IP Library Granted Patent US 12,489,748
Granted Patent B2
US 12,489,748 · App. 18/065,002 · Granted Dec 2, 2025

Device to device binding for push approval

Inventors: Omar Naji Abduljaber (Ypsilanti, MI); Michael G. Brown (Portland, OR); Mujtaba Hussain (Canton, MI); Robert Jacob Linial Small (Ann Arbor, MI); Bradley A. Kuykendall (Colorado Springs, CO)
Assignee: CISCO TECHNOLOGY, INC.
H04L63/0853
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,489,748
App. No.
18/065,002
Granted
Dec 2, 2025
Kind
B2
Abstract

In one embodiment, a method, by an authentication server, includes receiving user information associated with a first authentication factor for verification from the first endpoint device. The method further includes in response to verifying the first authentication factor, transmitting a prompt to provide an authentication decision associated with a second authentication factor to the second endpoint device, wherein the second endpoint device is communicatively coupled to the first endpoint device through the communication link. The method further includes receiving the authentication decision that is initiated by the first endpoint device from the second endpoint device, wherein the first endpoint device is configured to initiate and transmit the authentication decision to the second endpoint device in response to receiving the second authentication factor from the second endpoint device.

Claims (66)

1 . An authentication server, comprising:

one or more processors; and

one or more computer-readable non-transitory storage media comprising instructions that, when executed by the one or more processors, cause one or more components of the authentication server to perform operations comprising:

receiving user information associated with a first authentication factor for verification from a first endpoint device;

in response to verifying the first authentication factor, transmitting a prompt to provide an authentication decision associated with a second authentication factor to a second endpoint device, wherein:

the second endpoint device is communicatively coupled to the first endpoint device through a communication link,

the second endpoint device is registered to communicate with the authentication server and the first endpoint device is not,

the first endpoint device and the second endpoint device are associated with a user,

a first instance of an authentication application is installed on the first endpoint device to facilitate communication with the authentication server; and

a second instance of the authentication application is installed on the second endpoint device to facilitate communication with the authentication server; and

receiving the authentication decision that is initiated by the first endpoint device from the second endpoint device, wherein the first endpoint device is configured to initiate and transmit the authentication decision to the second endpoint device in response to receiving the second authentication factor from the second endpoint device.

2 . The authentication server of claim 1 , the operations further comprising:

starting a timer for a determined period of time in response to verifying the first authentication factor.

3 . The authentication server of claim 2 , the operations further comprising:

if the authentication decision is received after the determined period of time has expired, denying the first endpoint device access to a resource.

4 . The authentication server of claim 2 , the operations further comprising:

permitting the first endpoint device access to a resource in response to a determination that the authentication decision was received within the determined period of time.

5 . The authentication server of claim 1 , the operations further comprising:

instructing the second endpoint device to forward the transmitted prompt as a push notification to the first endpoint device.

6 . The authentication server of claim 1 , the operations further comprising:

determining that the first endpoint device has requested to access a resource; and

performing a first multi-factor authentication procedure by authenticating the first authentication factor, wherein authentication of the first authentication factor is based on verifying a login credential of the user with the received user information.

7 . The authentication server of claim 6 , the operations further comprising:

permitting the first endpoint device to access the resource based on determining that the first endpoint device successfully completed a second multi-factor authentication procedure.

8 . A method to authenticate a first endpoint device through a communication link with a second endpoint device, comprising:

receiving user information associated with a first authentication factor for verification from the first endpoint device;

in response to verifying the first authentication factor, transmitting a prompt to provide an authentication decision associated with a second authentication factor to the second endpoint device, wherein:

the second endpoint device is communicatively coupled to the first endpoint device through the communication link,

the second endpoint device is registered to communicate with an authentication server and the first endpoint device is not,

the first endpoint device and the second endpoint device are associated with a user,

a first instance of an authentication application is installed on the first endpoint device to facilitate communication with the authentication server; and

a second instance of the authentication application is installed on the second endpoint device to facilitate communication with the authentication server; and

receiving the authentication decision that is initiated by the first endpoint device from the second endpoint device, wherein the first endpoint device is configured to initiate and transmit the authentication decision to the second endpoint device in response to receiving the second authentication factor from the second endpoint device.

9 . The method of claim 8 , further comprising:

starting a timer for a determined period of time in response to verifying the first authentication factor.

10 . The method of claim 9 , further comprising if the authentication decision is received after the determined period of time has expired, denying the first endpoint device access to a resource.

11 . The method of claim 9 , further comprising:

permitting the first endpoint device access to a resource in response to a determination that the authentication decision was received within the determined period of time.

12 . The method of claim 8 , further comprising:

instructing the second endpoint device to forward the transmitted prompt as a push notification to the first endpoint device.

