Duo Mobile 图标

Duo Mobile MFA 数据 API:端点与字段

Cisco Systems, Inc. · 身份

Duo Mobile 是 Cisco Systems 为 Duo Security 提供的认证器——Duo 是 Cisco 于 2018 年收购的企业多因素认证产品。账户列表屏为每个已登记的 Duo 租户保留一张卡片,显示轮换的 HOTP 或 TOTP 口令;推送通知会打开批准或拒绝提示,并可要求步进验证码、GPS、蓝牙近距或生物识别 PIN。围绕该提示,应用通过扫描二维码激活码登记手机,在换机时重连或恢复账户(即时恢复与加密的 Google 备份),在认证因素被添加或身份核验问询开始时展示安全告警,并支持通过蓝牙的无密码 Windows 登录以及浏览器内联认证的受信终端检查。Cisco 把 Duo 卖给需要保护 VPN、SSO 与 SaaS 登录的 IT 团队;本页覆盖 Duo 总部所在的美国市场,它与 Microsoft Authenticator、Okta Verify、Google Authenticator 和 Twilio Authy 同属职场 MFA 一类。

待处理的 MFA 登录请求以 urgId 与手机的 pkey 为键,是这里反复出现的记录。每条请求带有 summary、type、expirationSec 窗口以及可选的 stepUpCodeInfo;设备信息调用则补充 os_status、integrity_status、require_mdm 等姿态标志,以及 customer_name、customer_logo 等租户外观。

安全告警行报告谁改动了认证因素——username、ipAddress、authFactorType、canQuarantine——changeType 取值如 new_auth_device 或 identity_verification,身份核验问询还会附上 identityVerificationId。换机恢复用 ir_nonce 换取 encrypted_hotp_key,并可在 revocationDeadline 截止。SOC 流水线、MDM 清单与身份治理工具消费这些字段;openData Studio 把它们变成可调用的开放数据。

应用截图

  • Duo Mobile 应用截图 1
  • Duo Mobile 应用截图 2
  • Duo Mobile 应用截图 3
  • Duo Mobile 应用截图 4
  • Duo Mobile 应用截图 5
  • Duo Mobile 应用截图 6

API 端点一览

以下端点与请求/响应示例均依据应用界面推导重构,为示意说明,并非实际抓包。

  • 在本机激活 Duo 账户

    POST /v1/enrollment/activate osint

    用扫描到的激活码换取本机 pkey、HMAC akey、HOTP/TOTP 密钥以及租户外观(customer_name、logo、卡片颜色),供后续每个设备调用使用。

    认证方式: 无需登录的登记调用。请求体携带二维码或邮件链接中的激活码,并附加 customer_protocol=1。响应中的 akey 是后续设备调用的 HMAC 密钥,pkey 是手机标识。

    • stat
    • pkey
    • akey
    • hotp_secret
    • use_totp
    • customer_name
    • customer_logo
    • customer_logo_md5
    • card_accent_color
    • current_app_version
    • current_os_version
    • app_status
    • os_status
    • admin
    • force_disable_analytics
    • has_trusted_endpoints
    • instant_restore_status
    • integrity_nonce
    • security_checkup_enabled
    • auth_mute_duration
    • auth_mute_expiration
    POST /v1/enrollment/activate HTTP/1.1
    Content-Type: application/json
    
    {
      "activation_code": "abc123def456",
      "customer_protocol": 1,
      "app_id": "com.duosecurity.duomobile",
      "app_version": "4.123.0",
      "platform": "Android",
      "os_version": "14",
      "manufacturer": "Google",
      "model": "Pixel 8",
      "jailbroken": false,
      "full_disk_encryption": true
    }
    {
      "stat": "OK",
      "response": {
        "pkey": "DPABC123XYZ",
        "akey": "9f8e7d6c5b4a39281706f5e4d3c2b1a09876543210",
        "hotp_secret": "JBSWY3DPEHPK3PXP",
        "use_totp": true,
        "customer_name": "Contoso",
        "customer_logo": "https://logo.example/contoso.png",
        "customer_logo_md5": "5d41402abc4b2a76b9719d911017c592",
        "card_accent_color": "#6B4C9A",
        "current_app_version": "4.123.0",
        "current_os_version": "14",
        "app_status": 1,
        "os_status": 1,
        "admin": 0,
        "force_disable_analytics": false,
        "has_trusted_endpoints": true,
        "instant_restore_status": "enrolled",
        "integrity_nonce": "n-8f21c0aa",
        "security_checkup_enabled": true,
        "auth_mute_duration": 0,
        "auth_mute_expiration": 0.0
      }
    }
  • 读取已登记设备信息与租户策略

