IP Library › Granted Patent US 12,542,685
Granted Patent B2
US 12,542,685 · App. 18/066,467 · Granted Feb 3, 2026

Systems and methods for securely transferring account information between devices

Inventors: Robert Jacob Linial Small (Ann Arbor, MI); Jordan David Neidlinger (Saline, MI); Benjamin Warren Freiband (Ann Arbor, MI); Aparna Ashok (Duvall, WA); Marshall Dean Anderson (Chicago, IL)
Assignee: Cisco Technology, Inc.
H04L9/3263H04L9/3236H04L2209/46
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,542,685
App. No.
18/066,467
Filed
Dec 15, 2022
Granted
Feb 3, 2026
Kind
B2
Art Unit
2493
USPC
713/156
Abstract

In one embodiment, a method includes scanning, by a first device, a code from a second device and determining, by the first device, information comprising a peer identifier and a first certificate hash using the code. The method also includes initiating, by the first device, a connection with the second device using the peer identifier and receiving, by the first device, a second certificate hash from the second device via the connection. The method further includes validating, by the first device, the second certificate hash using the first certificate hash, establishing a session with the second device, and transferring, by the first device, account information to the second device via the session.

Claims (79)

1 . A first device, comprising:

one or more processors; and

one or more computer-readable non-transitory storage media coupled to the one or more processors and comprising instructions that, when executed by the one or more processors, cause the first device to perform operations comprising:

scanning a code from a second device, wherein the code is generated by the second device in response to receiving a request to transfer account information from the second device to the first device;

determining information comprising a peer identifier and a first certificate hash using the code, wherein the first certificate hash is generated by the second device and the peer identifier is a verifiable link between a peer and its public cryptographic key;

initiating a connection with the second device using the peer identifier;

receiving a second certificate hash from the second device via the connection;

comparing the first certificate hash to the second certificate hash;

validating the second certificate hash using the first certificate hash;

establishing a session with the second device; and

transferring the account information to the second device via the session.

2 . The first device of claim 1 , wherein the code is a machine-readable image.

3 . The first device of claim 1 , wherein the connection is one of the following:

a Transport Layer Security (TLS) connection;

a Datagram Transport Layer Security (DTLS) connection; or

a Constrained Application Protocol (CoAP) connection.

4 . The first device of claim 1 , wherein the first certificate hash is generated by the second device by hashing a self-signed certificate.

5 . The first device of claim 1 , wherein:

an operating system of the first device is one of the following:

an iPhone Operating System (iOS); or

an Android OS; and

an operating system of the second device is one of the following:

an iOS; or

an Android OS.

6 . The first device of claim 1 , wherein:

the account information is associated with a mobile application installed on the first device; and

the account information comprises an identity of at least one third-party account.

7 . The first device of claim 1 , wherein the session is an encrypted, authenticated multi-party computation (MPC) session.

8 . A method, comprising:

scanning, by a first device, a code from a second device, wherein the code is generated by the second device in response to receiving a request to transfer account information from the second device to the first device;

determining, by the first device, information comprising a peer identifier and a first certificate hash using the code, wherein the first certificate hash is generated by the second device and the peer identifier is a verifiable link between a peer and its public cryptographic key;

initiating, by the first device, a connection with the second device using the peer identifier;

receiving, by the first device, a second certificate hash from the second device via the connection;

comparing, by the first device, the first certificate hash to the second certificate hash;

validating, by the first device, the second certificate hash using the first certificate hash;

establishing, by the first device, a session with the second device; and

transferring, by the first device, the account information to the second device via the session.

9 . The method of claim 8 , wherein the code is a machine-readable image.

10 . The method of claim 8 , wherein the connection is one of the following:

a Transport Layer Security (TLS) connection;

a Datagram Transport Layer Security (DTLS) connection; or

a Constrained Application Protocol (CoAP) connection.

11 . The method of claim 8 , wherein the first certificate hash is generated by the second device by hashing a self-signed certificate.

12 . The method of claim 8 , wherein:

an operating system of the first device is one of the following:

an iPhone Operating System (iOS); or

an Android OS; and

an operating system of the second device is one of the following:

an iOS; or

an Android OS.

13 . The method of claim 8 , wherein:

the account information is associated with a mobile application installed on the first device; and

the account information comprises an identity of at least one third-party account.

14 . The method of claim 8 , wherein the session is an encrypted, authenticated multi-party computation (MPC) session.

15 . One or more computer-readable non-transitory storage media embodying instructions that, when executed by a processor, cause the processor to perform operations comprising:

scanning, by a first device, a code from a second device, wherein the code is generated by the second device in response to receiving a request to transfer account information from the second device to the first device;

determining information comprising a peer identifier and a first certificate hash using the code, wherein the first certificate hash is generated by the second device and the peer identifier is a verifiable link between a peer and its public cryptographic key;

initiating a connection with the second device using the peer identifier;

receiving a second certificate hash from the second device via the connection;

determining that the first certificate hash matches the second certificate hash;

validating the second certificate hash using the first certificate hash;

establishing a session with the second device; and

transferring the account information to the second device via the session.

16 . The one or more computer-readable non-transitory storage media of claim 15 , wherein the code is a machine-readable image.

