Centralized MFA Gateway for Enterprise Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing multifactor authentication (MFA) solutions require separate integration with each resource, increasing deployment costs and complexity, and are hindered by intrusive user workflows and the need for users to carry authorization tokens, deterring their adoption in enterprise networks.

Innovation Solution

Implementing a firewall-based system that provides multifactor authentication as a network service, allowing for centralized MFA deployment and enforcement, intercept-based client enrollment, detection of compromised credentials, and time-based authentication challenges to enhance security and simplify the adoption of MFA across enterprise networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate integration with each resource is implemented for MFA, then authentication security is improved, but deployment complexity and cost increase

Engineering Contradiction:
Improveauthentication securityVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple resource-specific MFA integrations into a single centralized MFA gateway that mediates all authentication requests. Instead of integrating MFA separately with each resource system, the gateway consolidates these integrations, allowing resources to authenticate users through a unified interface without requiring individual MFA implementations.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The MFA gateway is designed as a universal authentication service that can handle multiple types of authentication requests from different resources through a single system. It provides multi-functional capabilities including authentication mediation, credential verification, and security policy enforcement that serve diverse resource types without requiring resource-specific customization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If traditional MFA solutions are deployed, then security is improved, but user workflow intrusiveness increases

Engineering Contradiction:
ImprovesecurityVSAvoiduser workflow
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The MFA gateway acts as an intermediary between users and resources, seamlessly handling authentication challenges without disrupting the user's interaction with the actual resource. The gateway mediates the authentication process by intercepting login requests, performing MFA verification in the background, and allowing authenticated users to access resources without noticing the additional security steps.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements self-service MFA capabilities where users can complete authentication through automated processes such as push notifications to mobile devices, biometric verification, or cached credentials. This reduces manual intervention and makes the MFA process feel like a natural extension of the login workflow rather than an intrusive obstacle.

Inventive Principle:
Principle #25Self-service

3Reliability

If users must carry authorization tokens for MFA, then authentication reliability is improved, but ease of use deteriorates

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidease of use
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system creates digital copies of authentication credentials stored securely in the MFA gateway, eliminating the need for users to physically carry tokens or authentication devices. The gateway maintains secure copies of user credentials and can present these copies during authentication without requiring the user to have the original physical token, thus maintaining security while improving convenience.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10904237B2Multifactor authentication as a network service
Publication Date: 2021.01.26 PALO ALTO NETWORKS INC
  • US10904237B2 patent drawing
  • US10904237B2 patent drawing
  • US10904237B2 patent drawing

AI summary

Techniques for multifactor authentication as a network service are disclosed. In some embodiments, a system, process, and/or computer program product for multifactor authentication as a network service includes monitoring a session at a firewall, applying an authentication profile based on the new session, and performing an action based on the authentication profile.