IP Library Granted Patent US 12,726,362
Granted Patent B1
US 12,726,362 · App. 18/965,705 · Granted Sep 1, 2026

Delegated device authentication between trusted devices

Inventors: Jonathan Clark (Seattle, WA); Chirag Deepak Agrawal (San Francisco, CA); Sachin Balaso Shinde (Pflugerville, TX)
Assignee: Amazon Technologies, Inc.
H04L9/3247H04L9/0825H04L9/3213H04L9/3271
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,726,362
App. No.
18/965,705
Granted
Sep 1, 2026
Kind
B1
Abstract

Systems, apparatuses, and methods are described for delegated device authentication. An example method includes receiving, from a first device, a request to access enterprise data managed by an enterprise service. The example method also includes determining a security status of the first device, where the security status indicates that the first device complies with a set of conditional access policies. The example method also includes determining, based on execution of a first authentication mechanism having a first confidence rating, an account associated with a natural language processing system. The example method also includes receiving, from a second device, an authentication response indicating an execution of a second authentication mechanism having a second confidence rating and authenticating the first account based on the authentication response. The example method also includes initiating a delegated authentication session for the first device during which the first device is authorized to access the enterprise data.

Claims (88)

1 . A natural language processing system comprising:

a processor; and

non-transitory computer-readable memory storing instructions that, when executed by the processor, are effective to cause:

an authentication delegation service to:

receive, from a first device, first input data comprising a first utterance, the first utterance is associated with a first request to access first enterprise data managed by a third-party (3P) enterprise service;

a device posture assessment service to:

determine, based on a first set of device compliance signals received from the first device, a first security status of the first device, the first security status to indicate that the first device complies with a set of predetermined conditional access policies; and

a recognition component to:

determine based on the first utterance, a first voice profile;

determine, based on the first voice profile, a first account registered with the natural language processing system;

determine, based on a first device identifier associated with the first account, a second device;

the authentication delegation service to:

send a first passkey-based authentication notification to the second device, wherein the first passkey-based authentication notification comprises a first passkey challenge object;

receive, from the second device, a first passkey response, the first passkey response comprising a first passkey challenge signature associated with the first passkey challenge object, and the first passkey challenge signature to indicate an execution of a first authentication challenge by the second device;

authenticate the first account based on the first passkey response by verifying the first passkey challenge signature based on a public cryptographic key associated with a passkey related to the second device;

upon successful authentication of the first account based on the passkey, initiate a first delegated authentication session for the first device, the first device authorized to access the first enterprise data during the first delegated authentication session;

generate a first application programming interface (API) call associated with the first utterance, the first API call configured to retrieve the first enterprise data associated with the first utterance from the 3P enterprise service, and the first API call comprising an authentication token associated with an enterprise service account;

receive, based on an execution of the first API call, the first enterprise data from the 3P enterprise service; and

store the first enterprise data in a storage device associated with the natural language processing system.

2 . The natural language processing system of claim 1 , wherein the instructions, when executed by the processor, are effective to cause the authentication delegation service to:

prior to authorizing the first device to access the first enterprise data, receive, based on an interaction with a software application instance associated with the natural language processing system, an enterprise service account linking request, the enterprise service account linking request a request to link the first account associated with the natural language processing system to the enterprise service account;

receive, upon successful authentication of the enterprise service account by the 3P enterprise service, the authentication token associated with the enterprise service account from the 3P enterprise service, wherein the authentication token is a refreshable authentication token;

generate the passkey associated with the first account associated with the natural language processing system, the passkey comprising a public-private cryptographic key pair and a device signature associated with the second device;

store the public cryptographic key of the passkey with relation to the first account, wherein a private cryptographic key of the passkey is stored by the second device; and

link the authentication token associated with the enterprise service account to the first account associated with the natural language processing system.

3 . The natural language processing system of claim 1 , wherein the first enterprise data comprises calendar event data associated with the enterprise service account.

4 . A computer-implemented method comprising:

receiving, from a first device, first input data comprising a first request to access first enterprise data managed by an enterprise service;

determining, based on execution of a first authentication mechanism having a first confidence rating, a first account, the first account associated with a natural language processing system;

determining, based on a first device identifier associated with the first account, a second device;

sending a first authentication notification to the second device;

receiving, from the second device, a first authentication response, the first authentication response to indicate an execution of a second authentication mechanism having a second confidence rating by the second device;

authenticating the first account based on the first authentication response and, upon successful authentication of the first account, initiating a first delegated authentication session for the first device, the first device authorized to access the first enterprise data during the first delegated authentication session; and

sending the first enterprise data to the first device.

