DETERMINING SESSION DURATION FOR DEVICE AUTHENTICATION

    公开(公告)号:US20230216847A1

    公开(公告)日:2023-07-06

    申请号:US18120889

    申请日:2023-03-13

    IPC分类号: H04L9/40

    CPC分类号: H04L63/0876 H04L63/108

    摘要: Techniques for adjusting a duration of an authenticated user device session. A baseline session duration is determined for a session for which a user account is authorized in response to a request for authentication. A first session is established on behalf of a user device associated with the user account based at least in part on the user account performing a first authentication. A posture associated with the user device is determined. The baseline duration is then adjusted to a dynamic duration based at least in part upon the posture associated with the user device. Based at least in part on the dynamic duration the user can be required to re-authenticate.

    Network security from host and network impersonation

    公开(公告)号:US11418481B2

    公开(公告)日:2022-08-16

    申请号:US17492214

    申请日:2021-10-01

    摘要: Systems and methods may include sending, to a network registrar, a first message including a first nonce generated by a host computing device, and receiving, from the network registrar, a second message including a second nonce, the second nonce being signed by the network registrar via a private key of a first public key infrastructure (PKI) key pair of the network registrar via a first signature. The method further includes sending a first neighbor advertisement (NA) message to the host computing device including the second nonce. The second nonce and the private key of the network registrar verifies the first signature from the network registrar, the verification of the first signature indicating that the router is not impersonating the network.

    NETWORK SECURITY FROM HOST AND NETWORK IMPERSONATION

    公开(公告)号:US20220116354A1

    公开(公告)日:2022-04-14

    申请号:US17492214

    申请日:2021-10-01

    摘要: Systems and methods may include sending, to a network registrar, a first message including a first nonce generated by a host computing device, and receiving, from the network registrar, a second message including a second nonce, the second nonce being signed by the network registrar via a private key of a first public key infrastructure (PKI) key pair of the network registrar via a first signature. The method further includes sending a first neighbor advertisement (NA) message to the host computing device including the second nonce. The second nonce and the private key of the network registrar verifies the first signature from the network registrar, the verification of the first signature indicating that the router is not impersonating the network.

    Redundant multicast tree in a fat tree network topology with anisotropic routing

    公开(公告)号:US11271774B2

    公开(公告)日:2022-03-08

    申请号:US16747157

    申请日:2020-01-20

    摘要: In one embodiment, a method comprises identifying a fat tree network topology comprising top-of-fabric (ToF) switching devices, an intermediate layer of intermediate switching devices connected to each of the ToF switching devices, and a layer of leaf network devices; and causing a first leaf network device to initiate establishment of first and second redundant multicast trees for multicasting of data packets, including: causing first and second ToF switching devices to operate as roots of the first and second multicast trees according to first and second attribute types, respectively, causing the first leaf network device to select first and second of the intermediate switching devices as first and second flooding relays belonging to the first and second attribute types, respectively, and causing the first and second flooding relays to limit propagation of registration messages generated by the first leaf network device to the first and second ToF switching devices, respectively.

    DETERMINING SESSION DURATION FOR DEVICE AUTHENTICATION

    公开(公告)号:US20220070156A1

    公开(公告)日:2022-03-03

    申请号:US17004368

    申请日:2020-08-27

    IPC分类号: H04L29/06 H04L29/08

    摘要: This disclosure describes techniques for authenticating a user device for a session. For instance, an authentication entity may authenticate a user device using single sign-on authentication and/or multi-factor authentication. The authentication entity may then determine a duration for which the user device is authenticated for the session. For example, the authentication entity may receive information representing a state of an environment of the user device. The authentication entity may then use the information to identify one or more transitions associated with the environment between the session and a previous session. Using the one or more transitions, the authentication entity may determine the duration for the session by increasing or decreasing a previous duration associated with the previous session.