IP Library › Granted Patent US 12,309,582
Granted Patent B2
US 12,309,582 · App. 18/052,013 · Granted May 20, 2025

Multi-factor authentication for IoT devices

Inventors: Rajesh Indira Viswambharan (Karnataka, IN); Ram Mohan Ravindranath (Karnataka, IN); Prashanth Patil (San Jose, CA)
Assignee: Cisco Technology, Inc.
H04W12/06H04L63/20H04W12/63H04L2463/082
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,309,582
App. No.
18/052,013
Granted
May 20, 2025
Kind
B2
Abstract

Disclosed herein are systems, methods, and computer-readable media for enabling multi-factor authentication (MFA) for an Internet Of Things (IoT) device. In one aspect, a method includes receiving a network connection request from the IoT device to connect to a network. In one aspect, the method includes fetching authentication information for the device in response to the request. In one aspect, the method includes authenticating the device to the network. In one aspect, the method includes in response to the authentication of the device to the network, establishing a network connection between the IoT device and the network. In one aspect, the method includes applying the MFA policy. In one aspect, the method includes after successful compliance with the MFA policy establishing a session between the device and the application over the network.

Claims (46)

1. A method for enabling multi-factor authentication (MFA) for an Internet Of Things (IoT) device, the method comprising:

receiving a network connection request from the IoT device to connect to a network;

fetching authentication information for the IoT device in response to the request,

wherein the authentication information includes subscription credentials to authenticate the IoT device to the network, and an MFA policy that defines a user or location restriction to authentication of the IoT device to an application accessed over the network;

authenticating the device to the network;

in response to the authentication of the device to the network, establishing a network connection between the IoT device and the network;

after the device is authenticated and the network connection is established between the IoT device and network, determining if a location restriction is satisfied;

in response to the location restriction being satisfied, applying the MFA policy; and

after successful compliance with the MFA policy establishing a session between the IoT device and the application over the network.

2. The method of claim 1 , wherein the network is a cellular network that utilizes an authentication and key management for applications (AKMA) to authenticate the IoT device to the cellular network.

3. The method of claim 2 , wherein the network is a 4 G network, a LTE network, a 5 G network.

4. The method of claim 1 , wherein the MFA policy defines an activation period, wherein the activation period determines whether the MFA policy is applied when authenticating the IoT device to the network, or when the IoT device attempts to connect to the application.

5. The method of claim 4 , further comprising:

when the activation period defined by the MFA policy is a delayed activation policy that requires that the MFA policies should be applied with the IoT device attempts to establish the session with the application; and

determining that the IoT device has requested to establish the session with the application before the MFA policy is applied.

6. The method of claim 1 , wherein the MFA policy defines a time parameter, the method further comprising: determining that the time parameter is satisfied before the MFA policy is applied.

7. The method of claim 1 , wherein the MFA policy defines the user restriction, wherein the user restriction defines at least one user to provide the MFA.

8. The method of claim 7 , wherein the user restriction defines a first user to provide the MFA at a first time or a first location, and a second user to provide the MFA at a second time or a second location.

9. The method of claim 1 , wherein the application is a plurality of applications, and the MFA policy defines a first MFA procedure for a first application of the plurality of applications, and a second MFA procedure for a second application of the plurality of applications.

10. The method of claim 1 , further comprising:

enforcing the MFA policy upon successful MFA authentication and providing an application key and an expiration time for the application key to an application function associated with the application of the IoT device.

11. The method of claim 1 , wherein the MFA policy defines a single sign-on policy, wherein the MFA policy requires a single MFA to permit the IoT device to establish sessions with multiple applications.

12. A device for enabling multi-factor authentication (MFA) for an Internet Of Things (IoT) device comprising:

a processor; and a memory storing instructions that, when executed by the processor, configure the device to:

receive a network connection request from the IoT device to connect to a network;

fetch authentication information for the IoT device in response to the request, wherein the authentication information includes subscription credentials to authenticate the IoT device to the network, and a MFA policy that defines a user or location restriction to authentication of the IoT device to an application accessed over the network;

authenticate the device to the network;

in response to the authentication of the device to the network, establish a network connection between the IoT device and the network;

in response to the location restriction being satisfied, after the device is authenticated and the network connection is established between the IoT device and network, determining if a location restriction is satisfied;

in response to the location restriction being satisfied, apply the MFA policy; and

after successful compliance with the MFA policy establish a session between the IoT device and the application over the network.

13. The device of claim 12 , wherein the network is a cellular network that utilizes an authentication and key management for applications (AKMA) to authenticate the IoT device to the cellular network.

14. The device of claim 12 , wherein the MFA policy defines an activation period, wherein the activation period determines whether the MFA policy is applied when authenticate the device to the network, or when the IoT device attempts to connect to the application.

15. The device of claim 12 , wherein the MFA policy defines a time parameter, the IoT device further configured to:

determine that the time parameter is satisfied before the MFA policy is applied.

16. The device of claim 12 , wherein the application is a plurality of applications, and the MFA policy defines a first MFA procedure for a first application of the plurality of applications, and a second MFA procedure for a second application of the plurality of applications.

17. The device of claim 12 , wherein the instructions further configure the device to:

enforce the MFA policy upon successful MFA authentication and providing an application key and an expiration time for the application key to an application function associated with the application of the IoT device.

18. A non-transitory computer-readable storage medium, the computer-readable storage medium including instructions that when executed by a computer, cause the computer to:

receive a network connection request from an IoT device to connect to a network;

fetch authentication information for the IoT device in response to the request, wherein the authentication information includes subscription credentials to authenticate the IoT device to the network, and a MFA policy that defines a user or location restriction to authentication of the IoT device to an application accessed over the network;

authenticate the device to the network;

in response to the authentication of the device to the network, establish a network connection between the IoT device and the network;

after the device is authenticated and the network connection is established between the IoT device and network, determining if a location restriction is satisfied;

in response to the location restriction being satisfied, apply the MFA policy; and

after successful compliance with the MFA policy establish a session between the IoT device and the application over the network.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 2, 2022
From: VISWAMBHARAN, RAJESH INDIRA; RAVINDRANATH, RAM MOHAN; PATIL, PRASHANTH
To: CISCO TECHNOLOGY, INC.
Reel/Frame 061632/0688 →
Continuity (1)
Related Publication 20240147232A1 · May 2, 2024
References Cited (9)
US 20180234461A1 · Mahaffey · 2018 [cited by examiner]
US 20210112411A1 · Pazhyannur et al. · 2021 [cited by applicant]
US 20210153016A1 · Ben Henda et al. · 2021 [cited by applicant]
US 20210185529A1 · Patil · 2021 [cited by examiner]
US 20220116774A1 · Rajadurai · 2022 [cited by examiner]
US 20220191251A1 · Gavish · 2022 [cited by examiner]
US 20220210636A1 · Gupta et al. · 2022 [cited by applicant]
US 20230247003A1 · Chanak · 2023 [cited by examiner]
Emin Huseynov, “Context-Aware Multifactor Authentication for the Augmented Human,” May 12, 2020, pp. 1-126. [cited by applicant]