    GET /v1/devices/status opendata

    返回已登记手机的 pkey、urg_token、租户策略标志(require_mdm、has_trusted_endpoints、security_checkup_enabled)以及姿态状态(app_status、os_status、integrity_status)。

    认证方式: 用账户 akey 对请求做 HMAC-SHA1 签名;账户登记后附加授权头,pkey 标识手机。先前状态或激活响应中的 urg_token 也可附带。调用还会携带设备遥测(app_id、platform、jailbroken、full_disk_encryption)。

    • stat
    • pkey
    • akey
    • urg_token
    • customer_name
    • customer_logo
    • app_status
    • os_status
    • integrity_status
    • integrity_nonce
    • new_keys_required
    • require_mdm
    • has_trusted_endpoints
    • has_device_change_feature
    • instant_restore_status
    • security_checkup_enabled
    • use_totp
    • admin
    • force_disable_analytics
    GET /v1/devices/status HTTP/1.1
    Authorization: Basic DPABC123XYZ:hmac-sha1-of-request
    {
      "stat": "OK",
      "response": {
        "pkey": "DPABC123XYZ",
        "akey": "9f8e7d6c5b4a39281706f5e4d3c2b1a09876543210",
        "urg_token": "urg-7f2c91aa",
        "customer_name": "Contoso",
        "customer_logo": "https://logo.example/contoso.png",
        "customer_logo_md5": "5d41402abc4b2a76b9719d911017c592",
        "card_accent_color": "#6B4C9A",
        "current_app_version": "4.123.0",
        "current_os_version": "14",
        "app_status": 1,
        "os_status": 1,
        "integrity_status": 1,
        "integrity_nonce": "n-8f21c0aa",
        "new_keys_required": 0,
        "require_mdm": 0,
        "has_trusted_endpoints": true,
        "has_device_change_feature": true,
        "instant_restore_status": "enrolled",
        "security_checkup_enabled": true,
        "use_totp": true,
        "admin": 0,
        "force_disable_analytics": false,
        "auth_mute_duration": 0,
        "auth_mute_expiration": 0.0
      }
    }
  • 登记 FCM 推送令牌

    POST /v1/devices/push-token opendata

    上传以 gcm_token 保存的 Firebase Cloud Messaging 令牌(前缀 GCM:),以便 Duo 向本机投递登录请求与安全告警推送。

    认证方式: 用 akey 做 HMAC-SHA1 签名;pkey 标识手机。平台推送服务签发新令牌后发送。

    • stat
    • pkey
    • gcm_token
    • platform
    • app_version
    POST /v1/devices/push-token HTTP/1.1
    Authorization: Basic DPABC123XYZ:hmac-sha1-of-request
    Content-Type: application/json
    
    {
      "pkey": "DPABC123XYZ",
      "gcm_token": "GCM:cXyzFcmRegistrationToken",
      "platform": "Android",
      "app_version": "4.123.0"
    }
    {
      "stat": "OK"
    }
  • 列出待处理 MFA 推送事务

