IP Library Granted Patent US 12,323,467
Granted Patent B2
US 12,323,467 · App. 18/413,227 · Granted Jun 3, 2025

Personal device network for user identification and authentication

Inventors: David M. T. Ting (Sudbury, MA); Alain Slak (Bedford, MA); Kyle Vernest (Boston, MA)
Assignee: Imprivata, Inc.
H04L63/20H04L63/08H04L63/10H04L63/107H04W4/02H04W12/06H04W12/08H04W12/63
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,323,467
App. No.
18/413,227
Granted
Jun 3, 2025
Kind
B2
Abstract

Established user habits in carrying multiple wirelessly detectable devices are used to provide or substantiate authentication. In some embodiments, simply detecting that expected devices are co-located within a limited spatial region is sufficient to establish that the devices are being carried by a single individual. In other embodiments, particularly where the potential for spoofing by multiple individuals is a concern, single-user possession of the devices may be confirmed by various corroborative techniques. This approach affords convenience to users, who may be working at a device that lacks the necessary modality (e.g., a fingerprint or vein reader) for strong authentication.

Claims (26)

1. A method for authenticating a user seeking access to a secure resource at a client device in accordance with a security policy, the method comprising:

electronically detecting one or more wireless devices co-located with the client device;

determining whether the one or more wireless devices are listed and related to the user in an identity database that includes entries relating users with wireless devices belonging to the users;

when the one or more wireless devices are listed and related to the user in the identity database, determining whether detection of the one or more wireless devices co-located with the client device is alone sufficient to satisfy the downloaded security policy; and

when detection of the one or more wireless devices co-located with the client device alone is sufficient to satisfy the security policy, allowing the user to access the secure resource on the client device.

2. The method of claim 1 , wherein the security policy does not require a predetermined location for the client device upon which access to the secure resource is to be allowed.

3. The method of claim 1 , wherein the client device does not receive user-specific authentication information from any of the one or more wireless devices.

4. The method of claim 1 , wherein the client device forms a network with the one or more wireless devices.

5. The method of claim 1 , wherein the one or more wireless devices comprises two or more wireless devices.

6. The method of claim 1 , further comprising, when the detection of the one or more wireless devices co-located with the client device is not sufficient to satisfy the security policy alone, identifying at least one additional authentication step whose fulfillment would satisfy the security policy, causing fulfillment of the at least one additional authentication step, and allowing the user to access the secure resource on the client device after fulfillment of the at least one additional authentication step.

7. The method of claim 6 , further comprising searching initially for additional authentication steps whose fulfillment would satisfy the security policy and that do not require user action.

8. The method of claim 7 , wherein, when there are no additional authentication steps that do not require user action but would satisfy the security policy, causing fulfillment of the at least one additional authentication step comprises engaging the user to fulfill the at least one additional authentication step.

9. The method of claim 1 , further comprising, after the user has been allowed to access the secure resource, (i) verifying the co-location, with the user and the client device, of all wireless devices associated with the user in the identity database, and (ii) for any wireless device associated with the user but not co-located with the user and the client device, at least one of (a) decrementing a counter associated with the wireless device or (b) disassociating the wireless device from the user in the identity database.

10. The method of claim 1 , wherein the client device lacks any modality for biometric authentication.

11. A method for authenticating a user seeking access to a secure resource on a first wireless device in accordance with a security policy, the method comprising:

at the first wireless device, electronically determining whether one or more additional wireless devices associated with the user are co-located with the first wireless device; and

when (i) the one or more additional wireless devices are co-located with the first wireless device, and (ii) when co-location of the one or more additional wireless devices with the first wireless device alone is sufficient to satisfy the security policy, allowing the user to access the secure resource on the first wireless device in response to a request for access from the user.

12. The method of claim 11 , further comprising forming a network among the first wireless device and one or more additional wireless devices.

13. The method of claim 12 , wherein the network comprises an ad hoc network.

14. The method of claim 11 , wherein the first wireless device lacks any modality for biometric authentication.

15. The method of claim 11 , wherein the security policy does not require a predetermined location for the first wireless device upon which access to the secure resource is to be allowed.

16. The method of claim 11 , wherein the first wireless device does not receive user-specific authentication information from any of the one or more additional wireless devices.

