IP Library › Granted Patent US 12,519,764
Granted Patent B2
US 12,519,764 · App. 18/334,158 · Granted Jan 6, 2026

Systems and methods for device connectivity-based authentication

Inventors: Shuvam Sengupta (Kolkata, IN); Justin Christopher Blackburn (Litchfield Park, AZ); Ashutosh Verma (Bangalore, IN); Rameshchandra Bhaskar Ketharaju (Hyderabad, IN)
Assignee: Wells Fargo Bank, N.A.
H04L63/08H04L2463/082
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,519,764
App. No.
18/334,158
Granted
Jan 6, 2026
Kind
B2
Abstract

Systems, apparatuses, methods, and computer program products are disclosed for device connectivity-based authentication. An example method includes receiving, from a first device, an authorization request associated with a first action. The example method also includes receiving a current connectivity dataset from the first device which indicates one or more devices detected by the first device to be in communication with the first device. The example method also includes comparing the current connectivity dataset with a reference connectivity dataset. The example method also includes determining, based on the comparison, whether the current connectivity dataset and the reference connectivity dataset satisfy a predefined similarity threshold. The example method also includes authorizing, in an instance in which the current connectivity dataset and the reference connectivity dataset satisfy the predefined similarity threshold, the first device to perform the first action.

Claims (58)

1 . A method comprising:

prior to receiving a current connectivity dataset from a first device, generating, by a location modeling engine, a reference connectivity dataset based on a plurality of current connectivity datasets received during a plurality of instances by respective devices of a plurality of devices at a first location, wherein generating the reference connectivity dataset comprises:

clustering, by the location modeling engine, data points representing devices included in the plurality of current connectivity datasets, wherein the devices included in the plurality of current connectivity datasets are devices that are detected by the devices of a plurality of devices to be in communication with the devices at the first location,

identifying, by the location modeling engine and based on the clustering, at least a portion of the devices as being representative of the first location, and

populating, by the location modeling engine, the reference connectivity dataset with the identified devices:

receiving, by communications hardware and from the first device, an authorization request associated with a first action;

receiving, by the communications hardware, the current connectivity dataset from the first device, wherein the current connectivity dataset indicates one or more devices detected by the first device to be in communication with the first device;

comparing, by an authentication engine, the current connectivity dataset with the reference connectivity dataset;

determining, by the authentication engine and based on the comparison, whether the current connectivity dataset and the reference connectivity dataset satisfy a predefined similarity threshold; and

in an instance in which the current connectivity dataset and the reference connectivity dataset satisfy the predefined similarity threshold:

authorizing, by the authentication engine, the first device to perform the first action.

2 . The method of claim 1 , further comprising:

in an instance in which the current connectivity dataset and the reference connectivity dataset fail to satisfy the predefined similarity threshold:

preventing, by the authentication engine, the first device from performing the first action.

3 . The method of claim 1 , wherein the current connectivity dataset further indicates a current location of the first device, and wherein the method further comprises:

selecting, by the authentication engine, the reference connectivity dataset from a plurality of reference connectivity datasets based at least on the current location of the first device.

4 . The method of claim 1 , further comprising:

receiving, by the communications hardware, at least one ancillary authorization factor; and

verifying, by the authentication engine, the at least one ancillary authorization factor, wherein the authorization of authorizing the first device to perform the first action is based further on a successful verification of the at least one ancillary authorization factor.

5 . The method of claim 4 , wherein the at least one ancillary authorization factor comprises a biometric scan factor.

6 . The method of claim 1 , further comprising:

selecting, by an optimization engine and based on the current connectivity dataset, at least one device from the one or more devices detected by the first device; and

facilitating, by the communications hardware, a data transfer to a second device via the at least one device.

7 . The method of claim 6 , wherein the at least one device is selected to be a node of an optimal communication path for the data transfer to the second device.

8 . The method of claim 1 , wherein comparing the current connectivity dataset with the reference connectivity dataset comprises:

comparing, by the authentication engine, characteristics of the one or more devices indicated in the current connectivity dataset with characteristics of the one or more devices indicated in the reference connectivity dataset.

9 . The method of claim 8 , wherein the characteristics comprise at least one of:

(i) one or more device identifying characteristics, and

(ii) one or more communication characteristics.

10 . The method of claim 9 , wherein the one or more device identifying characteristics comprise one or more of an internet protocol (IP) address, a Media Access Control (MAC) address, a network name, and a device type.

11 . The method of claim 9 , wherein the one or more communication characteristics comprise one or more of packet loss, connection type, bandwidth, latency, jitter, and security.

12 . The method of claim 1 , further comprising:

causing transmission, by the communications hardware, of a current connectivity dataset request to the first device, wherein the current connectivity dataset is received in response to the current connectivity dataset request.

13 . The method of claim 12 , wherein the current connectivity dataset request is transmitted as part of a re-challenge authentication procedure for an authenticated session with the first device.