5 . The computer-implemented method of claim 4 , wherein the computer-implemented method further comprises:

prior to authorizing the first device to access the first enterprise data, receiving, based on an interaction with a software application instance associated with the natural language processing system, an enterprise service account linking request, the enterprise service account linking request a request to link the first account associated with the natural language processing system to an enterprise service account;

receiving, upon successful authentication of the enterprise service account by the enterprise service, an authentication token associated with the enterprise service account from the enterprise service;

generating a passkey associated with the first account associated with the natural language processing system, the passkey comprising a public-private cryptographic key pair and a device signature associated with the second device;

storing a public cryptographic key of the passkey with relation to the first account, wherein a private cryptographic key of the passkey is stored by the second device; and

linking the authentication token associated with the enterprise service account to the first account associated with the natural language processing system.

6 . The computer-implemented method of claim 4 , wherein the first enterprise data comprises calendar event data associated with an enterprise service account.

7 . The computer-implemented method of claim 4 , wherein the first confidence rating of the first authentication mechanism is a lower confidence rating relative to the second confidence rating of the second authentication mechanism.

8 . The computer-implemented method of claim 7 , wherein the first request is a first natural language request and determining the first account based on the execution of the first authentication mechanism further comprises:

determining, based on the first natural language request, a first voice profile associated with the first account.

9 . The computer-implemented method of claim 8 , wherein determining the first account based on the execution of the first authentication mechanism further comprises:

determining, based on receiving first sensor data from the first device, a first facial profile associated with the first account.

10 . The computer-implemented method of claim 4 , wherein the second authentication mechanism is a passkey-based authentication mechanism comprising:

receiving, from the second device, the first authentication response comprising a first passkey challenge signature to indicate an execution of a first authentication challenge by the second device, the first authentication response comprising a device signature associated with the second device.

11 . The computer-implemented method of claim 4 , wherein the computer-implemented method further comprises:

generating, based on the first enterprise data, first tokenized enterprise data; and

storing the first tokenized enterprise data in a first search index.

12 . The computer-implemented method of claim 11 , wherein the computer-implemented method further comprises:

receiving, from the first device, second input data comprising a second natural language request to access second enterprise data;

determining a first access intent associated with the second natural language request;

querying the first search index based on the first access intent; and

sending the second enterprise data to the first device.

13 . The computer-implemented method of claim 4 , wherein the computer-implemented method further comprises:

generating, based on the first enterprise data, first obscured enterprise data; and

causing simultaneous display of the first obscured enterprise data and first personal data associated with the first account on the first device.

14 . The computer-implemented method of claim 13 , wherein the computer-implemented method further comprises:

receiving third input data, wherein the third input data comprises a selection indication associated with the first obscured enterprise data displayed on the first device;

authenticating the first account, wherein authenticating the first account comprises:

determining a delegated authentication session status related to the first device, the delegated authentication session status to indicate whether a delegated authentication session is currently active for the first device,

upon a determination that a delegated authentication session is not currently active for the first device, sending a second authentication notification to the second device,

receiving, from the second device, a second authentication response to indicate an execution of the second authentication mechanism by the second device, the second authentication mechanism a passkey-based authentication mechanism, and

authenticating the first account based on the second authentication response received from the second device, the second authentication response comprising a second passkey challenge signature associated with a second passkey challenge object, the second passkey challenge signature to indicate an execution of a second authentication challenge on the second device, and the second authentication response comprising a device signature associated with the second device; and

sending the first enterprise data associated with the first obscured enterprise data to the first device.

15 . The computer-implemented method of claim 13 , wherein the computer-implemented method further comprises:

generating, based on the first obscured enterprise data, an enterprise data alert; and

sending the enterprise data alert to the first device.

16 . The computer-implemented method of claim 4 , wherein authorizing the first device to access the first enterprise data during the first delegated authentication session enables the first device to initiate one or more enterprise data creation actions, enterprise data reading actions, enterprise data updating actions, or enterprise data deletion actions.

17 . The computer-implemented method of claim 4 , wherein the computer-implemented method further comprises determining a first security status of the first device, the first security status to indicate that the first device complies with a first conditional access policy.

18 . The computer-implemented method of claim 17 , wherein the first conditional access policy is based on one or more enterprise standards associated with the enterprise service.

