IP Library Granted Patent US 12,418,516
Granted Patent B2
US 12,418,516 · App. 18/528,014 · Granted Sep 16, 2025

Encryption-based device enrollment

Inventor: Karan Lyons (Los Angeles, CA)
Assignee: Zoom Communications, Inc.
H04L63/0442H04L9/3242H04L9/3247H04L63/102
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,418,516
App. No.
18/528,014
Granted
Sep 16, 2025
Kind
B2
Abstract

One example method includes a device management system detecting an attempt to access a user account by an unenrolled device. The device management system identifies a first enrolled device of the user account by accessing a signature chain of the user account. The device management system facilitates a transmission of a cryptographically-signed enrollment request from the unenrolled device to the first enrolled device. The first enrolled device is configured to cryptographically validate the enrollment request. The first enrolled device is further configured to generate an encrypted attestation message that indicates that the unenrolled device has been authenticated. The unenrolled device can receive and decrypt the encrypted attestation message based on a passcode being displayed on the first enrolled device. The device management system receives a decrypted attestation message from the unenrolled device and updates the signature chain to include a new sequential record for the unenrolled device.

Claims (43)

1. A method comprising:

detecting an attempt to access a user account by an unenrolled device;

identifying a first enrolled device corresponding to the user account based on a signature chain of the user account;

facilitating transmission of an enrollment request and a corresponding cryptographic signature from the unenrolled device to the first enrolled device;

receiving a decrypted attestation message from the unenrolled device, wherein the decrypted attestation message is generated based on decrypting an encrypted attestation message transmitted by the first enrolled device; and

updating, based on the decrypted attestation message, the signature chain to include a second record for the unenrolled device indicating the unenrolled device is enrolled.

2. The method of claim 1 , further comprising, after the updating the signature chain, providing access to the user account to the unenrolled device.

3. The method of claim 1 , further comprising determining an elapsed time based on a timestamp associated with the decrypted attestation message and a timestamp corresponding to receipt of the decrypted attestation message.

4. The method of claim 3 , wherein the updating the signature change is in response to the elapsed time satisfying a threshold value.

5. The method of claim 1 , wherein detecting the attempt to access the user account comprises receiving a username and password associated with the user account.

6. The method of claim 1 , further comprising:

restricting the enrolled device to perform one or more user-account operations for a predetermined period of time.

7. The method of claim 6 , wherein the one or more user-account operations being restricted include enrolling additional unenrolled devices or de-enrolling the first enrolled device.

8. The method of claim 1 , wherein:

the enrollment request further includes a reported location of the unenrolled device; and

wherein the first enrolled device is configured to authenticate the enrollment request by comparing the reported location of the unenrolled device and an estimated location of the unenrolled device, wherein the estimated location is estimated based on an Internet Protocol address from which the enrollment request was transmitted.

9. A system comprising:

a communications interface;

a non-transitory computer-readable medium; and

one or more processors communicatively coupled to the communications interface and the non-transitory computer-readable medium, the one or more processors configured to execute processor-executable instructions stored in the non-transitory computer-readable medium to:

detect an attempt to access a user account by an unenrolled device;

identify a first enrolled device corresponding to the user account based on a signature chain of the user account;

facilitate transmission of an enrollment request and a corresponding cryptographic signature from the unenrolled device to the first enrolled device;

receive a decrypted attestation message from the unenrolled device, wherein the decrypted attestation message is generated based on decrypting an encrypted attestation message transmitted by the first enrolled device; and

update, based on the decrypted attestation message, the signature chain to include a second record for the unenrolled device indicating the unenrolled device is enrolled.

10. The system of claim 9 , wherein the one or more processors are configured to execute further processor-executable instructions stored in the non-transitory computer-readable medium to, after the updating the signature chain, provide access to the user account to the unenrolled device.

11. The system of claim 9 , wherein the one or more processors are configured to execute further processor-executable instructions stored in the non-transitory computer-readable medium to determine an elapsed time based on a timestamp associated with the decrypted attestation message and a timestamp corresponding to receipt of the decrypted attestation message.

12. The system of claim 11 , wherein the updating the signature change is in response to the elapsed time satisfying a threshold value.

13. The system of claim 9 , wherein the one or more processors are configured to execute further processor-executable instructions stored in the non-transitory computer-readable medium to receive a username and password associated with the user account.

