IP Library › Granted Patent US 10,992,474
Granted Patent B2
US 10,992,474 · App. 16/174,632 · Granted Apr 27, 2021

Proactive user authentication for facilitating subsequent resource access across multiple devices

Inventors: Nagendra Gudibande Srikanta Sharma (Bangalore, IN); Udayendranaidu Gottapu (Visakhapatnam, IN); Pedda Peddy Kathriki (Bangalore, IN)
Assignee: EMC IP Holding Company LLC
H04L9/3218H04L63/0876H04L63/102
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,992,474
App. No.
16/174,632
Granted
Apr 27, 2021
Kind
B2
Abstract

Methods, apparatus, and processor-readable storage media for proactive user authentication for facilitating subsequent resource access across multiple devices are provided herein. An example computer-implemented method includes validating an authentication result received via a first user device; generating, in response to validating the authentication result, a proof of authentication that relates to the authentication performed via the first user device; outputting the proof of authentication to the first user device; receiving, via a second user device in connection with a request to access a protected resource, cryptographic information comprising at least a portion of the proof of authentication output to the first user device; validating the cryptographic information received via the second user device against the proof of authentication; and granting, to the second user device, access to the protected resource in response to validating the cryptographic information against the proof of authentication.

Claims (52)

1. A computer-implemented method comprising:

validating, via at least one authentication service connected to a first user device via network connectivity, an authentication result received via the first user device;

generating, via the at least one authentication service in response to validating the authentication result, a proof of authentication that relates to the authentication performed via the first user device;

outputting, via the at least one authentication service, the proof of authentication to the first user device via the network connectivity;

outputting, via the at least one authentication service to a second user device via network connectivity, a request for cryptographic information in response to a request to access a protected resource by the second user device;

obtaining, via the second user device from the first user device, wherein the first user device lacks network connectivity, at least a portion of the proof of authentication;

receiving, via the at least one authentication service from the second user device via network connectivity, cryptographic information comprising the at least a portion of the proof of authentication output to the first user device;

validating, via the at least one authentication service, the cryptographic information received from the second user device against the proof of authentication output by the at least one authentication service to the first user device; and

granting, via the at least one authentication service to the second user device, access to the protected resource in response to validating the cryptographic information received from the second user device against the proof of authentication output by the at least one authentication service to the first user device;

wherein the method is performed by at least one processing device comprising a processor coupled to a memory.

2. The computer-implemented method of claim 1 , further comprising:

storing the proof of authentication.

3. The computer-implemented method of claim 1 , wherein the proof of authentication comprises a quick response code.

4. The computer-implemented method of claim 1 , wherein the proof of authentication comprises one or more temporal parameters.

5. The computer-implemented method of claim 4 , wherein the one or more temporal parameters define a duration of time during which the proof of authentication remains valid.

6. The computer-implemented method of claim 1 , wherein the proof of authentication comprises a set of alphanumeric data.

7. The computer-implemented method of claim 1 , wherein the proof of authentication comprises a set of image data.

8. The computer-implemented method of claim 1 , wherein the proof of authentication comprises a set of audio data.

9. The computer-implemented method of claim 1 , wherein the proof of authentication comprises a set of video data.

10. The computer-implemented method of claim 1 , further comprising:

prompting, in response to receiving the request to access the protected resource from the second user device, the second user device to retrieve the proof of authentication from the first user device.

11. The computer-implemented method of claim 1 , further comprising:

creating, in response to validating the authentication result received via the first user device, an authentication session for the user.

12. The computer-implemented method of claim 11 , wherein the proof of authentication comprises information pertaining to the authentication session.

13. The computer-implemented method of claim 1 , wherein the first user device comprises one of a desktop computer, a laptop computer, a tablet, and a mobile device.

14. The computer-implemented method of claim 1 , wherein the second user device comprises one of a desktop computer, a laptop computer, a tablet, and a mobile device.

15. A non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code when executed by at least one processing device causes the at least one processing device:

to validate, via at least one authentication service connected to a first user device via network connectivity, an authentication result received via the first user device;

to generate, via the at least one authentication service in response to validating the authentication result, a proof of authentication that relates to the authentication performed via the first user device;

to output, via the at least one authentication service, the proof of authentication to the first user device via the network connectivity;

to output, via the at least one authentication service to a second user device via network connectivity, a request for cryptographic information in response to a request to access a protected resource by the second user device;

to obtain, via the second user device from the first user device, wherein the first user device lacks network connectivity, at least a portion of the proof of authentication;

to receive, via the at least one authentication service from the second user device via network connectivity, cryptographic information comprising the at least a portion of the proof of authentication output to the first user device;

to validate, via the at least one authentication service, the cryptographic information received from the second user device against the proof of authentication output by the at least one authentication service to the first user device; and

to grant, via the at least one authentication service to the second user device, access to the protected resource in response to validating the cryptographic information received from the second user device against the proof of authentication output by the at least one authentication service to the first user device.

16. The non-transitory processor-readable storage medium of claim 15 , wherein the proof of authentication comprises one or more temporal parameters.

17. The non-transitory processor-readable storage medium of claim 15 , wherein the program code when executed by the at least one processing device causes the at least one processing device:

to prompt, in response to receiving the request to access the protected resource from the second user device, the second user device to retrieve the proof of authentication from the first user device.

18. An apparatus comprising:

at least one processing device comprising a processor coupled to a memory;

the at least one processing device being configured:

to validate, via at least one authentication service connected to a first user device via network connectivity, an authentication result received via the first user device;

to generate, via the at least one authentication service in response to validating the authentication result, a proof of authentication that relates to the authentication performed via the first user device;

to output, via the at least one authentication service, the proof of authentication to the first user device via the network connectivity;

to output, via the at least one authentication service to a second user device via network connectivity, a request for cryptographic information in response to a request to access a protected resource by the second user device;

to obtain, via the second user device from the first user device, wherein the first user device lacks network connectivity, at least a portion of the proof of authentication;

to receive, via the at least one authentication service from the second user device via network connectivity, cryptographic information comprising the at least a portion of the proof of authentication output to the first user device;

to validate, via the at least one authentication service, the cryptographic information received from the second user device against the proof of authentication output by the at least one authentication service to the first user device; and

to grant, via the at least one authentication service to the second user device, access to the protected resource in response to validating the cryptographic information received from the second user device against the proof of authentication output by the at least one authentication service to the first user device.

19. The apparatus of claim 18 , wherein the proof of authentication comprises one or more temporal parameters.

20. The apparatus of claim 18 , wherein the at least one processing device being further configured:

to prompt, in response to receiving the request to access the protected resource from the second user device, the second user device to retrieve the proof of authentication from the first user device.

Assignments (4)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 30, 2018
From: SHARMA, NAGENDRA GUDIBANDE SRIKANTA; GOTTAPU, UDAYENDRANAIDU; KATHRIKI, PEDDA REDDY
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 047355/0526 →
Continuity (1)
Related Publication 20200136826A1 · Apr 30, 2020
Cited By (1)
US 12,671,690