IP Library › Granted Patent US 12,627,657
Granted Patent B2
US 12,627,657 · App. 18/360,093 · Granted May 12, 2026

Computerized system and method for device-based identity management

Inventors: Charles Kring (Sunnyvale, CA); Austen Martin (West Kelowna, CA)
Assignee: PLUME DESIGN, INC.
H04L63/0861H04L63/0807H04L63/083H04L63/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,627,657
App. No.
18/360,093
Granted
May 12, 2026
Kind
B2
Abstract

Disclosed are systems and methods that provide a novel cross-session authentication framework that enables secure local and/or network sessions to be effectuated via biometric tracking via a wearable device (e.g., smart ring). In some implementations, when a user wearing a smart ring is authenticated with a first secure resource (e.g., a computer system such as a smart phone application associated with the smart ring), such authentication can be maintained and leveraged to access other resources that are separately being securely held. The smart ring, when properly worn, can monitor biometrics (e.g., vital signs) of a user, and based therefrom, determine if and/or when the smart ring is removed/manipulated from the user's finder. Until the smart ring is removed, the smart ring's confirmation of being worn by the user can be leveraged as an identification token that can enable the user access to other securely held information.

Claims (66)

1 . A method comprising:

providing a session token to a device of a user, the session token corresponding to an authenticated session of the user with a first system, the session token stored in association with the device and configured to provide authentication credentials for accessing a plurality of systems;

collecting biometric data related to the user, the biometric data comprising data captured by one or more sensors of the device and providing an indication of a status of the user, the status indicating whether the user maintains an authenticated relationship with the device;

receiving a request for access to a second system, the second system being a distinct system from the first system and requiring separate authentication;

analyzing the collected biometric data based on the request, the analyzing comprising evaluating whether the biometric data is consistent with continued presence of an authenticated user with the device;

determining, based on the analysis, whether to authenticate the user for the second system, the determination comprising:

comparing the collected biometric data against reference biometric data associated with the authenticated session to identify whether the user associated with the session token remains the current user of the device; and

granting authentication when the comparison indicates continuity of the authenticated user; and

electronically communicating the session token to the second system along with information to the device based on the determination, the communicated session token enabling the second system to grant access without requiring the user to provide additional authentication credentials.

2 . The method of claim 1 , wherein the communicated information comprises an indication of an access denial.

3 . The method of claim 2 , further comprising:

determining, based on the analysis, that the status is not consistent with a manner corresponding to the authentication of the session with the first system.

4 . The method of claim 1 , further comprising:

determining, based on the analysis, that the status is consistent with a manner corresponding to the authentication of the session with the first system; and

communicating, via the device, the session token to the second system.

5 . The method of claim 4 , further comprising:

authenticating the user on the second system via the communicated session token.

6 . The method of claim 4 , wherein the communicated information comprises an indication of access to the second system.

7 . The method of claim 1 , further comprising:

monitoring, via the device, the biometric data; and

analyzing the biometric data to determine events corresponding to manners in which the user maintains the status, wherein the monitoring and analysis of the biometric data is based on the collection of the biometric data.

8 . The method of claim 1 , further comprising:

providing login credentials to the first system;

receiving, in response to the provided login credentials, an indication of authentication with the first system, the authentication comprising access to an account with the first system; and

communicating the session token to the device.

9 . The method of claim 1 , wherein the session token is stored in association with the device.

10 . The method of claim 1 , wherein the device is a user device.

11 . A system comprising:

a processor configured to:

provide a session token to a device of a user, the session token corresponding to an authenticated session of the user with a first system, the session token stored in association with the device and configured to provide authentication credentials for accessing a plurality of systems;

collect biometric data related to the user, the biometric data comprising data captured by one or more sensors of the device and providing an indication of a status of the user, the status indicating whether the user maintains an authenticated relationship with the device;

receive a request for access to a second system, the second system being a distinct system from the first system and requiring separate authentication;

analyze the collected biometric data based on the request, the analyzing comprising evaluating whether the biometric data is consistent with continued presence of an authenticated user with the device;

determine, based on the analysis, whether to authenticate the user for the second system by:

comparing the collected biometric data against reference biometric data associated with the authenticated session to identify whether the user associated with the session token remains the current user of the device; and

granting authentication when the comparison indicates continuity of the authenticated user; and

electronically communicate the session token to the second system along with information to the device based on the determination, the communicated session token enabling the second system to grant access without requiring the user to provide additional authentication credentials.

