IP Library › Granted Patent US 12,218,931
Granted Patent B2
US 12,218,931 · App. 17/168,301 · Granted Feb 4, 2025

Collaboration application integration for user-identity verification

Inventors: Thomas Szigeti (Vancouver, CA); Stefano Giorcelli (Valbonne, FR); Frank Michaud (Pully, CH); David John Zacks (Vancouver, CA)
Assignee: Cisco Technology, Inc.
H04L63/0861G06V40/172G06V40/70G10L17/22H04L63/0853H04L63/0876H04L63/18H04L2463/082
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,218,931
App. No.
17/168,301
Granted
Feb 4, 2025
Kind
B2
Abstract

Disclosed are methods, systems, and non-transitory computer-readable media for utilizes a collaboration application to provide data beneficial to the authentication of the user. The present application discloses receiving at least one item of personal identifying information for a user from a primary multi-factor authentication device. The present application further discloses receiving at least one item of personal identifying information for a user from a conferencing service in which the user is engaged in a conference. The present application also discloses determining whether to authenticate the user based on the items of personal identifying information from the primary multi-factor authentication device and from the conferencing service.

Claims (45)

1. A method comprising:

receiving a first item of personal identifying information for a user from a primary multi-factor authentication device;

determining that the first item of personal identifying information is insufficient to authenticate the user of the primary multi-factor authentication device due to a low confidence score associated with facial feature information;

based on the first item of personal identifying information being insufficient to authenticate the user, determining that a second service independent of the primary multi-factor authentication device is able to supply a second item of personal identifying information with a higher confidence score associated with the facial feature information than the primary multi-factor authentication device, wherein the second service is a conferencing service;

receiving the second item of personal identifying information for a user from the conferencing service in which the user is engaged in a conference; and

authenticating the user based on the second item of personal identifying information from the conferencing service rather than from the primary multi-factor authentication device.

2. The method of claim 1 , wherein the second service is executing on a series of devices within a conference room during the conferencing service.

3. The method of claim 1 , wherein determining that the confidence score is insufficient to authenticate the user comprises:

determining that the user is not looking at the primary multi-factor authentication device based on video captured by the second service.

4. The method of claim 1 , wherein determining that the second service is able to supply a second item of personal identifying information comprises:

determining that the user is attending a meeting based on calendar information or presence tool information; and

obtaining the second item of personal identifying information from the conferencing service based on the step of determining that the user is attending the meeting.

5. The method of claim 1 , wherein the second item of personal identifying information received from the conferencing service includes receiving an identification of the user and a confidence score indicating a confidence in the identification.

6. The method of claim 5 , wherein the identification of the user is a user name, a user account, or another user identifier.

7. The method of claim 5 , wherein the identification is transmitted via a secure API over a network.

8. The method of claim 5 , wherein the identification is performed by a server of the conferencing service and transmitted to an endpoint used to access the conferencing service, wherein the endpoint can transmit the identification to the primary multi-factor authentication device.

9. The method of claim 8 , wherein transmission of the identification by the endpoint to the primary multi-factor authentication device is done via a Bluetooth or ultrasonic connection.

10. The method of claim 1 , wherein the second item of personal identifying information from the conferencing service includes three streams of data, wherein each stream is labeled by a common flow ID, wherein:

a first stream of data includes data about a video stream and includes a quality score that represents a confidence score for facial recognition of the user;

a second stream of data includes data about an audio stream and includes a quality score that represents a confidence score for a voice recognition for the user;

a third stream of data includes a quality score that represents a confidence score indicating that behavior of the user in using the conferencing service is consistent with a pattern of past behavior by the user; and

wherein an identity of the user is extracted from correlating an IP address, MAC address, and user ID from data in the three streams of data.

11. The method of claim 10 , wherein the confidence score that the behavior of the user in using the conferencing service is consistent with the pattern of past behavior by the user includes factors such as how the user uses the conferencing service, how many meetings the user has during a day, and who is in the meetings with the user.

12. The method of claim 1 , wherein the conferencing service is associated with a score indicating a quality of data coming from the conferencing service, wherein the score is used to weigh the data when determining whether to authenticate the user.

13. The method of claim 1 , wherein the conferencing service reports a precise location of the user based on a known location of a conferencing endpoint which transmits the second item of personal identifying information.