17. The method of claim 11 , wherein the one or more additional wireless devices comprises two or more additional wireless devices.

18. The method of claim 11 , further comprising, when the co-location of the one or more additional wireless devices with the first wireless device is not sufficient to satisfy the security policy alone, identifying at least one additional authentication step whose fulfillment would satisfy the security policy, causing fulfillment of the at least one additional authentication step, and allowing the user to access the secure resource on the first wireless device after fulfillment of the at least one additional authentication step.

19. The method of claim 18 , further comprising searching initially for additional authentication steps whose fulfillment would satisfy the security policy and that do not require user action.

20. The method of claim 19 , wherein, when there are no additional authentication steps that do not require user action but would satisfy the security policy, causing fulfillment of the at least one additional authentication step comprises engaging the user to fulfill the at least one additional authentication step.

Assignments (3)
SECURITY INTEREST Recorded Aug 5, 2025
From: IMPRIVATA, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 071933/0153 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 8, 2025
From: TING, DAVID M.T.; SLAK, ALAIN; VERNEST, KYLE
To: IMPRIVATA, INC.
Reel/Frame 071231/0889 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 25, 2024
From: TING, DAVID M.T.; SLAK, ALAIN; VERNEST, KYLE
To: IMPRIVATA, INC.
Reel/Frame 067227/0436 →
Continuity (4)
Continuation 16408796 · May 10, 2019
Continuation 14945609 · Nov 19, 2015
Provisional Application 62081820 · Nov 19, 2014
Related Publication 20240267413A1 · Aug 8, 2024
References Cited (36)
US 8646060B1 · Ayed · 2014 [cited by applicant]
US 8973091B2 · Ting et al. · 2015 [cited by applicant]
US 9723003B1 · McClintock et al. · 2017 [cited by applicant]
US 10333980B2 · Ting · 2019 [cited by examiner]
US 11115628B2 · Phillips · 2021 [cited by examiner]
US 11909765B2 · Ting · 2024 [cited by examiner]
US 20070136792A1 · Ting et al. · 2007 [cited by applicant]
US 20080137622A1 · Russell · 2008 [cited by applicant]
US 20100022239A1 · Anzai · 2010 [cited by applicant]
US 20100059587A1 · Miller et al. · 2010 [cited by applicant]
US 20110047594A1 · Mahaffey et al. · 2011 [cited by applicant]
US 20110221566A1 · Kozlay · 2011 [cited by applicant]
US 20130102283A1 · Lau et al. · 2013 [cited by applicant]
US 20130145420A1 · Ting et al. · 2013 [cited by applicant]
US 20130197998A1 · Buhrmann · 2013 [cited by examiner]
US 20130268687A1 · Schrecker · 2013 [cited by examiner]
US 20130268767A1 · Schrecker · 2013 [cited by examiner]
US 20140091903A1 · Birkel et al. · 2014 [cited by applicant]
US 20140123237A1 · Gaudet et al. · 2014 [cited by applicant]
US 20140156833A1 · Robinson · 2014 [cited by applicant]
US 20140282967A1 · Maguire et al. · 2014 [cited by applicant]
US 20140359750A1 · Adams et al. · 2014 [cited by applicant]
US 20150082406A1 · Park et al. · 2015 [cited by applicant]
US 20150128240A1 · Richards et al. · 2015 [cited by applicant]
US 20150154597A1 · Bacastow · 2015 [cited by applicant]
US 20150189378A1 · Soundararajan et al. · 2015 [cited by applicant]
US 20150281227A1 · Ivey et al. · 2015 [cited by applicant]
US 20150286813A1 · Jakobsson · 2015 [cited by applicant]
US 20150363986A1 · Hoyos et al. · 2015 [cited by applicant]
US 20150365787A1 · Farrell · 2015 [cited by applicant]
US 20160004852A1 · McEvoy et al. · 2016 [cited by applicant]
US 20160112871A1 · White · 2016 [cited by applicant]
US 20160142443A1 · Ting et al. · 2016 [cited by applicant]
US 20170032114A1 · Turgeman · 2017 [cited by applicant]
US 20180109936A1 · Ting et al. · 2018 [cited by applicant]
US 20190313252A1 · Ting et al. · 2019 [cited by applicant]