    GET /v1/auth-requests osint

    分页返回本机未处理的登录请求推送:每条记录含 id(urgId)、summary、type、expirationSec、步进验证码位数以及组织/用户属性三元组。

    认证方式: 用账户 akey 对请求做 HMAC-SHA1 签名;pkey 标识手机。

    • stat
    • current_time
    • transactions
    • id
    • txid
    • summary
    • type
    • expirationSec
    • requireSecondAuth
    • mustRotateOnApprove
    • stepUpCodeInfo
    • numDigits
    • requireGps
    • isProximityPush
    • isStrictProximityPush
    • passwordlessOsLoginId
    • attributes
    GET /v1/auth-requests HTTP/1.1
    Authorization: Basic DPABC123XYZ:hmac-sha1-of-request
    {
      "stat": "OK",
      "response": {
        "current_time": 1770000000,
        "transactions": [
          {
            "id": "urg-aa11bb22",
            "txid": "tx-998877",
            "summary": "Login to VPN from Chrome on macOS",
            "type": "auth",
            "expirationSec": 60,
            "requireSecondAuth": false,
            "mustRotateOnApprove": false,
            "blockBiometricPinFallback": false,
            "isProximityPush": false,
            "isStrictProximityPush": false,
            "requireGps": false,
            "passwordlessOsLoginId": null,
            "passwordlessOsOfflineEnrollment": null,
            "stepUpCodeInfo": { "numDigits": 2 },
            "attributes": [
              [["Organization", "Contoso"], ["Application", "VPN"]],
              [["username", "[email protected]"], ["location", "Austin, TX"]],
              []
            ]
          }
        ]
      }
    }
  • 获取单条 MFA 推送事务

    GET /v1/auth-requests/{requestId} osint

    按 urgId 加载单条待处理登录请求,供批准/拒绝屏渲染 summary、type、步进验证码位数以及组织/用户属性三元组。

    认证方式: 用 akey 做 HMAC-SHA1 签名;pkey 标识手机。urgId 来自推送载荷或待处理请求列表。

    • stat
    • current_time
    • transaction
    • id
    • txid
    • summary
    • type
    • expirationSec
    • requireSecondAuth
    • mustRotateOnApprove
    • blockBiometricPinFallback
    • stepUpCodeInfo
    • numDigits
    • attributes
    GET /v1/auth-requests/urg-aa11bb22 HTTP/1.1
    Authorization: Basic DPABC123XYZ:hmac-sha1-of-request
    {
      "stat": "OK",
      "response": {
        "current_time": 1770000000,
        "transaction": {
          "id": "urg-aa11bb22",
          "txid": "tx-998877",
          "summary": "Login to Office 365",
          "type": "auth",
          "expirationSec": 60,
          "requireSecondAuth": true,
          "mustRotateOnApprove": true,
          "blockBiometricPinFallback": true,
          "isProximityPush": false,
          "isStrictProximityPush": false,
          "requireGps": false,
          "passwordlessOsLoginId": null,
          "stepUpCodeInfo": { "numDigits": 2 },
          "attributes": [
            [["Organization", "Contoso"], ["Application", "Office 365"]],
            [["username", "[email protected]"], ["browser", "Edge"]],
            []
          ]
        }
      }
    }
  • 批准或拒绝 MFA 推送

    POST /v1/auth-requests/{requestId}/decision osint

    写入用户对一条待处理登录的批准/拒绝(及可选 step_up_code)。无密码操作系统登录时,响应返回 passwordlessOsLoginEncryptedSecret 与封装的离线密钥。

    认证方式: 用 akey 做 HMAC-SHA1 签名;pkey 标识手机。用户在登录提示上点击批准、拒绝或输入步进验证码时提交。

    • stat
    • pkey
    • answer
    • step_up_code
    • step_up_code_autofilled
    • remediationBody
    • remediationTitle
    • passwordlessOsLoginId
    • passwordlessOsLoginEncryptedSecret
    • passwordlessOsOfflineWrappedSymmetricKey
    POST /v1/auth-requests/urg-aa11bb22/decision HTTP/1.1
    Authorization: Basic DPABC123XYZ:hmac-sha1-of-request
    Content-Type: application/json
    
    {
      "pkey": "DPABC123XYZ",
      "answer": "approve",
      "step_up_code": "14",
      "step_up_code_autofilled": false
    }
    {
      "stat": "OK",
      "response": {
        "remediationBody": null,
        "remediationTitle": null,
        "passwordlessOsLoginId": null,
        "passwordlessOsLoginEncryptedSecret": null,
        "passwordlessOsOfflineWrappedSymmetricKey": null
      }
    }
  • 列出认证因素安全告警

