Authenticating to a hybrid cloud using intranet connectivity as silent authentication factor
Abstract
A technique for performing authentication to a hybrid-cloud service includes selectively applying varying authentication requirements based on whether a client device can be confirmed to be connected to a private intranet. The technique includes operating a set of local agents on one or more computing machines on the intranet. When a client device requests access to the hybrid-cloud service, the client device attempts to contact one or more of the local agents. If the client device succeeds in contacting a local agent, then the client device is confirmed to be connected to the private intranet and receives relatively trusting treatment during authentication. However, if the client device fails to contact at least one local agent, the client device is not confirmed to be connected to the private intranet and receives relatively less trusting treatment.
Claims
exact text as granted — not AI-modifiedWat is claimed is:
1 . A method of authenticating to a hybrid-cloud service, the hybrid-cloud service including a cloud resource on a public network and a set of local resources on a private intranet coupled to the public network, the method comprising:
receiving a plurality of requests to access the cloud resource of the hybrid-cloud service, the plurality of requests including a first set of requests originating from inside the private intranet and a second set of requests originating from outside the private intranet on the public network; authenticating the first set of requests using a first set of authentication factors; and authenticating the second set of requests using a second set of authentication factors, the second set of authentication factors including a greater number of user-entered factors than the first set of authentication factors.
2 . The method of claim 1 wherein, in response to receipt of a first request of the first set of requests, the method further comprises generating a silent authentication factor that does not require manual user entry, wherein authenticating the first request of the first set of requests is based at least in part on the silent authentication factor.
3 . The method of claim 2 , wherein receipt of the first request is via a local agent running on a device connected to the private intranet, and wherein the method further comprises receiving a request from the local agent to obtain the silent authentication factor.
4 . The method of claim 3 wherein receiving a second request of the second set of requests includes receiving a connection request by a gateway that connects the local intranet to the public network, and wherein the method further comprises, responsive to the gateway rejecting the connection request, authenticating the second request without the silent authentication factor.
5 . The method of claim 2 , wherein generating the silent authentication factor includes creating a one-time-token (OTT), the OTT expiring after being used in a single authentication request.
6 . The method of claim 2 , wherein the second set of authentication factors includes an additional authentication factor that is not one of the first set of authentication factors.
7 . The method of claim 6 , wherein the additional authentication factor requires a user of a client device to perform a manual operation.
8 . An electronic system configured as part of a hybrid-cloud service that includes a cloud resource on a public network and a set of local resources on a private intranet coupled to the public network, the electronic system comprising control circuitry constructed and arranged to:
receive a plurality of requests to access the cloud resource of the hybrid-cloud service, the plurality of requests including a first set of requests originating from inside the private intranet and a second set of requests originating from outside the private intranet on the public network; authenticate the first set of requests using a first set of authentication factors; and authenticate the second set of requests using a second set of authentication factors, the second set of authentication factors including a greater number of user-entered factors than the first set of authentication factors.
9 . The electronic system of claim 8 wherein, in response to receipt of a first request of the first set of requests, the control circuitry is further constructed and arranged to generate a silent authentication factor that does not require manual user entry, wherein authentication of the first request of the first set of requests is based at least in part on the silent authentication factor.
10 . The electronic system of claim 9 , wherein receipt of the first request is via a local agent running on a device connected to the private intranet, and wherein the control circuitry is further constructed and arranged to receive a request from the local agent to obtain the silent authentication factor.
11 . The electronic system of claim 9 , wherein generation of the silent authentication factor includes creation of a one-time-token (OTT), the OTT expiring after being used in a single authentication request.
12 . The electronic system of claim 9 , wherein the second set of authentication factors includes an additional authentication factor that is not one of the first set of authentication factors.
13 . The electronic system of claim 12 , wherein the additional authentication factor requires a user of a client device to perform a manual operation.
14 . A computer program product including a set of non-transitory, computer-readable media having instructions which, when executed by control circuitry of an electronic system, cause the electronic system to perform a method of authenticating to a hybrid-cloud service that includes a cloud resource on a public network and a set of local resources on a private intranet coupled to the public network, the method comprising:
receiving a plurality of requests to access the cloud resource of the hybrid-cloud service, the plurality of requests including a first set of requests originating from inside the private intranet and a second set of requests originating from outside the private intranet on the public network; authenticating the first set of requests using a first set of authentication factors; and authenticating the second set of requests using a second set of authentication factors, the second set of authentication factors including a greater number of user-entered factors than the first set of authentication factors.
15 . The computer program product of claim 14 wherein, in response to receipt of a first request of the first set of requests, the method further comprises generating a silent authentication factor that does not require manual user entry, wherein authenticating the first request of the first set of requests is based at least in part on the silent authentication factor.
16 . The computer program product of claim 15 , wherein the first request is received via a local agent running on a device connected to the private intranet, and wherein authenticating the first request includes receiving a request by the local agent to obtain the silent authentication factor.
17 . The computer program product of claim 16 wherein receiving a second request of the second set of requests includes receiving a connection request by a gateway that connects the local intranet to the public network, and wherein the method further comprises, responsive to the gateway rejecting the connection request, authenticating the second request without the silent authentication factor.
18 . The computer program product of claim 15 , wherein generating the silent authentication factor includes creating a one-time-token (OTT), the OTT expiring after being used in a single authentication request.
19 . The computer program product of claim 15 , wherein the second set of authentication factors includes an additional authentication factor that is not one of the first set of authentication factors.
20 . The computer program product of claim 19 , wherein the additional authentication factor requires a user of a client device to perform a manual operation.Join the waitlist — get patent alerts
Track US2022158977A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.