IP Library › Granted Patent US 12,425,851
Granted Patent B2
US 12,425,851 · App. 18/122,942 · Granted Sep 23, 2025

Anchored Wi-Fi fingerprinting for risk-based authentication

Inventors: Vishal Satyendra Desai (San Jose, CA); Shayne Miel (Durham, NC); Ardalan Alizadeh (Milpitas, CA)
Assignee: Cisco Technology, Inc.
H04W12/06H04W12/79H04W84/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,425,851
App. No.
18/122,942
Granted
Sep 23, 2025
Kind
B2
Abstract

This disclosure describes techniques for using an anchored endpoint to enhance MFA authentication of a client device. A method performed at least in part by a security service includes authenticating of a client device connecting to a secure resource. The method also includes determining a first Wi-Fi fingerprint of the client device, determining that the client device is within a threshold proximity to an anchor device, and determining a second Wi-Fi fingerprint of the anchor device. The method also includes detecting a change to the first Wi-Fi fingerprint of the client device and determining that the second Wi-Fi fingerprint of the anchor device has not changed. The method also includes determining whether the client device is within the threshold proximity of the anchor device, if it is, access to the secured resource continues to be allowed, if it is not, a reauthentication of the client device is triggered.

Claims (67)

1. A method performed at least in part by a security service, the method comprising:

performing an authentication of a client device connecting to a secure resource;

determining a first Wi-Fi fingerprint of the client device;

determining that the client device is within a threshold proximity to an anchor device;

determining a second Wi-Fi fingerprint of the anchor device;

detecting a change to the first Wi-Fi fingerprint of the client device;

determining that the second Wi-Fi fingerprint of the anchor device has not changed;

determining whether the client device is within the threshold proximity of the anchor device;

in response to the client device being within the threshold proximity of the anchor device, continuing to allow access to the secured resource; and

in response to the client device not being within the threshold proximity of the anchor device, triggering a reauthentication of the client device.

2. The method of claim 1 , wherein determining whether the client device is within the threshold proximity of the anchor device further comprises receiving, from the client device, Bluetooth pairing information including an indication that the client device and the anchor device are paired.

3. The method of claim 1 , further comprising determining whether the client device is at a trusted location based at least in part on historical Wi-Fi associations including WLAN name, BSSID, and signal range.

4. The method of claim 1 , further comprising:

determining the client device is within the threshold proximity of a second anchor device;

determining a third Wi-Fi fingerprint of the second anchor device;

detecting the change to the first Wi-Fi fingerprint of the client device; determining that the third Wi-Fi fingerprint of the second anchor device has not changed;

determining whether the client device is within the threshold proximity of at least one of the first anchor device or the second anchor device;

in response to the client device being within the threshold proximity of at least one of the first anchor device of the second anchor device, continuing to allow access to the secured resource; and

in response to the to the client device not being within the threshold proximity of at least one of the first anchor device or the second the second anchor device, triggering a reauthentication of the client device.

5. The method of claim 1 , wherein the anchor device is a stationary device associated with a video conferencing platform.

6. The method of claim 5 , further comprising periodically receiving, from the video conferencing platform, a WLAN map generated for the anchor device.

7. The method of claim 1 , further comprising storing the Wi-Fi fingerprint of the client device and the Wi-Fi fingerprint of the anchor device in a Wi-Fi fingerprint repository associated with the security service.

8. A system, comprising:

at least one processor; and

one or more non-transitory media storing instructions that, when executed by the system, cause the system to perform operations comprising:

performing an authentication of a client device connecting to a secure resource;

determining a first Wi-Fi fingerprint of the client device;

determining that the client device is within a threshold proximity to an anchor device;

determining a second Wi-Fi fingerprint of the anchor device;

detecting a change to the first Wi-Fi fingerprint of the client device;

determining that the second Wi-Fi fingerprint of the anchor device has not changed;

determining whether the client device is within the threshold proximity of the anchor device;

in response to the client device being within the threshold proximity of the anchor device, continuing to allow access to the secured resource; and

in response to the client device not being within the threshold proximity of the anchor device, triggering a reauthentication of the client device.

9. The system of claim 8 , wherein determining whether the client device is within the threshold proximity of the anchor device further comprises receiving, from the client device, Bluetooth pairing information including an indication that the client device and the anchor device are paired.

10. The system of claim 8 , the operations further comprising determining whether the client device is at a trusted location based at least in part on historical Wi-Fi associations including WLAN name, BSSID, and signal range.