    GET /v1/security-events osint

    返回未处理的安全告警(认证因素添加/移除、身份核验),含操作者 username、ipAddress、location,以及用户是否可隔离该变更。

    认证方式: 用账户 akey 对请求做 HMAC-SHA1 签名;pkey 标识手机。

    • stat
    • notifications
    • notificationID
    • changeType
    • expiration
    • time
    • username
    • location
    • ipAddress
    • authFactorName
    • authFactorType
    • phoneNumber
    • canQuarantine
    • ssoEmail
    • identityVerificationId
    GET /v1/security-events HTTP/1.1
    Authorization: Basic DPABC123XYZ:hmac-sha1-of-request
    {
      "stat": "OK",
      "response": {
        "notifications": [
          {
            "notificationID": "n-44cc55dd",
            "changeType": "new_auth_device",
            "expiration": 1770003600,
            "info": {
              "time": 1770000000.0,
              "username": "[email protected]",
              "location": "Austin, TX",
              "ipAddress": "203.0.113.10",
              "authFactorName": "Hardware token",
              "authFactorType": "token",
              "phoneNumber": null,
              "canQuarantine": true,
              "ssoEmail": "[email protected]",
              "identityVerificationId": null
            }
          }
        ]
      }
    }
  • 获取单条安全告警

    GET /v1/security-events/{eventId} osint

    按 notificationID 加载单条安全告警;当告警为身份核验问询时包含 identityVerificationId。

    认证方式: 用账户 akey 对请求做 HMAC-SHA1 签名;pkey 标识手机。

    • stat
    • notificationID
    • changeType
    • expiration
    • username
    • location
    • ipAddress
    • ssoEmail
    • canQuarantine
    • identityVerificationId
    GET /v1/security-events/n-44cc55dd HTTP/1.1
    Authorization: Basic DPABC123XYZ:hmac-sha1-of-request
    {
      "stat": "OK",
      "response": {
        "notificationID": "n-44cc55dd",
        "changeType": "identity_verification",
        "expiration": 1770003600,
        "info": {
          "time": 1770000000.0,
          "username": "[email protected]",
          "location": "Austin, TX",
          "ipAddress": "203.0.113.10",
          "authFactorName": null,
          "authFactorType": null,
          "phoneNumber": null,
          "canQuarantine": false,
          "ssoEmail": "[email protected]",
          "identityVerificationId": "inq_8e21c0"
        }
      }
    }
  • 开始处理安全告警

    POST /v1/security-events/{eventId}/begin osint

    将安全告警标记为 in_progress,返回 status 与 expiresAt,以便因素变更或身份核验流程在窗口关闭前继续。

    认证方式: 用账户 akey 对请求做 HMAC-SHA1 签名;pkey 标识手机。

    • stat
    • pkey
    • status
    • expiresAt
    POST /v1/security-events/n-44cc55dd/begin HTTP/1.1
    Authorization: Basic DPABC123XYZ:hmac-sha1-of-request
    Content-Type: application/json
    
    {
      "pkey": "DPABC123XYZ"
    }
    {
      "stat": "OK",
      "response": {
        "status": "in_progress",
        "expiresAt": 1770003600.0
      }
    }
  • 回复安全告警

    POST /v1/security-events/{eventId}/respond osint

    写入用户对认证因素变更或身份核验告警的批准 / 拒绝 / 隔离决定。

    认证方式: 用账户 akey 对请求做 HMAC-SHA1 签名;pkey 标识手机。

    • stat
    • pkey
    • answer
    • can_quarantine
    POST /v1/security-events/n-44cc55dd/respond HTTP/1.1
    Authorization: Basic DPABC123XYZ:hmac-sha1-of-request
    Content-Type: application/json
    
    {
      "pkey": "DPABC123XYZ",
      "answer": "approve",
      "can_quarantine": true
    }
    {
      "stat": "OK"
    }
  • 将本机登记到即时恢复

    POST /v1/recovery/enroll osint

    登记本机即时恢复公钥(new_ir_pubkey),以便更换手机后无需新二维码即可重新激活同一 Duo 账户。

    认证方式: 用账户 akey 对请求做 HMAC-SHA1 签名;pkey 标识手机。

    • stat
    • pkey
    • new_ir_pubkey
    • public_key_version
    • instant_restore_status
    POST /v1/recovery/enroll HTTP/1.1
    Authorization: Basic DPABC123XYZ:hmac-sha1-of-request
    Content-Type: application/json
    