17 . The one or more computer-readable non-transitory storage media of claim 15 , wherein the connection is one of the following:

a Transport Layer Security (TLS) connection;

a Datagram Transport Layer Security (DTLS) connection; or

a Constrained Application Protocol (CoAP) connection.

18 . The one or more computer-readable non-transitory storage media of claim 15 , wherein the first certificate hash is generated by the second device by hashing a self-signed certificate.

19 . The one or more computer-readable non-transitory storage media of claim 15 , wherein:

an operating system of the first device is one of the following:

an iPhone Operating System (iOS); or

an Android OS; and

an operating system of the second device is one of the following:

an iOS; or

an Android OS.

20 . The one or more computer-readable non-transitory storage media of claim 15 , wherein:

the account information is associated with a mobile application installed on the first device; and

the account information comprises an identity of at least one third-party account.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 15, 2022
From: SMALL, ROBERT JACOB LINIAL; NEIDLINGER, JORDAN DAVID; FREIBAND, BENJAMIN WARREN; ASHOK, APARNA; ANDERSON, MARSHALL DEAN
To: CISCO TECHNOLOGY, INC.
Reel/Frame 062102/0717 →
Continuity (1)
Related Publication 20240205026A1 · Jun 20, 2024
References Cited (37)
US 6772331B1 · Hind · 2004 [cited by examiner]
US 7350074B2 · Gupta · 2008 [cited by examiner]
US 9143504B1 · Shi · 2015 [cited by examiner]
US 9401905B1 · Kowalski et al. · 2016 [cited by applicant]
US 10868802B2 · Westerlund · 2020 [cited by examiner]
US 20070136800A1 · Chan · 2007 [cited by examiner]
US 20120287290A1 · Jain · 2012 [cited by applicant]
US 20120308003A1 · Mukherjee · 2012 [cited by examiner]
US 20120331073A1 · Williams · 2012 [cited by examiner]
US 20130145165A1 · Brown · 2013 [cited by examiner]
US 20130237270A1 · Suumaki · 2013 [cited by examiner]
US 20130340044A1 · Litvin · 2013 [cited by examiner]
US 20150040222A1 · Boivie · 2015 [cited by examiner]
US 20160142211A1 · Metke et al. · 2016 [cited by applicant]
US 20160142214A1 · Ekberg et al. · 2016 [cited by applicant]
US 20160360412A1 · Wilson · 2016 [cited by examiner]
US 20170280488A1 · Kawasaki · 2017 [cited by examiner]
US 20180191501A1 · Lindemann · 2018 [cited by applicant]
US 20210044577A1 · Jung · 2021 [cited by examiner]
US 20210067347A1 · Yu · 2021 [cited by examiner]
US 20220155981A1 · Ciudad · 2022 [cited by examiner]
US 20220166761A1 · Waterton et al. · 2022 [cited by applicant]
US 20220255726A1 · Durak · 2022 [cited by examiner]
US 20220376933A1 · Guabtni · 2022 [cited by examiner]
US 20230023647A1 · Voss · 2023 [cited by examiner]
US 20230300614A1 · Holkal · 2023 [cited by examiner]
US 20240276228A1 · Zhou · 2024 [cited by examiner]
EP 4319043A1 · 2024 [cited by examiner]
WO WO2021036183A1 · 2021 [cited by examiner]
WO WO2023059696A1 · 2023 [cited by examiner]
Alapetite, Alexandre. “Dynamic 2D-barcodes for multi-device Web session migration including mobile phones.” Personal and Ubiquitous Computing 14 (2010): 45-52. (Year: 2010). [cited by examiner]
Ãlvarez, Flor, Max Kolhagen, and Matthias Hollick. “Sea of lights: Practical device-to-device security bootstrapping in the dark.” 2018 IEEE 43rd Conference on Local Computer Networks (LCN). IEEE, 2018. (Year: 2018). [cited by examiner]
J. M. McCune, A. Perrig and M. K. Reiter, “Seeing-is-believing: using camera phones for human-verifiable authentication, ” 2005 IEEE Symposium on Security and Privacy (S&P'05), Oakland, CA, USA, 2005, pp. 110-124, doi: … [cited by examiner]
N. Saxena, J. . -E. Ekberg, K. Kostiainen and N. Asokan, “Secure device pairing based on a visual channel, ” 2006 IEEE Symposium on Security and Privacy (S&P'06), Berkeley/Oakland, CA, USA, 2006, pp. 6 pp.-313, doi: 10.… [cited by examiner]
Scott, David, et al. “Using visual tags to bypass Bluetooth device discovery.” ACM Sigmobile Mobile Computing and Communications Review 9.1 (2005): 41-53. (Year: 2005). [cited by examiner]
T. Panton, D. Llewellyn-Jones, N. Shone and M. H. Eiza, “Secure proximity-based identity pairing using an untrusted signalling service,” 2016 13th IEEE Annual Consumer Communications & Networking Conference (CCNC), Las … [cited by examiner]
International Search Report and Written Opinion for International Application No. PCT/US2023/082229, mailed Mar. 18, 2024, 12 Pages. [cited by applicant]