IP Library Granted Patent US 12,477,331
Granted Patent B2
US 12,477,331 · App. 18/319,400 · Granted Nov 18, 2025

Continuous multi-factor authentication using wireless sensing data

Inventors: Indermeet Singh Gandhi (San Jose, CA); Frank Michaud (Pully, VA); Jerome Henry (Pittsboro, NC); David A. Maluf (Mountain View, CA)
Assignee: Cisco Technology, Inc.
H04W12/06H04L63/20H04L2463/082
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,477,331
App. No.
18/319,400
Granted
Nov 18, 2025
Kind
B2
Abstract

A method of continuous multi-factor authentication may include executing wireless sensing based at least in part on execution of a continuous multi-factor authentication (CMFA) application at a computing device, collecting channel state information (CSI) data from a network device communicatively coupled to the computing device, transmitting the CSI data to a CMFA device, and receiving a trust score from the CMFA device based on the CSI data.

Claims (45)

1 . A non-transitory computer-readable medium storing instructions that, when executed, causes a processor to perform operations, comprising:

determining, by a network device, to perform wireless sensing based at least in part on a continuous multi-factor authentication (CMFA) application executing on a computing device;

collecting, at the network device, channel state information (CSI) data associated with a connection between the network device and the computing device, the CSI data including an indication of static objects and non-static objects in an environment of the computing device;

transmitting the CSI data to a CMFA device; and

receiving a trust score from the CMFA device, the trust score being determined by the CMFA device based at least in part on the non-static objects indicated by the CSI data.

2 . The non-transitory computer-readable medium of claim 1 , the operations further comprising:

detecting a change in the CSI data; and

receiving an updated trust score from the CMFA device, the updated trust score being determined based at least in part on the change in the CSI data.

3 . The non-transitory computer-readable medium of claim 2 , the operations further comprising adjusting access via the computing device to at least one resource provided to the computing device based at least in part on the updated trust score.

4 . The non-transitory computer-readable medium of claim 1 , the operations further comprising establishing, by the network device, baseline CSI data.

5 . The non-transitory computer-readable medium of claim 1 , the operations further comprising adjusting access to the computing device based at least in part on the trust score.

6 . The non-transitory computer-readable medium of claim 1 , the operations further comprising adjusting access via the computing device to at least one resource provided to the computing device based at least in part on the trust score.

7 . The non-transitory computer-readable medium of claim 1 , wherein the collecting of the CSI data at the network device comprises collecting the CSI data associated with a connection between a plurality of network devices and the computing device.

8 . The non-transitory computer-readable medium of claim 1 , wherein the CSI data comprises:

long cycles defining the static objects within the environment of the computing device; and

short cycles defining the non-static objects within the environment of the computing device.

9 . A system comprising:

a processor; and

a non-transitory computer-readable media storing instructions that, when executed by the processor, causes the processor to perform operations comprising:

determining, by a network device, to perform wireless sensing based at least in part on a continuous multi-factor authentication (CMFA) application executing on a computing device;

collecting, at the network device, channel state information (CSI) data associated with a connection between the network device and the computing device, the CSI data including an indication of static objects and non-static objects in an environment of the computing device;

transmitting the CSI data to a CMFA device; and

receiving a trust score from the CMFA device, the trust score being determined by the CMFA device based at least in part on the non-static objects indicated by the CSI data.

10 . The system of claim 9 , the operations further comprising:

detecting a change in the CSI data; and

receiving an updated trust score from the CMFA device, the updated trust score being determined based at least in part on the change in the CSI data.

11 . The system of claim 10 , the operations further comprising adjusting access via the computing device to at least one resource provided to the computing device based at least in part on the updated trust score.

12 . The system of claim 9 , the operations further comprising establishing, by the network device, baseline CSI data.

13 . The system of claim 9 , the operations further comprising adjusting access to the computing device based at least in part on the trust score.

14 . The system of claim 9 , the operations further comprising adjusting access via the computing device to at least one resource provided to the computing device based at least in part on the trust score.

15 . The system of claim 9 , wherein the collecting of the CSI data at the network device comprises collecting the CSI data associated with a connection between a plurality of network devices and the computing device.

16 . The system of claim 9 , wherein the CSI data comprises:

long cycles defining the static objects within the environment of the computing device; and

short cycles defining the non-static objects within the environment of the computing device.

17 . A method of continuous multi-factor authentication, comprising:

determining, by a network device, to perform wireless sensing based at least in part on a continuous multi-factor authentication (CMFA) application executing on a computing device;

collecting, at the network device, channel state information (CSI) data associated with a connection between the network device and communicatively coupled to the computing device, the CSI data including an indication of static objects and non-static objects in an environment of the computing device;

transmitting the CSI data to a CMFA device; and

receiving a trust score from the CMFA device, the trust score being determined by the CMFA device based at least in part on the non-static objects indicated by the CSI data.

18 . The method of claim 17 , further comprising:

detecting a change in the CSI data;

receiving an updated trust score from the CMFA device, the updated trust score being determined based at least in part on the change in the CSI data; and

adjusting access via the computing device to at least one resource provided to the computing device based at least in part on the updated trust score.

19 . The method of claim 17 , further comprising adjusting access to the computing device based at least in part on the trust score.

20 . The method of claim 17 , further comprising adjusting access via the computing device to at least one resource provided to the computing device based at least in part on the trust score.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 18, 2023
From: GANDHI, INDERMEET SINGH; MICHAUD, FRANK; HENRY, JEROME; MALUF, DAVID A.
To: CISCO TECHNOLOGY, INC.
Reel/Frame 063692/0850 →
Continuity (1)
Related Publication 20240388901A1 · Nov 21, 2024
References Cited (11)
US 20150242605A1 · Du et al. · 2015 [cited by applicant]
US 20200092314A1 · Mital · 2020 [cited by examiner]
US 20200322330A1 · Lynn et al. · 2020 [cited by applicant]
US 20210224374A1 · Fong et al. · 2021 [cited by applicant]
US 20220070178A1 · Lee · 2022 [cited by examiner]
US 20220078610A1 · Montemurro et al. · 2022 [cited by applicant]
US 20220255942A1 · Szigeti et al. · 2022 [cited by applicant]
US 20230065765A1 · Vadlamani · 2023 [cited by examiner]
Shah et al, Towards a Lightweight Continuous Authentication Protocol for Device-to-Device Communication, IEEE, Jan. 29, 2021, pp. 1119-1126. (Year: 2021). [cited by examiner]
Wang et al, Deep Neural Networks for CSI-Based Authentication, IEEE, Aug. 30, 2019, pp. 123034-123026. (Year: 2019). [cited by examiner]
Du et al., “An Overview on IEEE 802.11bf: WLAN Sensing,” arXiv:2207.04859v1, Jul. 11, 2022, downloaded from https://arxiv.org/pdf/2207.04859.pdf, 23 pages. [cited by applicant]