.
H04L63/0876H04L2101/663
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,799,856
App. No.
17/194,000
Granted
Oct 24, 2023
Kind
B2
Abstract

This disclosure describes techniques for identifying an application (e.g., accessing application) that is attempting to access a resource. In some examples, access may be managed by an authentication service. When an access request is received at the authentication service from an application on a client device, the authentication service may ask the application to communicate with an identification agent on the client device. The identification agent may perform one or more tests to discover the identity of the application. In some cases, the identification agent may send the identity of the application to the authentication service. The authentication service may then allow or deny access by the accessing application to the resource based at least in part on the discovered identity.

Claims (52)

1. A computer-implemented method comprising:

receiving an identity request for an identity of an application on a client device, the application sending the identity request using a first port on the client device and an identification agent receiving the identity request at a second port on the client device;

accessing a port list that lists entities using the first port and the second port of the client device;

identifying the identity of the application based at least in part on the port list and at least in part on the application using the first port;

sending, by the identification agent, a query for identity information of the application that is utilizing the first port;

receiving, in response to the query, the identity information of the application; and

sending the identity information of the application to an authentication service on a remote device.

2. The computer-implemented method of claim 1 , further comprising:

sending, from the application on the client device and to the authentication service on the remote device, an access request for a resource managed by the authentication service; and

in response to the access request, receiving, by the application and from the authentication service, a directive directing the application to send the identity request for the identity of the application to the identification agent on the client device.

3. The computer-implemented method of claim 2 , wherein the identity request for the identity of the application is a hypertext transport protocol (HTTP) request sent from the application to the identification agent.

4. The computer-implemented method of claim 1 , wherein the port list is a transport control protocol (TCP) connection table.

5. The computer-implemented method of claim 1 , further comprising:

initiating a system call, by the identification agent; and

in response to the system call, receiving, by the identification agent, a process identification (PID) of the application.

6. The computer-implemented method of claim 5 , wherein the query for the identity information of the application sent by the identification agent is based on the PID of the application received in response to the system call.

7. The computer-implemented method of claim 1 , wherein the identity information of the application includes a browser identity of a browser used to communicate between the application and the authentication service.

8. The computer-implemented method of claim 7 , wherein the identity information of the application sent to the authentication service on the remote device includes the browser identity and a version of the browser.

9. A client device comprising:

at least a first port and a second port;

one or more processors; and

one or more non-transitory computer-readable media storing computer-executable instructions that, when executed by the one or more processors, cause the one or more processors to:

receive an identity request for an identity of an application on the client device, the application sending the identity request using the first port and an identification agent receiving the identity request at the second port;

access a port list that lists entities using the first port and the second port of the client device;

identifying the identity of the application based at least in part on the port list and at least in part on the application using the first port;

send, by the identification agent, a query for identity information of the application that is utilizing the first port;

receive, in response to the query, the identity information of the application; and

send the identity information of the application to an authentication service on a remote device.

10. The client device of claim 9 , wherein the computer-executable instructions further cause the one or more processors to:

send, from the application and to the authentication service on the remote device, an access request for a resource managed by the authentication service; and

in response to the access request, receive, by the application and from the authentication service, a directive directing the application to send the identity request for the identity of the application to the identification agent on the client device.

11. The client device of claim 10 , wherein the identity request for the identity of the application is an Ajax request sent from the application to the identification agent.

12. The client device of claim 9 , wherein the port list is a transport control protocol (TCP) connection table.

13. The client device of claim 9 , wherein the computer-executable instructions further cause the one or more processors to:

initiate a system call, by the identification agent; and

in response to the system call, receive, by the identification agent, a process identification (PID) of the application.

14. The client device of claim 13 , wherein the query for the identity information of the application sent by the identification agent is based on the PID of the application received in response to the system call.

15. The client device of claim 14 , wherein the identity information of the application includes a browser identity of a browser used to communicate between the application and the authentication service.

16. The client device of claim 15 , wherein the identity information of the application sent to the authentication service on the remote device includes the browser identity and a version of the browser.

17. A method comprising:

receiving an identity request for an identity of an application on a client device, the application sending the identity request using a first port on the client device and an identification agent receiving the identity request at a second port the client device;

accessing a port list that lists entities using the first port and the second port of the client device;

identifying the identity of the application based at least in part on the port list and at least in part on the application using the first port;

sending, by the identification agent, a query for identity information of the application that is utilizing the first port; and

receiving, in response to the query, the identity information of the application.

18. The method of claim 17 , further comprising:

sending, from the application on the client device and to an authentication service on a remote device, an access request for a resource managed by the authentication service; and

in response to the access request, receiving, by the application and from the authentication service, a directive directing the application to send the identity request for the identity of the application to the identification agent on the client device.

19. The method of claim 17 , further comprising:

initiating a system call, by the identification agent; and

in response to the system call, receiving, by the identification agent, a process identification (PID) of the application.

20. The method of claim 19 , wherein the identity information of the application includes a browser identity of a browser used to communicate between the application and an authentication service.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 5, 2021
From: GROSS, DAVID STEVEN; BAMMEL, JENNIFER LEE; MATTESON, DAVID WILLIAM; CASSELL, CHRISTOPHER CARL; MILLS, KYLE DAVID
To: CISCO TECHNOLOGY, INC.
Reel/Frame 055512/0725 →
Continuity (1)
Related Publication 20220286455A1 · Sep 8, 2022