12 . The system of claim 11 , wherein the processor is further configured to:

determine, based on the analysis, that the status is not consistent with a manner corresponding to the authentication of the session with the first system, wherein the communicated information comprises an indication of an access denial.

13 . The system of claim 11 , wherein the processor is further configured to:

determine, based on the analysis, that the status is consistent with a manner corresponding to the authentication of the session with the first system;

communicate the session token to the second system;

authenticate the user on the second system via the communicated session token, wherein the communicated information comprises an indication of access to the second system.

14 . The system of claim 11 , wherein the processor is further configured to:

monitor the biometric data; and

analyze the biometric data to determine events corresponding to manners in which the user maintains the status, wherein the monitoring and analysis of the biometric data is based on the collection of the biometric data.

15 . The system of claim 11 , wherein the device is a user device.

16 . A non-transitory computer-readable storage medium tangibly encoded with computer-executable instructions that when executed by a processor, perform a method comprising:

providing a session token to a device of a user, the session token corresponding to an authenticated session of the user with a first system, the session token stored in association with the device and configured to provide authentication credentials for accessing a plurality of systems;

collecting biometric data related to the user, the biometric data comprising data captured by one or more sensors of the device and providing an indication of a status of the user, the status indicating whether the user maintains an authenticated relationship with the device;

receiving a request for access to a second system, the second system being a distinct system from the first system and requiring separate authentication;

analyzing the collected biometric data based on the request, the analyzing comprising evaluating whether the biometric data is consistent with continued presence of an authenticated user with the device;

determining, based on the analysis, whether to authenticate the user for the second system, the determination comprising:

comparing the collected biometric data against reference biometric data associated with the authenticated session to identify whether the user associated with the session token remains the current user of the device; and

granting authentication when the comparison indicates continuity of the authenticated user; and

electronically communicating the session token to the second system along with information to the device based on the determination, the communicated session token enabling the second system to grant access without requiring the user to provide additional authentication credentials.

17 . The non-transitory computer-readable storage medium of claim 16 , further comprising:

determining, based on the analysis, that the status is not consistent with a manner corresponding to the authentication of the session with the first system, wherein the communicated information comprises an indication of an access denial.

18 . The non-transitory computer-readable storage medium of claim 16 , further comprising:

determining, based on the analysis, that the status is consistent with a manner corresponding to the authentication of the session with the first system;

communicating the session token to the second system;

authenticating the user on the second system via the communicated session token, wherein the communicated information comprises an indication of access to the second system.

19 . The non-transitory computer-readable storage medium of claim 16 , further comprising:

monitoring the biometric data; and

analyzing the biometric data to determine events corresponding to manners in which the user maintains the status, wherein the monitoring and analysis of the biometric data is based on the collection of the biometric data.

20 . The non-transitory computer-readable storage medium of claim 16 , wherein the device is a user device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 27, 2023
From: KRING, CHARLES; MARTIN, AUSTEN
To: PLUME DESIGN, INC.
Reel/Frame 064401/0876 →
Continuity (1)
Related Publication 20250039171A1 · Jan 30, 2025
References Cited (8)
US 11405189B1 · Bennison · 2022 [cited by examiner]
US 20160191511A1 · Tijerina et al. · 2016 [cited by applicant]
US 20170068956A1 · Jones · 2017 [cited by applicant]
US 20210211288A1 · Yarabolu · 2021 [cited by applicant]
US 20210358251A1 · Maclean · 2021 [cited by examiner]
US 20230143293A1 · Sanchez · 2023 [cited by applicant]
US 20240223549A1 · Yarabolu · 2024 [cited by examiner]
International Search Report and Written Opinion issued in corresponding Int'l Appln. No. PCT/US24/38148 mailed Oct. 21, 2024 (12 pages). [cited by applicant]