14. The system of claim 9 , wherein the one or more processors are configured to execute further processor-executable instructions stored in the non-transitory computer-readable medium to restrict the enrolled device to perform one or more user-account operations for a predetermined period of time.

15. The system of claim 14 , wherein the one or more user-account operations being restricted include enrolling additional unenrolled devices and/or de-enrolling the first enrolled device.

16. The system of claim 9 , wherein:

the enrollment request further includes a reported location of the unenrolled device; and

wherein the first enrolled device is configured to authenticate the enrollment request by comparing the reported location of the unenrolled device and an estimated location of the unenrolled device, wherein the estimated location is estimated based on an Internet Protocol address from which the enrollment request was transmitted.

17. A non-transitory computer-readable medium comprising processor-executable instructions configured to cause one or more processors to:

detect an attempt to access a user account by an unenrolled device;

identify a first enrolled device corresponding to the user account based on a signature chain of the user account;

facilitate transmission of an enrollment request and a corresponding cryptographic signature from the unenrolled device to the first enrolled device;

receive a decrypted attestation message from the unenrolled device, wherein the decrypted attestation message is generated based on decrypting an encrypted attestation message transmitted by the first enrolled device; and

update, based on the decrypted attestation message, the signature chain to include a second record for the unenrolled device indicating the unenrolled device is enrolled.

18. The non-transitory computer-readable medium of claim 17 , further comprising processor-executable instructions configured to cause the one or more processors to determine an elapsed time based on a timestamp associated with the decrypted attestation message and a timestamp corresponding to receipt of the decrypted attestation message.

19. The non-transitory computer-readable medium of claim 18 , wherein the updating the signature change is in response to the elapsed time satisfying a threshold value.

20. The non-transitory computer-readable medium of claim 17 , further comprising processor-executable instructions configured to cause the one or more processors to restrict the enrolled device to perform one or more user-account operations for a predetermined period of time.

Assignments (2)
CHANGE OF NAME Recorded Aug 14, 2025
From: ZOOM VIDEO COMMUNICATIONS, INC.
To: ZOOM COMMUNICATIONS, INC.
Reel/Frame 072486/0632 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 5, 2023
From: LYONS, KARAN
To: ZOOM VIDEO COMMUNICATIONS, INC.
Reel/Frame 065760/0001 →
Continuity (2)
Continuation 17390663 · Jul 30, 2021
Related Publication 20240106808A1 · Mar 28, 2024
References Cited (23)
US 9867043B2 · Aissi · 2018 [cited by examiner]
US 9935953B1 · Costigan · 2018 [cited by examiner]
US 9996684B2 · Hoyos et al. · 2018 [cited by applicant]
US 10454674B1 · Bar-El · 2019 [cited by examiner]
US 11356257B2 · Law · 2022 [cited by applicant]
US 11863539B2 · Lyons · 2024 [cited by applicant]
US 20140066015A1 · Aissi · 2014 [cited by applicant]
US 20160210169A1 · Kaufman · 2016 [cited by examiner]
US 20160285873A1 · Lambert · 2016 [cited by examiner]
US 20170063846A1 · Mohamad Abdul et al. · 2017 [cited by applicant]
US 20180109418A1 · Cammarota et al. · 2018 [cited by applicant]
US 20180254898A1 · Sprague · 2018 [cited by examiner]
US 20190116038A1 · Sprague · 2019 [cited by examiner]
US 20190140828A1 · Wheeler · 2019 [cited by examiner]
US 20190347384A1 · Smith · 2019 [cited by applicant]
US 20200007530A1 · Mohamad Abdul et al. · 2020 [cited by applicant]
US 20210320805A1 · Shockley · 2021 [cited by examiner]
WO WO2014036021A1 · 2014 [cited by examiner]
WO 2016118542A1 · 2016 [cited by applicant]
WO 2020263938A1 · 2020 [cited by applicant]
U.S. Appl. No. 17/390,663 , “Notice of Allowance”, Jul. 6, 2023, 14 pages. [cited by applicant]
International Application No. PCT/US2022/033943 , “International Preliminary Report on Patentability”, Feb. 8, 2024, 15 pages. [cited by applicant]
International Application No. PCT/US2022/033943 , “International Search Report and Written Opinion”, Sep. 15, 2022, 19 pages. [cited by applicant]