IP Library Granted Patent US 12,061,683
Granted Patent B2
US 12,061,683 · App. 18/317,760 · Granted Aug 13, 2024

Methods for managing user access to computing devices based on evaluation of authentication and maintenance of user control

Inventors: Kevin Patrick Mahaffey (San Francisco, CA); Brian James Buck (Livermore, CA)
Assignee: LOOKOUT, INC.
G06F21/35H04L63/0853H04L63/105H04W12/06H04W12/64H04R1/1008H04R1/1041H04W12/61H04W84/18H04W88/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,061,683
App. No.
18/317,760
Granted
Aug 13, 2024
Kind
B2
Abstract

The method disclosed herein provides for performing user authentication and maintaining user authentication and access to a second device based on the user maintaining control of a first device. The user's continued control may be based on determining the user's continued possession of the first device from the authentication to a pairing with the second electronic device which then causes a second security component executing on the second electronic device to change the second electronic device to an unlocked state.

Claims (25)

1. A method comprising:

authenticating, by a first computing device, a user;

determining an authentication, by a first security component executing on the first computing device, that the user is authenticated;

determining a pairing, by the first security component, that the first computing device is paired with a second electronic device;

determining, by the first security component, that the user has been in control of the first computing device from the authentication to the pairing with the second electronic device; and

causing, by a second security component executing on the second electronic device, the second electronic device to change to an unlocked state when:

the first security component informs the second security component that the user is authenticated and has been in control of the first computing device from the authentication to the pairing with the second electronic device;

the second security component determines, from interpreting visual data provided by the second electronic device, that the user exceeded a threshold distance from the second electronic device and returned within the threshold distance from the second electronic device after a first period of time; and

the second security component determines, from interpreting the visual data, that the user was in continuous possession of the first electronic device during the first period of time.

2. A method comprising:

authenticating, by a first computing device, a user;

determining an authentication, by a first security component executing on the first computing device, that the user is authenticated;

determining a pairing, by the first security component, that the first computing device is paired with a second electronic device by confirming that the second electronic device has been previously paired with the first computing device;

determining, by the first security component, that the user has been in control of the first computing device based on continued presence data detected by the first security component;

generating a derived credential, by the first security component, in response to the first security component determining that the user is authenticated, that the second electronic device is paired with the first computing device, and that the user has been in control of the first computing device;

transmitting the derived credential to the second electronic device; and

causing the second electronic device to change to an unlocked state without requiring any action by the user.

3. The method of claim 2 , the derived credential comprising at least one of a protected key or a cryptographic proof of knowledge of an authorizing key.

4. The method of claim 2 , the determining that the user has been in control of the first computing device comprising confirming that the user has been in possession of the first computing device via a predetermined possession method selected from the group of: detecting a predetermined interaction with an input device of the first computing device, detecting that the first computing device is in motion, or receiving biometric signals from the user.

5. The method of claim 2 , further comprising:

continuing to monitor, by the first security component, the proximity between the first computing device and the second electronic device after the first computing device enters the locked state;

comparing, by the first security component, subsequent presence data, received from the first computing device after the first computing device enters the locked state, and the continued presence data; and

causing, by the first security component, the first computing device to enter an unlocked state when the proximity is less than the predetermined proximity threshold data and the subsequent presence data is determined to match the continued presence data based on the comparison.

6. The method of claim 2 , the continued presence data including

a notification, from the second electronic device, that interaction is taking place with input devices of the second electronic device.

Assignments (3)
SECURITY INTEREST Recorded Oct 7, 2025
From: LOOKOUT, INC.
To: MIDCAP FINANCIAL TRUST
Reel/Frame 073028/0189 →
SECURITY INTEREST Recorded Oct 2, 2025
From: LOOKOUT, INC.
To: CRESCENT COVE OPPORTUNITY LENDING, LLC, AS AGENT
Reel/Frame 072989/0675 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 16, 2023
From: MAHAFFEY, KEVIN PATRICK; BUCK, BRIAN JAMES
To: LOOKOUT, INC.
Reel/Frame 063660/0520 →