IP Library Granted Patent US 12683798
Granted Patent B2
US 12683798 · App. 18/481,965 · Granted Jul 14, 2026

Efficient transfer of authentication credentials between client devices

Inventors: Chandra Shirashyad (Fremont, CA); Ildar Abdullin (Dublin, CA); Umang Shah (Fremont, CA); Naveen Kumar Keerthy (San Jose, CA); Cedric Beust (Sunnyvale, CA)
H04L9/3234H04L9/0825H04L9/3228H04L9/3231H04W4/80H04L2209/127H04L2209/80
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12683798
App. No.
18/481,965
Granted
Jul 14, 2026
Kind
B2
Abstract

An authentication system facilitates a transfer of enrollment in authentication services between client devices. The authentication system enrolls a client device in authentication services to enable the client device to be used for authenticating requests to access one or more services. As part of enrolling the client device, the authentication system receives authentication enrollment information for the client device that is associated with one or more authentication credentials securely stored on the client device (e.g., a multi-factor authentication (MFA) certificate). The authentication system facilitates one or more processes for transferring the enrollment from an enrolled client device to a non-enrolled client device that limit the number and complexity of actions performed by the user. In particular, the authentication system facilitates transfer of enrollment based on receiving enrollment transfer requests authorized by the enrolled client device using one or more authentication credentials associated with the enrollment of the enrolled client device.

Claims (43)

1 . A computer-implemented method performed by a first client device associated with a user of an authentication system, the method comprising:

receiving, from a client device associated with the user, a first request for an authorization of an enrollment transfer from the first client device to the client device;

transmitting, to the client device, an indication of the authorization of the enrollment transfer;

receiving, from the client device associated with the user, information corresponding to an authentication credential for the client device based at least in part on the authorization of the enrollment transfer;

transmitting, to the authentication system, a request to enroll the client device in authentication services of the authentication system, wherein authorization of the request is based at least in part on a first authentication credential that is associated with authentication enrollment information of the user for authenticating access requests through the authentication system, and wherein the request includes the information corresponding to the authentication credential provided by the client device; and

receiving, from the authentication system, confirmation of enrollment of the client device, wherein the enrollment of the client device includes associating the authentication enrollment information for the user with at least the authentication credential.

2 . The computer-implemented method of claim 1 , further comprising:

transmitting, to the client device, confirmation of successful transfer of the enrollment from the first client device to the client device.

3 . The computer-implemented method of claim 1 , further comprising:

receiving, from the authentication system, a second request for presence verification of the user; and

transmitting, to the authentication system, presence information verifying the presence of the user, wherein the associating the authentication enrollment information with the authentication credential is based at least in part of the presence information.

4 . The computer-implemented method of claim 1 , wherein the request is transmitted to the authentication system via a user interface associated with the authentication system.

5 . The computer-implemented method of claim 1 , wherein the request comprises an enrollment transfer request.

6 . The computer-implemented method of claim 1 , wherein the first authentication credential is securely stored on the first client device and the authentication credential is securely stored on the client device.

7 . The computer-implemented method of claim 6 , wherein the first authentication credential is stored on the first client device using a first trusted platform module (TPM) of the first client device and the authentication credential is stored on the client device using a trusted platform module (TPM) of the client device.

8 . The computer-implemented method of claim 1 , wherein associating the authentication credential with the authentication enrollment information comprises replacing the first authentication credential with the authentication credential.

9 . The computer-implemented method of claim 1 , further comprising:

removing the first authentication credential from secure storage on the first client device in response to the confirmation.

10 . The computer-implemented method of claim 1 , wherein the first authentication credential corresponds to a first multi-factor authentication (MFA) certificate of the first client device and the authentication credential corresponds to an MFA certificate of the client device.

11 . A computer-implemented method performed by a client device associated with a user of an authentication system, the method comprising:

transmitting, to a first client device associated with the user, a first request for authorization of an enrollment transfer from the first client device to the client device;

receiving, from the first client device, authentication enrollment information for the user with the authentication system, wherein the authentication enrollment information indicates the authorization of the enrollment transfer;

generating an authentication credential for the client device to authenticate with the authentication system;

transmitting, to the first client device, information corresponding to the authentication credential; and

receiving, from the first client device, confirmation of successful transfer of enrollment from the first client device to the client device, wherein the enrollment of the client device includes associating the authentication enrollment information for the user with at least the authentication credential.

12 . The computer-implemented method of claim 11 , further comprising:

transmitting an access request to the authentication system;

receiving, from the authentication system, a request for an authentication factor for authenticating the access request;

generating, the authentication factor using the authentication credential; and

transmitting, to the authentication system, the generated authentication factor for authentication of the access request.

13 . The computer-implemented method of claim 11 , wherein the enrollment of the client device is based at least in part on a first authentication credential of the first client device that is associated with the authentication enrollment information of the user for authenticating access requests through the authentication system, and wherein the enrollment of the client device includes associating the authentication enrollment information for the user with at least the authentication credential.

14 . The computer-implemented method of claim 13 , wherein the first authentication credential is securely stored on the first client device and the authentication credential is securely stored on the client device.

15 . The computer-implemented method of claim 14 , wherein the authentication credential is stored on the client device using a trusted platform module (TPM) of the client device and the first authentication credential is stored on the first client device using a first trusted platform module (TPM) of the first client device.

16 . The computer-implemented method of claim 13 , wherein associating the authentication credential with the authentication enrollment information comprises replacing the first authentication credential with the authentication credential.

17 . The computer-implemented method of claim 13 , wherein the authentication credential corresponds to a multi-factor authentication (MFA) certificate of the client device and the first authentication credential corresponds to a first MFA certificate of the first client device.

18 . A non-transitory computer-readable storage medium comprising executable instructions that when executed by a computer processor cause the computer processor to perform actions comprising:

receiving, from a client device associated with a user of an authentication system, a first request for an authorization of an enrollment transfer from a first client device to a client device;

transmitting, to the client device, an indication of the authorization of the enrollment transfer;

receiving, from the client device associated with the user, information corresponding to an authentication credential for the client device based at least in part on the authorization of the enrollment transfer;

transmitting, to the authentication system, a request to enroll the client device in authentication services of the authentication system, wherein authorization of the request is based at least in part on a first authentication credential that is associated with authentication enrollment information of the user for authenticating access requests through the authentication system, and wherein the request includes the information corresponding to the authentication credential provided by the client device; and

receiving, from the authentication system, confirmation of enrollment of the client device, wherein the enrollment of the client device includes associating the authentication enrollment information for the user with at least the authentication credential.

19 . The non-transitory computer-readable storage medium of claim 18 , further comprising:

transmitting, to the client device, confirmation of successful transfer of the enrollment from the first client device to the client device.