IP Library Granted Patent US 12,341,820
Granted Patent B2
US 12,341,820 · App. 17/931,192 · Granted Jun 24, 2025

System and method for providing location-based access in 5G

Inventors: Niranjan M M (Bengaluru, IN); Nagaraj Kenchaiah (Bengaluru, IN)
Assignee: CISCO TECHNOLOGY, INC.
H04L63/20H04L63/0853
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,341,820
App. No.
17/931,192
Granted
Jun 24, 2025
Kind
B2
Abstract

In one embodiment, a method includes transmitting, to a multi-factor authentication (MFA) agent running on a user device, a request for a location of the user device, receiving, from the MFA agent, the location of the user device, wherein the location is determined by the MFA agent to be a most common location indicated by a plurality of location indicators, receiving, from a policy server, a location-based access policy, appending, to the location-based access policy, the location of the user device and determining, based on the location of the user device and the location-based access policy, whether to allow the user device to access one or more of: a remote service, a remote database, and a remote device.

Claims (66)

1. A system, comprising:

one or more processors; and

one or more computer-readable non-transitory storage media comprising instructions that, when executed by the one or more processors, cause one or more components of the system to perform operations comprising:

transmitting, to a multi-factor authentication (MFA) agent running on a user device, a request for a location of the user device;

receiving, from the MFA agent, the location of the user device, wherein the location is determined by the MFA agent to be a common location indicated by a plurality of location indicators;

receiving, from a policy server, a location-based access policy;

appending, to the location-based access policy, the location of the user device;

in response to appending the location of the user device to the location-based access policy, storing the location-based access policy;

receiving a first authentication result from an authentication server; and

determining, based on the location of the user device, the first authentication result, and the location-based access policy, a second authentication result, wherein the second authentication result indicates whether to allow the user device to access one or more of:

a remote service,

a remote database, and

a remote device.

2. The system of claim 1 , wherein the plurality of location indicators is generated by a plurality of location information sources including one or more of:

a Global Positioning System (GPS),

a cellular location provider, and

an other location provider.

3. The system of claim 1 , wherein the policy server is distributed using a plurality of policy server instances.

4. The system of claim 1 , wherein determining the second authentication result comprises determining whether the user device is within a pre-defined geographic border.

5. The system of claim 1 , wherein determining the second authentication result comprises determining whether the location of the user device corresponds to a geographic identifier associated with the user device.

6. The system of claim 1 , the operations further comprising:

authenticating, via the authentication server, the user device.

7. The system of claim 6 , wherein determining the second authentication result is further based on an authentication result of authenticating the user device.

8. A method, comprising:

transmitting, to a multi-factor authentication (MFA) agent running on a user device, a request for a location of the user device;

receiving, from the MFA agent, the location of the user device, wherein the location is determined by the MFA agent to be a most common location indicated by a plurality of location indicators;

receiving, from a policy server, a location-based access policy;

appending, to the location-based access policy, the location of the user device; and

in response to appending the location of the user device to the location-based access policy, storing the location-based access policy;

receiving a first authentication result from an authentication server; and

determining, based on the location of the user device, the first authentication result, and the location-based access policy, a second authentication result, wherein the second authentication result indicates whether to allow the user device to access one or more of:

a remote service,

a remote database, and

a remote device.

9. The method of claim 8 , wherein the plurality of location indicators are generated by a plurality of location information sources including one or more of:

a Global Positioning System (GPS),

a cellular location provider, and

an other location provider.

10. The method of claim 8 , wherein the policy server is distributed using a plurality of policy server instances.

11. The method of claim 8 , wherein determining the second authentication result comprises determining whether the user device is within a pre-defined geographic border.

12. The method of claim 8 , wherein determining the second authentication result comprises determining whether the location of the user device corresponds to a geographic identifier associated with the user device.

13. The method of claim 8 , further comprising:

authenticating, via the authentication server, the user device.

14. The method of claim 13 , wherein determining the second authentication result is further based on an authentication result of authenticating the user device.

15. One or more computer-readable non-transitory storage media embodying instructions that, when executed by a processor, cause performance of operations comprising:

transmitting, to a multi-factor authentication (MFA) agent running on a user device, a request for a location of the user device;

receiving, from the MFA agent, the location of the user device, wherein the location is determined by the MFA agent to be a most common location indicated by a plurality of location indicators;

receiving, from a policy server, a location-based access policy;

appending, to the location-based access policy, the location of the user device; and

in response to appending the location of the user device to the location-based access policy, storing the location-based access policy;

receiving a first authentication result from an authentication server; and

determining, based on the location of the user device, the first authentication result, and the location-based access policy, a second authentication result, wherein the second authentication result indicates whether to allow the user device to access one or more of:

a remote service,

a remote database, and

a remote device.

16. The one or more computer-readable non-transitory storage media of claim 15 , wherein the plurality of location indicators are generated by a plurality of location information sources including one or more of:

a Global Positioning System (GPS),

a cellular location provider, and

an other location provider.

17. The one or more computer-readable non-transitory storage media of claim 15 , wherein the policy server is distributed using a plurality of policy server instances.

18. The one or more computer-readable non-transitory storage media of claim 15 , wherein determining the second authentication result comprises determining one or more of:

whether the user device is within a pre-defined geographic border; and

whether the location of the user device corresponds to a geographic identifier associated with the user device.

19. The one or more computer-readable non-transitory storage media of claim 15 , further comprising:

authenticating, via the authentication server, the user device.

20. The one or more computer-readable non-transitory storage media of claim 19 , wherein determining the second authentication result is further based on an authentication result of authenticating the user device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 12, 2022
From: M M, NIRANJAN; KENCHAIAH, NAGARAJ
To: CISCO TECHNOLOGY, INC.
Reel/Frame 061061/0364 →
Continuity (1)
Related Publication 20240089290A1 · Mar 14, 2024
References Cited (9)
US 10237070B2 · Lindemann · 2019 [cited by examiner]
US 20160224799A1 · Uzun et al. · 2016 [cited by applicant]
US 20180083943A1 · Bowman · 2018 [cited by examiner]
US 20180109945A1 · Kweon et al. · 2018 [cited by applicant]
US 20210360401A1 · Marinho et al. · 2021 [cited by applicant]
CA 2915570A1 · 2014 [cited by examiner]
CA 3025198A1 · 2017 [cited by examiner]
Borcoci, Eugen & Ambarus, Tudor & Bruneau-Queyreix, Joachim & Negru, Daniel & Batalla, Jordi. (2016). Optimization of Multi-server Video Content Streaming in 5G Environment. Download citation of Optimization of Multi-se… [cited by applicant]
Tomasin, Stefano, Marco Centenaro, Gonzalo Seco-Granados, Stefan Roth, and Aydin Sezgin. 2021. “Location-Privacy Leakage and Integrated Solutions for 5G Cellular Networks and Beyond” Sensors21, No. 15: 5176. https://doi… [cited by applicant]