IP Library Granted Patent US 12,470,543
Granted Patent B2
US 12,470,543 · App. 18/065,040 · Granted Nov 11, 2025

Trusted mobile endpoints using webview

Inventors: Harold Todd Chapman (Howell, MI); Robert Jacob Linial Small (Ann Arbor, MI); Michael G. Brown (Portland, OR); Adam Vincent Patruno (Canton, MI); Dylan Miles Kite (Ann Arbor, MI); Zachary Oliver Weglarz (Ann Arbor, MI); Erdenebat Gantumur (Ann Arbor, MI)
Assignee: CISCO TECHNOLOGY, INC.
H04L63/083G06Q20/3821G06Q20/40
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,470,543
App. No.
18/065,040
Granted
Nov 11, 2025
Kind
B2
Abstract

In one embodiment, a method, by an authentication server, includes generating a transaction identifier associated with an authentication request received from an external device. In response to verifying a first authentication factor of the authentication request, the method includes transmitting a prompt and the transaction identifier to the external device, wherein the prompt is an HTTP link associated with a browser comprising a generated cookie, the generated cookie being associated with the transaction identifier. The method includes receiving a signal comprising a transmitted transaction identifier and an instruction to process the HTTP link. The method includes instructing an application installed on the external device to open the browser in a webview in response to processing the instruction, wherein a cookie is provided. The method includes identifying the generated cookie based on verifying the transmitted transaction identifier. The method includes determining if the cookie is equivalent to the generated cookie.

Claims (56)

1 . An authentication server, comprising:

one or more processors; and

one or more computer-readable non-transitory storage media comprising instructions that, when executed by the one or more processors, cause one or more components of the authentication server to perform operations comprising:

generating a transaction identifier associated with an authentication request received from an external device, wherein the authentication request is part of a multi-factor authentication procedure;

in response to verifying a first authentication factor of the authentication request, transmitting a prompt and the transaction identifier to the external device, wherein the prompt is an HTTP link associated with a browser comprising a generated cookie that is generated at the authentication server and wherein the generated cookie comprises a random value corresponding to the transaction identifier;

receiving a signal comprising the transaction identifier and an instruction to process the HTTP link;

instructing an instance of an application installed on the external device to open the browser in a webview in response to processing the instruction, wherein a cookie is stored in the browser;

identifying the generated cookie based on verifying the transaction identifier;

determining if the cookie is equivalent to the generated cookie; and

in response to determining that the cookie is not equivalent to the generated cookie, determining that the prompt and the transaction identifier transmitted to the external device was subsequently forwarded by the external device to a trusted endpoint device, wherein the trusted endpoint device is associated with a user having previously established authentication with the authentication server, wherein the generated cookie was not transmitted to the trusted endpoint device when the external device forwarded the prompt and the transaction identifier to the trusted endpoint device.

2 . The authentication server of claim 1 , the operations further comprising:

performing a first multi-factor authentication procedure by authenticating the first authentication factor, wherein authentication of the first authentication factor is based on verifying a login credential of the user with the received authentication request.

3 . The authentication server of claim 1 , the operations further comprising:

denying access to a resource associated with the authentication request.

4 . The authentication server of claim 1 , the operations further comprising:

in response to determining that the cookie is equivalent to the generated cookie, determining that the received signal was transmitted by a trusted endpoint device; and

receiving an authentication decision associated with a second authentication factor from the trusted endpoint device via the prompt.

5 . The authentication server of claim 4 , the operations further comprising:

permitting the trusted endpoint device to access a resource associated with the authentication request based on determining that the trusted endpoint device successfully completed a second multi-factor authentication procedure.

6 . The authentication server of claim 1 , wherein the authentication request is a request to perform a multi-factor authentication procedure to verify the first authentication factor and a second authentication factor.

7 . A method to prevent second factor phishing, comprising:

generating a transaction identifier associated with an authentication request received from an external device, wherein the authentication request is part of a multi-factor authentication procedure;

in response to verifying a first authentication factor of the authentication request, transmitting a prompt and the transaction identifier to the external device, wherein the prompt is an HTTP link associated with a browser comprising a generated cookie that is generated at the authentication server, and wherein the generated cookie comprises a random value corresponding to the transaction identifier;

receiving a signal comprising the transaction identifier and an instruction to process the HTTP link;

instructing an instance of an application installed on the external device to open the browser in a webview in response to processing the instruction, wherein a cookie is stored in the browser;

identifying the generated cookie based on verifying the transaction identifier;

determining if the cookie is equivalent to the generated cookie; and

in response to determining that the cookie is not equivalent to the generated cookie, determining that the prompt and the transaction identifier transmitted to the external device was subsequently forwarded by the external device to a trusted endpoint device, wherein the trusted endpoint device is associated with a user having previously established authentication with an authentication server, wherein the generated cookie was not transmitted to the trusted endpoint device when the external device forwarded the prompt and the transaction identifier to the trusted endpoint device.

8 . The method of claim 7 , further comprising:

performing a first multi-factor authentication procedure by authenticating the first authentication factor, wherein authentication of the first authentication factor is based on verifying a login credential of the user with the received authentication request.

9 . The method of claim 7 , further comprising:

denying access to a resource associated with the authentication request.

