Centralized Firewall MFA Gateway for Network Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing multifactor authentication (MFA) solutions are costly and complex to deploy, requiring separate integration with each resource, and often burden users with intrusive workflows and the need to carry authorization tokens.

Innovation Solution

A system and process for multifactor authentication as a network service, where a firewall monitors sessions, applies authentication profiles, and performs actions based on policy rules, allowing for centralized enforcement of MFA without the need for individual application integration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing multifactor authentication solutions are deployed with separate integration with each resource, then authentication security is improved, but deployment complexity and cost increase

Engineering Contradiction:
Improveauthentication securityVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple authentication factors and resource access control into a single centralized authentication service. Instead of integrating MFA separately with each resource, the system consolidates authentication challenges, token management, and policy enforcement into one gateway that serves multiple resources, thereby reducing deployment complexity while maintaining security

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The authentication service is designed as a universal gateway that can authenticate users accessing multiple different resources through a single integration point. The system provides multi-functional capabilities including generating authentication challenges, verifying responses, managing session state, and enforcing access policies across diverse resources, eliminating the need for resource-specific MFA implementations

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If existing multifactor authentication solutions are deployed with separate integration with each resource, then authentication security is improved, but deployment cost increases

Engineering Contradiction:
Improveauthentication securityVSAvoiddeployment cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent consolidates authentication functionality into a single shared service that multiple resources can utilize. By merging authentication challenges, token generation, and verification processes into one centralized system, the organization avoids duplicating expensive authentication infrastructure at each resource, thereby reducing overall deployment cost while maintaining security standards

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If existing multifactor authentication solutions are used, then authentication security is improved, but user workflow complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoiduser workflow
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The authentication system automatically manages the complexity of multifactor authentication without requiring user intervention. The service autonomously generates authentication challenges, presents them to users through appropriate channels, verifies responses, and manages session state. This self-service approach handles the workflow complexity on the system side, keeping the user experience simple while maintaining strong authentication security

Inventive Principle:
Principle #25Self-service

4Reliability

If existing multifactor authentication solutions are deployed, then authentication security is improved, but system complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the complex authentication logic from individual resources and places it in a dedicated centralized authentication service. This extraction separates the security-critical authentication functions (challenge generation, response verification, session management) from resource-specific applications, reducing system complexity at each resource while concentrating and standardizing complexity in a single manageable service

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12212550B2Time-based network authentication challenges
Publication Date: 2025.01.28 PALO ALTO NETWORKS INC
  • US12212550B2 patent drawing
  • US12212550B2 patent drawing
  • US12212550B2 patent drawing

AI summary

Techniques for time-based network authentication challenges are disclosed. In some embodiments, a system, process, and/or computer program product for time-based network authentication challenges includes monitoring a session at a firewall to identify a user associated with the session, generating a timestamp for an authentication factor associated with the user after the user successfully authenticates for access to a resource based on an authentication profile, intercepting another request from the user for access to the resource at the firewall, and determining whether the timestamp for the authentication factor is expired based on the authentication profile.