    {
      "pkey": "DPABC123XYZ",
      "new_ir_pubkey": "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA...",
      "public_key_version": 1
    }
    {
      "stat": "OK",
      "response": {
        "instant_restore_status": "enrolled",
        "pkey": "DPABC123XYZ"
      }
    }
  • 开始即时恢复握手

    POST /v1/recovery/handshake osint

    开启即时恢复握手:新手机发送 ir_nonce 与 new_ir_pubkey,并在下发 encrypted_hotp_key 之前收到 new_ir_nonce。

    认证方式: 用旧手机或加密备份中的恢复材料做 HMAC-SHA1 签名;在重新激活之前调用。

    • stat
    • pkey
    • ir_nonce
    • new_ir_nonce
    • new_ir_pubkey
    • public_key_version
    • instant_restore_status
    POST /v1/recovery/handshake HTTP/1.1
    Content-Type: application/json
    
    {
      "pkey": "DPABC123XYZ",
      "ir_nonce": "irn-0a1b2c3d",
      "new_ir_pubkey": "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA...",
      "public_key_version": 1
    }
    {
      "stat": "OK",
      "response": {
        "new_ir_nonce": "irn-9f8e7d6c",
        "instant_restore_status": "started"
      }
    }
  • 通过 Android 即时恢复重新激活账户

    POST /v1/recovery/reactivate-mobile osint

    在新的 Android 手机上重新激活 Duo 账户,返回新的 pkey 与 encrypted_hotp_key,以便恢复 TOTP/HOTP 生成。

    认证方式: 用旧手机或加密备份中的恢复材料做 HMAC-SHA1 签名;响应签发新的 pkey。

    • stat
    • pkey
    • encrypted_hotp_key
    • use_totp
    • new_ir_pubkey
    • platform
    • app_version
    POST /v1/recovery/reactivate-mobile HTTP/1.1
    Content-Type: application/json
    
    {
      "pkey": "DPABC123XYZ",
      "new_ir_pubkey": "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA...",
      "platform": "Android",
      "app_version": "4.123.0"
    }
    {
      "stat": "OK",
      "response": {
        "pkey": "DPNEW456XYZ",
        "encrypted_hotp_key": "U2FsdGVkX1+encryptedHotpKey==",
        "use_totp": true
      }
    }
  • 通过跨平台即时恢复重新激活

    POST /v1/recovery/reactivate osint

    在更换后的手机上重新激活 Duo 账户(非 Android 专用路径),返回新的 pkey 与 encrypted_hotp_key,以便恢复 TOTP/HOTP 生成。

    认证方式: 用旧手机或加密备份中的恢复材料做 HMAC-SHA1 签名;响应签发新的 pkey。与移动端专用重新激活调用同级,二者返回相同载荷。

    • stat
    • pkey
    • encrypted_hotp_key
    • use_totp
    • ir_nonce
    • new_ir_nonce
    • new_ir_pubkey
    • public_key_version
    POST /v1/recovery/reactivate HTTP/1.1
    Content-Type: application/json
    
    {
      "pkey": "DPABC123XYZ",
      "ir_nonce": "irn-0a1b2c3d",
      "new_ir_nonce": "irn-9f8e7d6c",
      "new_ir_pubkey": "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA...",
      "public_key_version": 1
    }
    {
      "stat": "OK",
      "response": {
        "pkey": "DPNEW456XYZ",
        "encrypted_hotp_key": "U2FsdGVkX1+encryptedHotpKey==",
        "use_totp": true
      }
    }
  • 撤销待处理的即时恢复

    POST /v1/recovery/cancel osint

    从旧手机取消待处理的自动恢复/重新激活,返回 revocationDeadline(线上字段 revocation_deadline),过期后恢复窗口关闭。

    认证方式: 用 akey 做 HMAC-SHA1 签名;pkey 标识仍已登记的旧手机。

    • stat
    • pkey
    • revocationDeadline
    • revocation_deadline
    POST /v1/recovery/cancel HTTP/1.1
    Authorization: Basic DPABC123XYZ:hmac-sha1-of-request
    Content-Type: application/json
    