13 . The method of claim 8 , further comprising:

determining that the first endpoint device has requested to access a resource; and

performing a first multi-factor authentication procedure by authenticating the first authentication factor, wherein authentication of the first authentication factor is based on verifying a login credential of the user with the received user information.

14 . The method of claim 13 , further comprising:

permitting the first endpoint device to access the resource based on determining that the first endpoint device successfully completed a second multi-factor authentication procedure.

15 . A non-transitory computer-readable medium comprising instructions that are configured, when executed by a processor, to:

receive user information associated with a first authentication factor for verification from a first endpoint device;

in response to verifying the first authentication factor, transmit a prompt to provide an authentication decision associated with a second authentication factor to a second endpoint device, wherein:

the second endpoint device is communicatively coupled to the first endpoint device through a communication link,

the second endpoint device is registered to communicate with an authentication server and the first endpoint device is not,

the first endpoint device and the second endpoint device are associated with a user,

a first instance of an authentication application is installed on the first endpoint device to facilitate communication with the authentication server; and

a second instance of the authentication application is installed on the second endpoint device to facilitate communication with the authentication server; and

receive the authentication decision that is initiated by the first endpoint device from the second endpoint device, wherein the first endpoint device is configured to initiate and transmit the authentication decision to the second endpoint device in response to receiving the second authentication factor from the second endpoint device.

16 . The non-transitory computer-readable medium of claim 15 , wherein the instructions are further configured to:

start a timer for a determined period of time in response to verifying the first authentication factor.

17 . The non-transitory computer-readable medium of claim 16 , wherein the instructions are further configured to:

if the authentication decision is received after the determined period of time has expired, deny the first endpoint device access to a resource.

18 . The non-transitory computer-readable medium of claim 16 , wherein the instructions are further configured to:

permit the first endpoint device access to a resource in response to a determination that the authentication decision was received within the determined period of time.

19 . The non-transitory computer-readable medium of claim 15 , wherein the instructions are further configured to:

instruct the second endpoint device to forward the transmitted prompt as a push notification to the first endpoint device.

20 . The non-transitory computer-readable medium of claim 15 , wherein the instructions are further configured to:

determine that the first endpoint device has requested to access a resource;

perform a first multi-factor authentication procedure by authenticating the first authentication factor, wherein authentication of the first authentication factor is based on verifying a login credential of the user with the received user information; and

permit the first endpoint device to access the resource based on determining that the first endpoint device successfully completed a second multi-factor authentication procedure.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 13, 2022
From: ABDULJABER, OMAR; BROWN, MICHAEL G.; HUSSAIN, MUJTABA; SMALL, ROBERT JACOB LINIAL; KUYKENDALL, BRADLEY
To: CISCO TECHNOLOGY, INC.
Reel/Frame 062065/0224 →
Continuity (1)
Related Publication 20240195804A1 · Jun 13, 2024
References Cited (21)
US 10122719B1 · Vltavsky et al. · 2018 [cited by applicant]
US 20020169988A1 · Vandergeest et al. · 2002 [cited by applicant]
US 20140189840A1 · Metke et al. · 2014 [cited by applicant]
US 20160241605A1 · Taboriskiy et al. · 2016 [cited by applicant]
US 20170359342A1 · Magyar et al. · 2017 [cited by applicant]
US 20180097901A1 · Ramachandra · 2018 [cited by applicant]
US 20190188368A1 · Hastings · 2019 [cited by applicant]
US 20190372959A1 · Pattar · 2019 [cited by examiner]
US 20210176229A1 · Xuan · 2021 [cited by examiner]
US 20210194883A1 · Badhwar · 2021 [cited by examiner]
US 20220070156A1 · Thubert · 2022 [cited by examiner]
US 20220092162A1 · Keith, Jr. · 2022 [cited by examiner]
US 20220116392A1 · Shah · 2022 [cited by examiner]
US 20220166763A1 · Hong · 2022 [cited by examiner]
US 20220247789A1 · Itoi · 2022 [cited by examiner]
US 20220417240A1 · Zhang · 2022 [cited by examiner]
US 20230119797A1 · Fabjanski · 2023 [cited by examiner]
US 20230216850A1 · Pasirstein · 2023 [cited by examiner]
US 20230245082A1 · Venu · 2023 [cited by examiner]
Anonymous: “Duo Universal Prompt—Guide to Two-Factor Authentication”, Duo Security, Oct. 17, 2022, pp. 1-50, XP093137704, Retrieved from https://web.archive.org/web/20221017100201/https://guide.duo.com/universal-prompt … [cited by applicant]
International Search Report and Written Opinion for International Application No. PCT/US2023/081997, mailed Mar. 20, 2024, 16 Pages. [cited by applicant]