IP Library › Granted Patent US 12,407,531
Granted Patent B2
US 12,407,531 · App. 18/424,361 · Granted Sep 2, 2025

Transparent short-range wireless device factor in a multi-factor authentication system

Inventors: Stephen Woodward Lind (El Cerrito, CA); Bidan Sinha (Milpitas, CA); Karthik Bhat (Saratoga, CA); Naveen Kumar Keerthy (San Jose, CA); Jintai He (San Mateo, CA); Kavitha Chandramohan (Maple, CA)
H04L9/3273H04W12/0431H04W12/069H04W12/63H04W4/80
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,407,531
App. No.
18/424,361
Granted
Sep 2, 2025
Kind
B2
Abstract

An authentication system supports multi-factor authentication (MFA) when authenticating the identity of a user. A challenge-response portion of the authentication process is delegated to an MFA device-a secondary device within control of the user, but separate from the primary login device that the user is using when initiating the authentication. Communications between the MFA device and the login device are conducted using a short-range wireless communication protocol (e.g., Bluetooth™ or NFC), so that the two devices must be in close physical proximity to each other.

Claims (41)

1. A computer-implemented method for secure, automated multi-factor authentication (MFA) login to a resource performed by an MFA device, the computer-implemented method comprising:

enrolling with an authentication system, the enrolling comprising:

pairing with a login device to establish data for an encrypted communication channel between the MFA device and the login device over a short-range wireless connection;

providing, to the authentication system, a public key of the MFA device and metadata describing the MFA device;

receiving, over the short-range wireless connection, authentication challenge metadata sent to the login device by the authentication system in response to a request by the login device to access a resource for which authentication is required;

generating MFA metadata to establish that the MFA device shares a physical presence with the login device; and

sending the MFA metadata to the authentication system, wherein responsive to verifying the MFA metadata using the metadata provided to the authentication system during the enrolling, the authentication system authenticates the login device.

2. The computer-implemented method of claim 1 , wherein the metadata describing the MFA device comprises at least one of: an operating system ID of the MFA device, or network information of the MFA device.

3. The computer-implemented method of claim 1 , wherein the short-range wireless connection comprises a BLUETOOTH connection or a near-field communication (NFC) connection.

4. The computer-implemented method of claim 1 , further comprising:

verifying a signature of the authentication system on the authentication challenge metadata.

5. The computer-implemented method of claim 1 , further comprising:

determining an answer to a challenge of the authentication challenge metadata by decrypting a nonce value using a private key corresponding to the public key of the MFA device.

6. The computer-implemented method of claim 5 , wherein the authentication system authenticates the login device, wherein the authentication comprises verifying at least one of: the answer to the challenge, or the MFA metadata using the metadata describing the MFA device.

7. The computer-implemented method of claim 1 , wherein the MFA metadata comprises an indicator of a physical distance of the MFA device from the login device.

8. The computer-implemented method of claim 7 , wherein the indicator of the physical distance is computed based on a signal strength of the short-range wireless connection when received from the login device the MFA device.

9. The computer-implemented method of claim 1 , wherein the receiving, the generating, and the sending are performed by the MFA device without manual input from a user.

10. A computer-implemented method for secure, automated multi-factor authentication (MFA) login to a resource performed by an authentication system, the computer-implemented method comprising:

enrolling an MFA device, the enrolling comprising:

pairing the MFA device with a login device to establish data for an encrypted communication channel between the MFA device and the login device over a short-range wireless connection;

obtaining, from the MFA device, a public key of the MFA device, and metadata describing the MFA device;

receiving, on behalf of a user from the login device, a request for authentication;

sending, over the short-range wireless connection, authentication challenge metadata to the login device;

receiving, from the MFA device, MFA metadata in response to sending the authentication challenge metadata to the login device;

verifying, using the received MFA metadata, that the MFA device is within a threshold distance of the login device; and

issuing an authentication token for the login device.

11. The computer-implemented method of claim 10 , wherein the authentication challenge metadata further comprises a nonce value generated by the authentication system and encrypted using the public key of the MFA device.