    {
      "pkey": "DPABC123XYZ"
    }
    {
      "stat": "OK",
      "response": {
        "revocationDeadline": 1770086400.0
      }
    }
  • 轮换 HOTP/TOTP 密钥

    POST /v1/credentials/rotate osint

    在需要轮换的批准之后签发新的 encrypted_hotp_secret,替换手机上存储的口令种子。

    认证方式: 用 akey 做 HMAC-SHA1 签名;pkey 标识手机。当登录请求带 mustRotateOnApprove 或设备状态置位 new_keys_required 时触发。

    • stat
    • pkey
    • pubkey
    • encrypted_hotp_secret
    POST /v1/credentials/rotate HTTP/1.1
    Authorization: Basic DPABC123XYZ:hmac-sha1-of-request
    Content-Type: application/json
    
    {
      "pkey": "DPABC123XYZ",
      "pubkey": "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA..."
    }
    {
      "stat": "OK",
      "response": {
        "pkey": "DPABC123XYZ",
        "encrypted_hotp_secret": "U2FsdGVkX1+rotatedHotpSecret=="
      }
    }
  • 检查本机 HOTP/TOTP 密钥

    POST /v1/credentials/verify osint

    证明本机仍持有预期的密钥材料(pubkey)而不进行轮换;在设备状态置位 new_keys_required 或在轮换之前使用。

    认证方式: 用 akey 做 HMAC-SHA1 签名;pkey 标识手机。与凭据轮换调用一起运行。

    • stat
    • pkey
    • pubkey
    POST /v1/credentials/verify HTTP/1.1
    Authorization: Basic DPABC123XYZ:hmac-sha1-of-request
    Content-Type: application/json
    
    {
      "pkey": "DPABC123XYZ",
      "pubkey": "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA..."
    }
    {
      "stat": "OK",
      "response": {
        "pkey": "DPABC123XYZ"
      }
    }
  • 提交 Play Integrity 证明

    POST /v1/devices/attestation opendata

    提交针对 integrity_nonce 签发的 Play Integrity 证明,供租户设置 integrity_status 并拒绝来自被入侵手机的推送。

    认证方式: 用 akey 做 HMAC-SHA1 签名;pkey 标识手机。证明所用的 nonce 与 pkey 来自设备状态响应中的 integrity_nonce。

    • stat
    • pkey
    • nonce
    • integrity_status
    POST /v1/devices/attestation HTTP/1.1
    Authorization: Basic DPABC123XYZ:hmac-sha1-of-request
    Content-Type: application/json
    
    {
      "pkey": "DPABC123XYZ",
      "nonce": "n-8f21c0aa"
    }
    {
      "stat": "OK",
      "response": {
        "integrity_status": 1,
        "pkey": "DPABC123XYZ"
      }
    }
  • 为内联认证核验受信终端

    POST /v1/devices/trust-check osint

    检查浏览器/设备来源是否为受信终端。返回 trusted_endpoint、可选 bypass_auth、origin_check_failure_reason,以及附带登录时的内联认证事务。

    认证方式: 用 akey 做 HMAC-SHA1 签名;pkey 标识手机。当 has_trusted_endpoints 为真时,由内联浏览器登录流程使用。

    • stat
    • trusted_endpoint
    • bypass_auth
    • origin_check_failure_reason
    • urgid
    • current_time
    • transaction
    • id
    • txid
    • summary
    • trusted_endpoints_uri
    POST /v1/devices/trust-check HTTP/1.1
    Authorization: Basic DPABC123XYZ:hmac-sha1-of-request
    Content-Type: application/json
    
    {
      "pkey": "DPABC123XYZ",
      "trusted_endpoints_uri": "https://access.example/trusted"
    }
    {
      "stat": "OK",
      "response": {
        "trusted_endpoint": true,
        "bypass_auth": false,
        "origin_check_failure_reason": null,
        "urgid": "urg-aa11bb22",
        "current_time": 1770000000,
        "transaction": {
          "id": "urg-aa11bb22",
          "txid": "tx-998877",
          "summary": "Inline login from Chrome",
          "type": "auth",
          "expirationSec": 60,
          "requireSecondAuth": false,
          "attributes": []
        }
      }
    }

