IP Library Granted Patent US 11,297,055
Granted Patent B2
US 11,297,055 · App. 16/857,750 · Granted Apr 5, 2022

Multifactor contextual authentication and entropy from device or device input or gesture authentication

Inventors: Georgy Momchilov (Parkland, FL); Chris Pavlou (Boca Raton, FL); Ola Nordstrom (Fort Lauderdale, FL); Christopher Wade (Ocean Ridge, FL)
Assignee: Citrix Systems, Inc.
H04L63/0853G06F21/34G06F21/41G06F21/83H04L63/0272H04L63/0815H04L63/0884H04W12/06H04W12/35G06F2221/2139H04L9/083H04L9/0825H04L9/3247H04L63/0846H04W12/43
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,297,055
App. No.
16/857,750
Filed
Apr 24, 2020
Granted
Apr 5, 2022
Kind
B2
Art Unit
2437
USPC
726/7
Abstract

Methods and systems for authenticating a user requesting to access one or more resources via a device are described herein. Authentication may be based on or otherwise rely on a plurality of devices. For example, aspects described herein are directed towards a system and method for receiving an authentication request from a first user device. A second user device may send a request for and receive a public key of the first user device and receive. The second user device may verify the authentication request using the public key of the first user device and perform authentication based on an authentication secret received from a user.

Claims (44)

1. A method comprising:

receiving, from a first user device by a second user device via a device mesh, an authentication request, wherein the authentication request is signed with a private key of the first user device;

sending, by the second user device to a computing device associated with the device mesh, a request for a public key of the first user device;

receiving, by the second user device from the computing device, the public key of the first user device;

based on a successful verification of the authentication request using the public key of the first user device, receiving, by the second user device, an authentication secret from a user;

performing, by the second user device based on the received authentication secret, authentication with an authentication server; and

sending, by the second user device to the first user device, a message indicating that the authentication is successful.

2. The method of claim 1 , further comprising sending, by the second user device to the computing device, a public key of the second user device, wherein the authentication request is encrypted with the public key of the second user device.

3. The method of claim 1 , wherein the message is encrypted with the public key of the first user device, and wherein the message is signed with a private key of the second user device.

4. The method of claim 1 , wherein the message comprises a validity time period within which the message is valid.

5. The method of claim 1 , wherein the first user device is paired with the second user device in the device mesh.

6. The method of claim 1 , wherein the second user device comprises a mouse or a smartwatch, and wherein the receiving the authentication secret comprises receiving a user input via at least one of a wheel of the mouse, a button of the mouse, a wheel of the smartwatch, or a button of the smartwatch.

7. The method of claim 1 , further comprising:

sending, by the second user device to the computing device, a request to verify that the first user device is registered with the device mesh,

wherein the receiving the public key of the first user device is based on a verification that the first user device is registered with the device mesh.

8. An apparatus comprising:

one or more processors; and

memory storing instructions that, when executed by the one or more processors, cause the apparatus to:

receive, from a user device via a device mesh, an authentication request, wherein the authentication request is signed with a private key of the user device;

send, to a computing device associated with the device mesh, a request for a public key of the user device;

receive, from the computing device, the public key of the user device;

based on a successful verification of the authentication request using the public key of the user device, receive an authentication secret from a user;

perform, based on the received authentication secret, authentication with an authentication server; and

send, to the user device, a message indicating that the authentication is successful.

9. The apparatus of claim 8 , wherein the instructions, when executed by the one or more processors, further cause the apparatus to send, to the computing device, a public key of the apparatus, wherein the authentication request is encrypted with the public key of the apparatus.

10. The apparatus of claim 8 , wherein the message is encrypted with the public key of the user device, and wherein the message is signed with a private key of the apparatus.

11. The apparatus of claim 8 , wherein the message comprises a validity time period within which the message is valid.

12. The apparatus of claim 8 , wherein the apparatus is paired with the user device in the device mesh.

13. The apparatus of claim 8 , wherein the apparatus comprises a mouse or a smartwatch, and wherein the instructions, when executed by the one or more processors, further cause the apparatus to receive the authentication secret by receiving a user input via at least one of a wheel of the mouse, a button of the mouse, a wheel of the smartwatch, or a button of the smartwatch.

14. The apparatus of claim 8 , wherein the instructions, when executed by the one or more processors, further cause the apparatus to:

send, to the computing device, a request to verify that the user device is registered with the device mesh,

wherein the instructions, when executed by the one or more processors, cause the apparatus to receive the public key of the user device based on a verification that the user device is registered with the device mesh.

15. A non-transitory computer-readable media storing instructions that, when executed, cause:

receiving, from a first user device by a second user device via a device mesh, an authentication request, wherein the authentication request is signed with a private key of the first user device;

sending, by the second user device to a computing device associated with the device mesh, a request for a public key of the first user device;

receiving, by the second user device from the computing device, the public key of the first user device;

based on a successful verification of the authentication request using the public key of the first user device, receiving, by the second user device, an authentication secret from a user;

performing, by the second user device based on the received authentication secret, authentication with an authentication server; and

sending, by the second user device to the first user device, a message indicating that the authentication is successful.

16. The non-transitory computer-readable media s of claim 15 , wherein the instructions, when executed, further cause sending, by the second user device to the computing device, a public key of the second user device, wherein the authentication request is encrypted with the public key of the second user device.

17. The non-transitory computer-readable media s of claim 15 , wherein the message is encrypted with the public key of the first user device and wherein the message is signed with a private key of the second user device.

18. The non-transitory computer-readable media s of claim 15 , wherein the message comprises a validity time period within which the message is valid.

19. The non-transitory computer-readable media s of claim 15 , wherein the first user device is paired with the second user device in the device mesh.

20. The non-transitory computer-readable media s of claim 15 , wherein the second user device comprises a mouse or a smartwatch, and wherein the instructions, when executed, cause the receiving the authentication secret by receiving a user input via at least one of a wheel of the mouse, a button of the mouse, a wheel of the smartwatch, or a button of the smartwatch.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 6, 2022
From: MOMCHILOV, GEORGY; PAVLOU, CHRIS; NORDSTROM, OLA; WADE, CHRISTOPHER
To: CITRIX SYSTEMS, INC.
Reel/Frame 059268/0027 →
Continuity (4)
Continuation 16164258 · Oct 18, 2018
Continuation 15150558 · May 10, 2016
Provisional Application 62160144 · May 12, 2015
Related Publication 20200252394A1 · Aug 6, 2020
Cited By (3)
US 12,381,869 US 12,418,529 US 12,418,543