Invention Grant
- Patent Title: Whitelisting clients accessing resources via a secure web gateway with time-based one time passwords for authentication
-
Application No.: US18451155Application Date: 2023-08-17
-
Publication No.: US12041173B2Publication Date: 2024-07-16
- Inventor: Mohit Sahni
- Applicant: Palo Alto Networks, Inc.
- Applicant Address: US CA Santa Clara
- Assignee: Palo Alto Networks, Inc.
- Current Assignee: Palo Alto Networks, Inc.
- Current Assignee Address: US CA Santa Clara
- Agency: Gilliam IP PLLC
- The original application number of the division: US17314514 2021.05.07
- Main IPC: G06F21/00
- IPC: G06F21/00 ; H04L9/08 ; H04L9/32 ; H04L29/06 ; H04L67/02

Abstract:
Each tenant of a secure web gateway (SWG) is issued a secret key. A user accesses a unique secret key derived from the tenant's secret key and loads the secret key into an application which generates time-based one time passwords (TOTPs). When the SWG receives a connection request from a client and cannot decrypt the network traffic, the SWG challenges the client request and indicates an authentication scheme to be used. The client obtains user credentials, constructs a response to the challenge based on the authentication scheme, and issues a connection request to the SWG which indicates the response. The SWG determines an expected response based on a locally generated TOTP and the secret key of the corresponding tenant. If the expected response matches the provided response, the SWG authenticates the user, allows the connection request, and whitelists the client for a period longer than the lifetime of the TOTP.
Public/Granted literature
Information query