IP Library Granted Patent US 10,367,813
Granted Patent B2
US 10,367,813 · App. 15/281,905 · Granted Jul 30, 2019

Distributed authentication with thresholds in IoT devices

Inventors: Glen J. Anderson (Beaverton, OR); John Teddy (Beaverton, OR); Chakradhar Kotamraju (Beaverton, OR)
Assignee: McAfee, LLC
H04L63/0884H04L63/062H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,367,813
App. No.
15/281,905
Granted
Jul 30, 2019
Kind
B2
Abstract

Managing authentication of a child device includes receiving, by a host device, sensor data from a child device, deriving simplified authentication data from the sensor data based on a capability of the child device, storing the simplified authentication data in an authentication profile for the child device, and transmitting the simplified authentication data to the child device, wherein the simplified authentication data is sufficient to allow the child device to authenticate a user without the host device.

Claims (78)

1. A non-transitory computer readable medium comprising instructions which, when executed, cause at least one host device processor to at least:

determine a processing resource of a child device operably coupled to the at least one host device processor;

derive simplified authentication data from sensor data from the child device, the simplified authentication data able to be processed by the processing resource of the child device to authenticate a user of the child device without analysis of the sensor data by the at least one host device processor;

store the simplified authentication data in an authentication profile for the child device; and

transmit the simplified authentication data to the child device, wherein the simplified authentication data is to allow the child device to authenticate the user without the at least one host device processor,

wherein the simplified authentication data stored in the authentication profile for the child device is to be updated by the at least one host device processor based on a change in the sensor data, the updated simplified authentication data to be provided to the child device to authenticate the user.

2. The computer readable medium of claim 1 , wherein the instructions, when executed, cause the at least one host device processor to derive the simplified authentication data by determining threshold values corresponding to the sensor data within which the user is to be authenticated.

3. The computer readable medium of claim 2 , wherein the instructions, when executed, cause the at least one host device processor to derive simplified authentication data by at least:

determining the threshold values for the sensor data based on the resource of the child device.

4. The computer readable medium of claim 2 , wherein the instructions, when executed, further cause the at least one host device processor to:

receive historic sensor data from the child device;

determine that the threshold values are to be modified based on the historic sensor data;

modify the simplified authentication data based on the historic sensor data; and

transmit the modified simplified authentication data to the child device.

5. The computer readable medium of claim 1 , wherein the sensor data is to be obtained from a plurality of sensors of the child device, and wherein the simplified authentication data includes weighted values for sensor data from each of the plurality of sensors.

6. The computer readable medium of claim 1 , wherein the instructions, when executed, further cause the at least one host device processor to:

receive an indication from the child device that additional sensor data does not conform to the simplified authentication data; and

disable the child device.

7. The computer readable medium of claim 6 , wherein disabling the child device includes:

performing an analysis of the additional sensor data to determine whether the additional sensor data conforms to the authentication profile for the child device, and

disabling the child device in response to determining that the additional sensor data does not conform to the authentication profile for the child device.

8. A system for managing authentication of a child device, the system comprising:

one or more processors; and

a memory coupled to the one or more processors and including instructions which, when executed by the one or more processors, cause the one or more processors to at least:

determine a processing resource of a child device;

derive simplified authentication data from sensor data received from the child device, the simplified authentication data able to be processed by the processing resource of the child device to authenticate a user of the child device without analysis of the sensor data by the one or more processors;

store the simplified authentication data in an authentication profile for the child device; and

transmit the simplified authentication data to the child device, wherein the simplified authentication data is to allow the child device to authenticate the user without the one or more processors,

wherein the simplified authentication data stored in the authentication profile for the child device is to be updated by the one or more processors based on a change in the sensor data, the updated simplified authentication data to be provided to the child device to authenticate the user.

9. The system of claim 8 , wherein the instructions, when executed, cause the one or more processors to derive the simplified authentication data by determining threshold values corresponding to the sensor data within which the user is to be authenticated.

10. The system of claim 9 , wherein the instructions, when executed, cause the one or more processors to derive simplified authentication data by:

determining the threshold values for the sensor data based on the resource of the child device.

