IP Library Granted Patent US 12,101,319
Granted Patent B2
US 12,101,319 · App. 17/448,536 · Granted Sep 24, 2024

Computing session multi-factor authentication

Inventors: Georgy Momchilov (Parkland, FL); Hubert Divoux (Parkland, FL); Santosh Gummunur Chiranjeevi Sampath (Bangalore, IN); Leo C. Singleton, IV (Fort Lauderdale, FL)
H04L63/0884H04L63/0838H04L63/0846H04L63/0861H04L2463/082
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,101,319
App. No.
17/448,536
Granted
Sep 24, 2024
Kind
B2
Abstract

A computing device includes a memory and a processor configured to cooperate with the memory to receive a connection lease and a token from a client device, with the token being generated responsive to the client device completing multi-factor authentication (MFA) with a provider of MFA. The processor further verifies, responsive to unavailability of the provider of MFA, that the client device has previously performed MFA based upon the token, and connect the client device to a computing session with use of the connection lease and responsive to the verification that the client device has performed MFA.

Claims (30)

1. A computing device comprising:

a memory and a processor configured to cooperate with the memory to:

receive a connection lease and a token from a client device, the token being generated responsive to the client device completing Multi-Factor Authentication (MFA) with a provider of MFA in compliance with an MFA policy;

verify, responsive to unavailability of the provider of MFA, that the client device has previously performed MFA based upon the token and a secondary information, wherein the secondary information is selected from an IP address for a prior successful MFA, a latency associated with communications with the client device, or a combination thereof;

change a level of access associated with a computing session responsive to an identity provider being offline; and

connect the client device to the computing session with use of the connection lease and responsive to the verification that the client device has performed MFA, wherein the connecting comprises selecting an appropriate policy tier from a plurality of tiers of the MFA policy based on a user context.

2. The computing device of claim 1 wherein the connection lease includes data about the MFA; and wherein the processor is further configured to verify that the token is valid based upon the data, and connect the client device to the computing session also responsive to verification of the token being valid.

3. The computing device of claim 1 wherein the processor verifies that the client device has performed MFA for external connections outside of a network.

4. The computing device of claim 1 wherein the token has an expiration, and wherein the processor requests MFA authentication from the MFA provider prior to the expiration of the token.

5. The computing device of claim 4 wherein the processor is further configured to delay the MFA authentication request responsive to an identity provider being offline and extend the connection to the computing session during the delay.

6. The computing device of claim 1 wherein the MFA comprises generating a Time-based One-time Password (TOTP) based upon a key, and wherein the processor is further configured to receive the key and verify that the client device has performed MFA based upon the key.

7. A method comprising:

at a computing device,

receiving a connection lease and a token from a client device, the token being generated responsive to the client device completing Multi-Factor Authentication (MFA) with a provider of MFA in compliance with an MFA policy;

verifying, responsive to unavailability of the provider of MFA, that the client device has previously performed MFA based upon the token and a secondary information, wherein the secondary information is selected from an IP address for a prior successful MFA, a latency associated with communications with the client device, or a combination thereof;

changing a level of access associated with a computing session responsive to an identity provider being offline; and

connecting the client device to the computing session with use of the connection lease and responsive to the verification that the client device has performed MFA, wherein the connecting comprises selecting an appropriate policy tier from a plurality of tiers of the MFA policy based on a user context.

8. The method of claim 7 wherein the connection lease includes data about the MFA; wherein verifying further comprises verifying that the token is valid based upon the data; and wherein connecting further comprises connecting the client device to the computing session also responsive to verification of the token being valid.

9. The method of claim 7 wherein verifying comprises verifying that the client device has performed MFA for external connections outside of a network.

10. The method of claim 7 wherein the token has an expiration, and further comprising, at the computing device, requesting MFA authentication from the MFA provider prior to the expiration of the token.

11. The method of claim 7 wherein the MFA comprises generating a Time-based One-time Password (TOTP) based upon a key, and further comprising, at the computing device, receiving the key and verifying that the client device has performed MFA based upon the key.

12. A non-transitory computer-readable medium having computer-executable instructions for causing a computing device to perform steps comprising:

receiving a connection lease and a token from a client device, the token being generated responsive to the client device completing Multi-Factor Authentication (MFA) with a provider of MFA in compliance with an MFA policy;

verifying, responsive to unavailability of the provider of MFA, that the client device has previously performed MFA based upon the token and a secondary information, wherein the secondary information is selected from an IP address for a prior successful MFA, a latency associated with communications with the client device, or a combination thereof;

changing a level of access associated with a computing session responsive to an identity provider being offline; and

connecting the client device to the computing session with use of the connection lease and responsive to the verification that the client device has performed MFA, wherein the connecting comprises selecting an appropriate policy tier from a plurality of tiers of the MFA policy based on a user context.

13. The non-transitory computer-readable medium of claim 12 wherein the connection lease includes data about the MFA; wherein verifying further comprises verifying that the token is valid based upon the data; and wherein connecting further comprises connecting the client device to the computing session also responsive to verification of the token being valid.

14. The non-transitory computer-readable medium of claim 12 wherein verifying comprises verifying that the client device has performed MFA for external connections outside of a network.

15. The non-transitory computer-readable medium of claim 12 wherein the token has an expiration, and further having computer-executable instructions for causing the computing device to request MFA authentication from the MFA provider prior to the expiration of the token.

16. The non-transitory computer-readable medium of claim 12 wherein the MFA comprises generating a Time-based One-time Password (TOTP) based upon a key, and further having computer-executable instructions for causing the computing device to receive the key and verify that the client device has performed MFA based upon the key.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 23, 2021
From: MOMCHILOV, GEORGY; DIVOUX, HUBERT; SAMPATH, SANTOSH GUMMUNUR CHIRANJEEVI; SINGLETON, IV, LEO C.
To: CITRIX SYSTEMS, INC.
Reel/Frame 057572/0732 →
Continuity (2)
Provisional Application 63203025 · Jul 6, 2021
Related Publication 20230020656A1 · Jan 19, 2023
Cited By (2)
US 12,438,721 US 12,537,854