14. A system comprising:

one or more processors; and

at least one non-transitory computer-readable medium having stored therein instructions which, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

receiving a first item of personal identifying information for a user from a primary multi-factor authentication device;

determining that the first item of personal identifying information is insufficient to authenticate the user of the primary multi-factor authentication device due to a low confidence score associated with facial feature information;

based on the first item of personal identifying information being insufficient to authenticate the user, determining that a second service independent of the primary multi-factor authentication device is able to supply a second item of personal identifying information with a higher confidence score associated with the facial feature information than the primary multi-factor authentication device, wherein the second service is a conferencing service;

receiving the second item of personal identifying information for a user from the conferencing service in which the user is engaged in a conference; and

authenticating the user based on the second item of personal identifying information from the conferencing service rather than from the primary multi-factor authentication device.

15. The system of claim 14 , wherein the determining that the second service is able to supply the second item of personal identifying information comprises:

determining that the user is attending a meeting based on calendar information or presence tool information; and

obtaining the second item of personal identifying information from the conferencing service based on the step of determining that the user is attending the meeting.

16. A non-transitory computer-readable medium having stored therein instructions which, when executed by a processor, cause the processor to perform operations comprising:

receiving a first item of personal identifying information for a user from a primary multi-factor authentication device;

determining that the first item of personal identifying information is insufficient to authenticate the user of the primary multi-factor authentication device due to a low confidence score associated with facial feature information;

based on the first item of personal identifying information being insufficient to authenticate the user, determining that a second service independent of the primary multi-factor authentication device is able to supply a second item of personal identifying information with a higher confidence score associated with the facial feature information than the primary multi-factor authentication device, wherein the second service is a conferencing service;

receiving the second item of personal identifying information for a user from the conferencing service in which the user is engaged in a conference; and

authenticating the user based on the second item of personal identifying information from the conferencing service rather than from the primary multi-factor authentication device.

17. The non-transitory computer-readable medium of claim 16 , wherein the determining that the second service is able to supply the second item of personal identifying information comprises:

determining that the user is attending a meeting based on calendar information or presence tool information; and

obtaining the second item of personal identifying information from the conferencing service based on the step of determining that the user is attending the meeting.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 5, 2021
From: SZIGETI, THOMAS; GIORCELLI, STEFANO; MICHAUD, FRANK; ZACKS, DAVID JOHN
To: CISCO TECHNOLOGY, INC.
Reel/Frame 055158/0599 →
Continuity (1)
Related Publication 20220255923A1 · Aug 11, 2022
References Cited (19)
US 10027662B1 · Mutagi · 2018 [cited by examiner]
US 10681547B1 · Yang · 2020 [cited by examiner]
US 11341222B1 · Caffey · 2022 [cited by examiner]
US 20110035788A1 · White · 2011 [cited by examiner]
US 20130305337A1 · Newman et al. · 2013 [cited by applicant]
US 20140109210A1 · Borzycki · 2014 [cited by examiner]
US 20140123275A1 · Azar · 2014 [cited by examiner]
US 20150365522A1 · Anderson et al. · 2015 [cited by applicant]
US 20200272716A1 · Hassan et al. · 2020 [cited by applicant]
US 20200342084A1 · Zhao · 2020 [cited by applicant]
US 20200401791A1 · Gao · 2020 [cited by examiner]
US 20210176235A1 · Keith, Jr. · 2021 [cited by examiner]
US 20210288829A1 · Zhang · 2021 [cited by examiner]
US 20220232004A1 · Soman · 2022 [cited by examiner]
WO WO2009055228A2 · 2009 [cited by examiner]
A-Fairuz et al., “Multi-channel, Multi-level Authentication for More Secure eBanking”, Information Security South Africa Conference 2010, Sandton Convention Centre, Sandton, South Africa, Aug. 2-4, 2010. Proceedings ISS… [cited by examiner]
Al-Fairuz et al, “Multi-channel, Multi-level Authentication for More Secure eBanking”, Published in Information Security South Africa Conference, Sandton Convention Center, Proceedings ISSA 2010 (Year: 2010). [cited by examiner]
Al-Assam et al, “On security of multi-factor biometric authentication,” 2010 International Conference for Internet Technology and Secured Transactions, London, UK, 2010, pp. 1-6. (Year: 2010). [cited by examiner]
Abbadi, “Multi-Factor Authentication Techniques for Video Applications Over The Untrusted Internet,” University of Ottawa, 2012, pp. 1-142. [cited by applicant]