14 . An apparatus comprising:

a location modeling engine configured to:

prior to receiving the current connectivity dataset from a first device, generate a reference connectivity dataset based on a plurality of current connectivity datasets received during a plurality of instances by respective devices of a plurality of devices at a first location, wherein the location modeling engine generates the reference connectivity dataset by:

clustering data points representing devices included in the plurality of current connectivity datasets, wherein the devices included in the plurality of current connectivity datasets are devices that are detected by the devices of a plurality of devices to be in communication with the devices at the first location, identifying, based on the clustering, at least a portion of the devices as being representative of the first location, and populating the reference connectivity dataset with the identified devices:

communications hardware configured to:

receive, from the first device, an authorization request associated with a first action, and receive the current connectivity dataset from the first device, wherein the current connectivity dataset indicates one or more devices detected by the first device to be in communication with the first device; and an authentication engine configured to:

compare the current connectivity dataset with the reference connectivity dataset, determine, based on the comparison, whether the current connectivity dataset and the reference connectivity dataset satisfy a predefined similarity threshold, and in an instance in which the current connectivity dataset and the reference connectivity dataset satisfy the predefined similarity threshold:

authorize the first device to perform the first action.

15 . The apparatus of claim 14 , wherein the authentication engine is further configured to, in an instance in which the current connectivity dataset and the reference connectivity dataset fail to satisfy the predefined similarity threshold:

prevent the first device from performing the first action.

16 . The apparatus of claim 14 , further comprising an optimization engine configured to select, based on the current connectivity dataset, at least one device from the one or more devices detected by the first device; and

wherein the communications hardware is further configured to facilitate a data transfer to a second device via the at least one device.

17 . The apparatus of claim 16 , wherein the optimization engine selects the at least one device to be a node of an optimal communication path for the data transfer to the second device.

18 . The apparatus of claim 14 , wherein the authentication engine compares the current connectivity dataset with the reference connectivity dataset by:

comparing characteristics of the one or more devices indicated in the current connectivity dataset with characteristics of the one or more devices indicated in the reference connectivity dataset.

19 . The apparatus of claim 18 , wherein the characteristics comprise at least one of:

(i) one or more device identifying characteristics, and

(ii) one or more communication characteristics.

20 . A computer program product comprising at least one non-transitory computer-readable storage medium storing software instructions that, when executed, cause an apparatus to:

prior to receiving a current connectivity dataset from a first device, generate a reference connectivity dataset based on a plurality of current connectivity datasets received during a plurality of instances by respective devices of a plurality of devices at a first location, wherein generating the reference connectivity dataset comprises: clustering data points representing devices included in the plurality of current connectivity datasets, wherein the devices included in the plurality of current connectivity datasets are devices that are detected by the devices of a plurality of devices to be in communication with the devices at the first location, identifying, based on the clustering, at least a portion of the devices as being representative of the first location, and populating the reference connectivity dataset with the identified devices:

receive, from the first device, an authorization request associated with a first action;

receive the current connectivity dataset from the first device, wherein the current connectivity dataset indicates one or more devices detected by the first device to be in communication with the first device;

compare the current connectivity dataset with the reference connectivity dataset; determine, based on the comparison, whether the current connectivity dataset and the reference connectivity dataset satisfy a predefined similarity threshold; and

in an instance in which the current connectivity dataset and the reference connectivity dataset satisfy the predefined similarity threshold: authorize the first device to perform the first action.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 3, 2023
From: SENGUPTA, SHUVAM; BLACKBURN, JUSTIN CHRISTOPHER; VERMA, ASHUTOSH; KETHARAJU, RAMESHCHANDRA BHASKAR
To: WELLS FARGO BANK, N.A.
Reel/Frame 064139/0729 →
Continuity (1)
Related Publication 20240422146A1 · Dec 19, 2024
References Cited (9)
US 8407765B2 · Wiley · 2013 [cited by examiner]
US 10742647B2 · Crabtree et al. · 2020 [cited by applicant]
US 20090254975A1 · Turnbull · 2009 [cited by examiner]
US 20130055346A1 · Singh · 2013 [cited by examiner]
US 20180225592A1 · Ponnuswamy · 2018 [cited by examiner]
US 20250005383A1 · Sharpe · 2025 [cited by examiner]
US 20250217334A1 · Khan · 2025 [cited by examiner]
Fegzhan, Aon Kondoro, Sead Muftc, Location-based Authentication and Authorization Using Smart Phones, School of Information and Communication Technology, Stockholm, Sweden. [cited by applicant]
Markus Miettinen, Thien Duc Nguyen, Ahmad-Rez Sadeghi, N. Asokan, Revisiting Context-Based Authentication in IoT, Proceedings of the 55th Annual Design Automation Conference, Apr. 24, 2018. [cited by applicant]