10 . The method of claim 7 , further comprising:

in response to determining that the cookie is equivalent to the generated cookie, determining that the received signal was transmitted by a trusted endpoint device; and

receiving an authentication decision associated with a second authentication factor from the trusted endpoint device via the prompt.

11 . The method of claim 10 , further comprising:

permitting the trusted endpoint device to access a resource associated with the authentication request based on determining that the trusted endpoint device successfully completed a second multi-factor authentication procedure.

12 . The method of claim 7 , wherein the authentication request is a request to perform a multi-factor authentication procedure to verify the first authentication factor and a second authentication factor.

13 . A non-transitory computer-readable medium comprising instructions that are configured, when executed by a processor, to:

generate a transaction identifier associated with an authentication request received from an external device, wherein the authentication request is part of a multi-factor authentication procedure;

in response to verifying a first authentication factor of the authentication request, transmit a prompt and the transaction identifier to the external device, wherein the prompt is an HTTP link associated with a browser comprising a generated cookie that is generated at the authentication server, and wherein the generated cookie comprises a random value corresponding to the transaction identifier;

receive a signal comprising the transaction identifier and an instruction to process the HTTP link;

instruct an instance of an application installed on the external device to open the browser in a webview in response to processing the instruction, wherein a cookie is stored in the browser;

identify the generated cookie based on verifying the transaction identifier;

determine if the cookie is equivalent to the generated cookie; and

in response to determining that the cookie is not equivalent to the generated cookie, determining that the prompt and the transaction identifier transmitted to the external device was subsequently forwarded by the external device to a trusted endpoint device, wherein the trusted endpoint device is associated with a user having previously established authentication with an authentication server, wherein the generated cookie was not transmitted to the trusted endpoint device when the external device forwarded the prompt and the transaction identifier to the trusted endpoint device.

14 . The non-transitory computer-readable medium of claim 13 , wherein the instructions are further configured to:

perform a first multi-factor authentication procedure by authenticating the first authentication factor, wherein authentication of the first authentication factor is based on verifying a login credential of the user with the received authentication request.

15 . The non-transitory computer-readable medium of claim 13 , wherein the instructions are further configured to:

deny access to a resource associated with the authentication request.

16 . The non-transitory computer-readable medium of claim 13 , wherein the instructions are further configured to:

in response to determining that the cookie is equivalent to the generated cookie, determine that the received signal was transmitted by a trusted endpoint device; and

receive an authentication decision associated with a second authentication factor from the trusted endpoint device via the prompt.

17 . The non-transitory computer-readable medium of claim 16 , wherein the instructions are further configured to:

permit the trusted endpoint device to access a resource associated with the authentication request based on determining that the trusted endpoint device successfully completed a second multi-factor authentication procedure.

18 . The non-transitory computer-readable medium of claim 13 , wherein the authentication request is a request to perform a multi-factor authentication procedure to verify the first authentication factor and a second authentication factor.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 13, 2022
From: CHAPMAN, HAROLD TODD; SMALL, ROBERT JACOB LINIAL; BROWN, MICHAEL G.; PATRUNO, ADAM VINCENT; KITE, DYLAN MILES; WEGLARZ, ZACHARY OLIVER; GANTUMUR, ERDENEBAT
To: CISCO TECHNOLOGY, INC.
Reel/Frame 062066/0687 →
Continuity (1)
Related Publication 20240195798A1 · Jun 13, 2024
References Cited (26)
US 11233802B1 · Rudeanu · 2022 [cited by examiner]
US 11528140B2 · Tiffany · 2022 [cited by examiner]
US 20090006861A1 · Bemmel · 2009 [cited by examiner]
US 20110154488A1 · Rajan · 2011 [cited by examiner]
US 20120254935A1 · Yato · 2012 [cited by examiner]
US 20150052584A1 · Rudraraju · 2015 [cited by examiner]
US 20150222615A1 · Allain et al. · 2015 [cited by applicant]
US 20170279798A1 · Reynolds · 2017 [cited by examiner]
US 20180131686A1 · Brannon · 2018 [cited by applicant]
US 20180285552A1 · Oberheide et al. · 2018 [cited by applicant]
US 20180351936A1 · Battacharya · 2018 [cited by examiner]
US 20190253404A1 · Briceno et al. · 2019 [cited by applicant]
US 20190354709A1 · Brinskelle · 2019 [cited by examiner]
US 20210166226A1 · Wang · 2021 [cited by applicant]
US 20210258344A1 · Kula · 2021 [cited by examiner]
US 20220131854A1 · Joshi · 2022 [cited by examiner]
US 20220329579A1 · Grinman · 2022 [cited by applicant]
US 20220337590A1 · Jaiswal · 2022 [cited by examiner]
US 20220385656A1 · Gujarathi · 2022 [cited by examiner]
US 20230006844A1 · Cohen · 2023 [cited by examiner]
US 20230014970A1 · Gujarathi · 2023 [cited by examiner]
US 20240037279A1 · Marudi · 2024 [cited by examiner]
US 20240195798A1 · Chapman · 2024 [cited by examiner]
TW 201215062A · 2012 [cited by applicant]
“Duo Trusted Endpoints—Duo Mobile Verification,” © 2022 Duo, https://duo.com/docs/trusted-endpoints-duo-moble, Dec. 3, 2021. [cited by applicant]
International Search Report and Written Opinion for International Application No. PCT/US2023/082222, mailed Mar. 15, 2024, 12 Pages. [cited by applicant]