11. The system of claim 9 , wherein the instructions, when executed, further cause the one or more processors to:

receive historic sensor data from the child device;

determine that the threshold values are to be modified based on the historic sensor data;

modify the simplified authentication data based on the historic sensor data; and

transmit the modified simplified authentication data to the child device.

12. The system of claim 8 , wherein the sensor data is to be obtained from a plurality of sensors of the child device, and wherein the simplified authentication data includes weighted values for sensor data from each of the plurality of sensors.

13. The system of claim 8 , wherein the instructions, when executed, further cause the one or more processors to:

receive an indication from the child device that additional sensor data does not conform to the simplified authentication data; and

disable the child device.

14. A method for managing authentication of a child device by a parent device, comprising:

determining a processing resource of a child device;

deriving simplified authentication data from sensor data received from the child device, the simplified authentication data able to be processed by the processing resource of the child device to authenticate a user of the child device without analysis of the sensor data by the parent device;

storing the simplified authentication data in an authentication profile for the child device; and

transmitting the simplified authentication data to the child device, wherein the simplified authentication data is to allow the child device to authenticate the user without the parent device,

wherein the simplified authentication data stored in the authentication profile for the child device is to be updated by the parent device based on a change in the sensor data, the updated simplified authentication data to be provided to the child device to authenticate the user.

15. The method of claim 14 , wherein deriving the simplified authentication data includes determining threshold values corresponding to the sensor data within which the user is to be authenticated.

16. The method of claim 15 , wherein deriving simplified authentication data includes:

determining the threshold values for the sensor data based on the resource of the child device.

17. The method of claim 15 , further including:

receiving historic sensor data from the child device;

determining that the threshold values are to be modified based on the historic sensor data;

modifying the simplified authentication data based on the historic sensor data; and

transmitting the modified simplified authentication data to the child device.

18. The method of claim 14 , wherein the sensor data is obtained from a plurality of sensors of the child device, and wherein the simplified authentication data includes weighted values for sensor data from each of the plurality of sensors.

19. The method of claim 14 , further including:

receiving an indication from the child device that additional sensor data does not conform to the simplified authentication data;

performing an analysis of the additional sensor data to determine whether the additional sensor data conforms to the authentication profile for the child device, and

disabling the child device in response to determining that the additional sensor data does not conform to the authentication profile for the child device.

20. A non-transitory computer readable medium comprising instructions which, when executed, cause at least one local device processor of a local device to at least:

obtain sensor data from one or more sensors;

transmit the sensor data to a host device for authentication analysis;

receive, from the host device, simplified authentication data based on the sensor data and a processing resource of the local device, the simplified authentication data able to be processed by the processing resource of the local device to authenticate a user of the local device without analysis of the sensor data by the host device; and

authenticate the local device based on the simplified authentication data,

wherein the simplified authentication data is to be updated by the host device based on a change in the sensor data, the updated simplified authentication data to be provided to the local device to authenticate the user.

21. The computer readable medium of claim 20 , wherein the instructions, when executed, further cause the at least one local device processor to:

determining that current sensor data does not conform to the simplified authentication data; and

in response to determining that the current sensor data does not conform to the simplified authentication data, disabling the local device.

22. The computer readable medium of claim 20 , wherein the instructions, when executed, further cause the at least one local device processor to:

transmit the current sensor data to the host device for further analysis; and

authenticate the user based on the further analysis.

23. The computer readable medium of claim 20 , wherein the simplified authentication data includes threshold values corresponding to the sensor data.

24. The computer readable medium of claim 20 , wherein the simplified authentication data includes weighted values for sensor data from each of the plurality of sensors.

25. The computer readable medium of claim 20 , wherein the instructions, when executed, further cause the at least one local device processor to:

transmit additional sensor data to the host device for further analysis, and

receive updated simplified authentication data based on the additional sensor data.

26. The computer readable medium of claim 1 , wherein the child device includes an Internet of Things device, and wherein the simplified authentication data includes at least one of an image, a movement, or a sound.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Sep 15, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043969/0057 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 17, 2016
From: ANDERSON, GLEN J.; TEDDY, JOHN; KOTAMRAJU, CHAKRADHAR
To: MCAFEE, INC.
Reel/Frame 040033/0847 →
Continuity (1)
Related Publication 20180097808A1 · Apr 5, 2018