12. The computer-implemented method of claim 10 , wherein the MFA metadata comprises an indicator of a physical distance of the MFA device from the login device.

13. The computer-implemented method of claim 12 , wherein the indicator of the physical distance is computed based on a signal strength of the short-range wireless connection when received from the login device the MFA device.

14. A multi-factor authentication (MFA) device comprising at least one memory that stores code and one or more processors coupled with the at least one memory, wherein the one or more processors are operable to execute the code to cause the MFA device to login to a resource, the login comprising:

enrolling with an authentication system, the enrolling comprising:

pairing with a login device to establish data for an encrypted communication channel between the MFA device and the login device over a short-range wireless connection;

providing, to the authentication system, a public key of the MFA device and metadata describing the MFA device;

receiving, over the short-range wireless connection, authentication challenge metadata sent to the login device by the authentication system in response to a request by the login device to access a resource for which authentication is required;

generating MFA metadata to establish that the MFA device shares a physical presence with the login device; and

sending the MFA metadata to the authentication system, wherein responsive to verifying the MFA metadata using the metadata provided to the authentication system during the enrolling, the authentication system authenticates the login device.

15. The MFA device of claim 14 , wherein the metadata describing the MFA device comprises at least one of: an operating system ID of the MFA device, or network information of the MFA device.

16. The MFA device of claim 14 , wherein the short-range wireless connection comprises a BLUETOOTH connection or a near-field communication (NFC) connection.

17. The MFA device of claim 14 , wherein the MFA metadata comprises an indicator of a physical distance of the MFA device from the login device.

18. The MFA device of claim 17 , wherein the indicator of the physical distance is computed based on a signal strength of the short-range wireless connection when received from the login device the MFA device.

19. The MFA device of claim 14 , wherein the authentication system authenticates the login device, wherein the authentication comprises verifying at least one of: an answer to a challenge of the authentication challenge metadata, or the MFA metadata using the metadata describing the MFA device.

Continuity (2)
Continuation 17589719 · Jan 31, 2022
Related Publication 20240163117A1 · May 16, 2024
References Cited (9)
US 9398012B2 · Neuman · 2016 [cited by examiner]
US 11917087B2 · Lind et al. · 2024 [cited by applicant]
US 20190386981A1 · Ramesh Kumar · 2019 [cited by examiner]
Kensington, “VeriMark(Trademark) Fingerprint Key—FIDO U2F for Universal 2nd Factor Authentication & Windows Hello(Trademark) SKU: K67977WW,” Date Unknown, five pages, [Online] [Retrieved on Oct. 20, 2022] Retrieved from… [cited by applicant]
Saaspass, “Move Beyond Passwords with The Only Full-Stack Identity & Access Management Solution,” 2021, 23 pages, [Online]] [Retrieved on Oct. 20, 2022] Retrieved from the Internet <URL: https://saaspass.com/>. [cited by applicant]
Symantec, “Symantec VIP—Two Factor Authentication Anywhere,” Date Unknown, six pages, [Online] [Retrieved on Oct. 20, 20221 Retrieved from the Internet <URL: https://vip.symantec.com/>. [cited by applicant]
Wikipedia, “FIDO Alliance,” Jan. 21, 2021, four pages, [Online] [Retrieved on Oct. 20, 2022] Retrieved from the Internet <URL: https://en.wikipedia.org/w/index.php?title=FIDO Alliance&oldid=1001844970>. [cited by applicant]
Wikipedia, “Titan Security Key,” Jun. 30, 2022, two pages, [Online] [Retrieved on Oct. 20, 2022] Retrieved from the Internet <URL: https://en.wikipedia.org/wiki/Titan_Security_Key>. [cited by applicant]
Wikipedia, “YubiKey,” Jan. 14, 2021, eight pages, [Online] [Retrieved on Oct. 20, 2022] Retrieved from the Internet <URL: https://en.wikipedia.org/w/index.php?title=YubiKey&oldid=1000388024>. [cited by applicant]