11. The system of claim 8 , the operations further comprising:

determining the client device is within the threshold proximity of a second anchor device;

determining a third Wi-Fi fingerprint of the second anchor device;

detecting the change to the first Wi-Fi fingerprint of the client device; determining that the third Wi-Fi fingerprint of the second anchor device has not changed;

determining whether the client device is within the threshold proximity of at least one of the first anchor device or the second anchor device;

in response to the client device being within the threshold proximity of at least one of the first anchor device of the second anchor device, continuing to allow access to the secured resource; and

in response to the to the client device not being within the threshold proximity of at least one of the first anchor device or the second the second anchor device, triggering a reauthentication of the client device.

12. The system of claim 8 , wherein the anchor device is a stationary device associated with a video conferencing platform.

13. The system of claim 12 , the operations further comprising periodically receiving, from the video conferencing platform, a WLAN map generated for the anchor device.

14. The system of claim 8 , the operations further comprising, storing the Wi-Fi fingerprint of the client device and the Wi-Fi fingerprint of the anchor device in a Wi-Fi fingerprint repository associated with a security service.

15. One or more non-transitory computer-readable media storing instructions that, when executed, cause one or more processors to perform operations comprising:

performing an authentication of a client device connecting to a secure resource;

determining a first Wi-Fi fingerprint of the client device;

determining that the client device is within a threshold proximity to an anchor device;

determining a second Wi-Fi fingerprint of the anchor device;

detecting a change to the first Wi-Fi fingerprint of the client device;

determining that the second Wi-Fi fingerprint of the anchor device has not changed;

determining whether the client device is within the threshold proximity of the anchor device;

in response to the client device being within the threshold proximity of the anchor device, continuing to allow access to the secured resource; and

in response to the client device not being within the threshold proximity of the anchor device, triggering a reauthentication of the client device.

16. The one or more non-transitory computer-readable media of claim 15 , wherein determining whether the client device is within the threshold proximity of the anchor device further comprises receiving, from the client device, Bluetooth pairing information including an indication that the client device and the anchor device are paired.

17. The one or more non-transitory computer-readable media of claim 15 , the operations further comprising determining a location of the client device based at least in part on historical Wi-Fi associations including WLAN name, BSSID, and signal range.

18. The one or more non-transitory computer-readable media of claim 15 , the operations further comprising:

determining the client device is within the threshold proximity of a second anchor device;

determining a third Wi-Fi fingerprint of the second anchor device;

detecting the change to the first Wi-Fi fingerprint of the client device; determining that the third Wi-Fi fingerprint of the second anchor device has not changed;

determining whether the client device is within the threshold proximity of at least one of the first anchor device or the second anchor device;

in response to the client device being within the threshold proximity of at least one of the first anchor device of the second anchor device, continuing to allow access to the secured resource; and

in response to the to the client device not being within the threshold proximity of at least one of the first anchor device or the second the second anchor device, triggering a reauthentication of the client device.

19. The one or more non-transitory computer-readable media of claim 15 , wherein the anchor device is a stationary device associated with a video conferencing platform.

20. The one or more non-transitory computer-readable media of claim 15 , the operations further comprising storing the Wi-Fi fingerprint of the client device and the Wi-Fi fingerprint of the anchor device in a Wi-Fi fingerprint repository associated with a security service.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 17, 2023
From: DESAI, VISHAL SATYENDRA; MIEL, SHAYNE; ALIZADEH, ARDALAN
To: CISCO TECHNOLOGY, INC.
Reel/Frame 063018/0809 →
Continuity (1)
Related Publication 20240314554A1 · Sep 19, 2024
References Cited (11)
US 11184766B1 · Lord · 2021 [cited by examiner]
US 20150085725A1 · Estevez et al. · 2015 [cited by applicant]
US 20170006470A1 · Gupta · 2017 [cited by applicant]
US 20180241626A1 · Kumar et al. · 2018 [cited by applicant]
US 20180242137A1 · Gupta et al. · 2018 [cited by applicant]
US 20190364493A1 · Yu et al. · 2019 [cited by applicant]
US 20210274310A1 · Chen et al. · 2021 [cited by applicant]
US 20210400485A1 · Ergen et al. · 2021 [cited by applicant]
US 20220255913A1 · Zacks et al. · 2022 [cited by applicant]
US 20220255929A1 · Rafferty · 2022 [cited by examiner]
Search Report and Written Opinion for International Application No. PCT/US2024/019682, Dated May 21, 2024, 14 pages. [cited by applicant]