19 . The computer-implemented method of claim 17 , wherein the computer-implemented method further comprises:

determining, based on a first co-location confidence score, that a third device is in a same environment as the first device, the first co-location confidence score generated based on first co-location data comprising one or more of co-wake data associated with the first request, Bluetooth low energy (BLE) beaconing data, or network identifier data associated with the first device and the third device;

determining whether the first co-location confidence score satisfies a predetermined co-location confidence threshold defined by the first conditional access policy;

determining, upon a determination that the first co-location confidence score satisfies the predetermined co-location confidence threshold, a second security status of the third device, the second security status to indicate the third device complies with the first conditional access policy; and

extending the first delegated authentication session to the third device to authorize the third device to access the first enterprise data during the first delegated authentication session and to initiate one or more enterprise data creation actions, enterprise data reading actions, enterprise data updating actions, or enterprise data deletion actions.

20 . A system comprising:

at least one processor; and

non-transitory computer-readable memory storing instructions that, when executed by the at least one processor, are effective to perform operations comprising:

receiving, from a first device, first input data comprising a first request to access first enterprise data managed by an enterprise service;

determining, based on execution of a first authentication mechanism having a first confidence rating, a first account, the first account associated with a natural language processing system;

determining, based on a first device identifier associated with the first account, a second device;

sending a first authentication notification to the second device;

receiving, from the second device, a first authentication response, the first authentication response to indicate an execution of a second authentication mechanism having a second confidence rating by the second device;

authenticating the first account based on the first authentication response and, upon successful authentication of the first account, initiating a first delegated authentication session for the first device, the first device authorized to access the first enterprise data during the first delegated authentication session; and

sending the first enterprise data to the first device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 2, 2024
From: CLARK, JONATHAN; AGRAWAL, CHIRAG DEEPAK; SHINDE, SACHIN BALASO
To: AMAZON TECHNOLOGIES, INC.
Reel/Frame 069455/0369 →
References Cited (27)
US 9172699B1 · Vazquez · 2015 [cited by examiner]
US 9191381B1 · Popp · 2015 [cited by examiner]
US 9264419B1 · Johansson · 2016 [cited by examiner]
US 9503452B1 · Kumar · 2016 [cited by examiner]
US 10089983B1 · Gella · 2018 [cited by examiner]
US 11640453B2 · Gorsica, IV · 2023 [cited by examiner]
US 12335255B1 · Piri · 2025 [cited by examiner]
US 12499444B1 · Stennett · 2025 [cited by examiner]
US 12525243B2 · Lim · 2026 [cited by examiner]
US 20170374176A1 · Agrawal · 2017 [cited by examiner]
US 20180007060A1 · Leblang · 2018 [cited by examiner]
US 20190272831A1 · Kajarekar · 2019 [cited by examiner]
US 20190364034A1 · Alexander · 2019 [cited by examiner]
US 20190378499A1 · Miller · 2019 [cited by examiner]
US 20220408259A1 · Adel · 2022 [cited by examiner]
US 20230146095A1 · Kim · 2023 [cited by examiner]
US 20240118744A1 · Vaughan · 2024 [cited by examiner]
US 20240171380A1 · Jobard · 2024 [cited by examiner]
US 20240259190A1 · Karthikeyan · 2024 [cited by examiner]
US 20240422540A1 · Hopper · 2024 [cited by examiner]
US 20250111356A1 · Kostovski · 2025 [cited by examiner]
US 20250384118A1 · Pollard · 2025 [cited by examiner]
WO WO2026030384A1 · 2026 [cited by examiner]
Hayashi, V. T., & Ruggiero, W. V. (2022). Hands-free authentication for virtual assistants with trusted IoT device and machine learning. Sensors, 22(4), 1325. (Year: 2022). [cited by examiner]
Jana, A. K., & Saha, S. (2021). Natural Language Processing and Artificial intelligence to guarantee security in Decentralized Finance (DeFi). European Journal of Advances in Engineering and Technology, 8(9), 58-63. (Ye… [cited by examiner]
Khalil, U., Ahmad, A., Abdel-Aty, A. H., Elhoseny, M., El-Soud, M. W. A., & Zeshan, F. (2021). Identification of trusted IoT devices for secure delegation. Computers & Electrical Engineering, 90, 106988. (Year: 2021). [cited by examiner]
Steffen, R., & Knorr, R. (2005). A trust based delegation system for managing access control. na. (Year: 2005). [cited by examiner]