数据类别

  • MFA 事务
  • 设备姿态
  • 安全告警
  • 账户登记

数据使用场景与案例

  • MFA 批准/拒绝的 SOC 流

    SIEM 连接器按 urgId 分页待处理事务,并记录每次批准或拒绝以及 summary、type、用户名属性与是否存在 step_up_code,便于分析师把 Duo 推送与 VPN、SSO 日志关联。

  • MDM 姿态门槛

    MDM 或设备合规任务从设备信息与 Play Integrity 读取 app_status、os_status、integrity_status、require_mdm、jailbroken 与 full_disk_encryption,在手机未达租户门槛时阻断访问。

  • 认证因素变更监视

    身份治理工具消费安全告警行(changeType、ipAddress、authFactorType、canQuarantine、identityVerificationId),为意外的硬件令牌添加开单,或在需要身份核验时驱动 Persona 问询。

  • 换机恢复

    IT 入职剧本在旧手机上登记即时恢复,在新手机上启动握手(ir_nonce / new_ir_nonce),重新激活以恢复 pkey 与 encrypted_hotp_key;若旧手机仍在手,可在 revocationDeadline 前撤销该窗口。

常见问题

登记后如何标识一台 Duo 手机?

激活返回 pkey(手机标识)与 akey(HMAC 密钥)。后续设备调用用 akey 签名并发送 pkey;设备信息还会返回 urg_token,供之后的推送获取使用。

待处理 MFA 登录有哪些字段?

每条事务含 id(urgId)、txid、summary、type、expirationSec、requireSecondAuth、stepUpCodeInfo.numDigits 以及嵌套的组织/用户属性三元组。批准或拒绝时提交 answer 与可选的 step_up_code。

应用是否暴露设备姿态数据?

是。设备信息返回 app_status、os_status、integrity_status、require_mdm、has_trusted_endpoints 与 instant_restore_status。Play Integrity 针对 integrity_nonce 提交证明(extras 为 nonce、pkey),租户可据此拒绝被入侵的手机。即时恢复可启动、重新激活或撤销(revocationDeadline)。

Duo Mobile 里的安全告警是什么?

change_notifications 列出认证因素与身份核验事件,含 notificationID、changeType(new_auth_device、removed_auth_device、password_reset、bypass_code_generated、identity_verification)、username、ipAddress、location、authFactorType、canQuarantine 与 identityVerificationId。用户先开始流程,再回复批准、拒绝或隔离。

与 Duo Mobile 相似的应用

  • Microsoft Authenticator — 微软的验证器可生成 TOTP 验证码、发送推送批准,并为微软账户及 Entra ID 工作或学校账户提供无密码登录与通行密钥。
  • Google Authenticator — 谷歌验证器实现 TOTP 与 HOTP,登录 Google 或受支持的第三方网站时会显示六到八位一次性密码。
  • Twilio Authy — Twilio Authy 是一款双重验证应用,用户用手机号注册后可将一次性验证码在线备份,并支持 Android 与 iOS。
  • Okta Verify — Okta 的多因素验证应用通过推送通知或一次性验证码确认登录 Okta 账户及其保护的应用,也可作为 GitHub、Facebook 或 Google 等站点的第三方验证器。
  • PingID — Ping Identity 面向员工的多因素验证产品用手机推送、邮件或短信一次性码、TOTP 验证器、二维码和 FIDO2 等方法保护单点登录应用,并可与 Azure AD、AD FS、Windows 登录、Mac 登录和 SSH 集成。
  • RSA SecurID — RSA SecurID 是一种双重验证机制,硬件或软件令牌按固定间隔生成新的认证码,用于登录网络资源。

相关主题

  • Duo Mobile API
  • Cisco Duo MFA 端点
  • push 事务 urgId
  • Duo pkey akey
  • Duo 安全告警
  • Duo 即时恢复
  • Play Integrity Duo
  • 受信终端 Duo

需要集成这个 App 的数据 API?

我们可为任意指定 App 交付定制集成——源码交付 USD 500 起,或托管 API 按调用计费。告诉我们您需要的数据即可。

  • 每个项目均签 NDA 与 SOW
  • 3–7 天交付
  • 验收通过后才付款
  • 仅在授权范围内作业

获取报价