IP Library Granted Patent US 12,549,944
Granted Patent B2
US 12,549,944 · App. 18/439,860 · Granted Feb 10, 2026

Elevated device authentication through mutual identification

Inventors: David M. Cesarano (Queen Creek, AZ); Su Liu (Austin, TX); Logan Bailey (Atlanta, GA); Mir Farhan Ali (The Colony, TX)
Assignee: International Business Machines Corporation
H04W12/062H04W12/71
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,549,944
App. No.
18/439,860
Granted
Feb 10, 2026
Kind
B2
Abstract

A computer-implemented method, a computer system and a computer program product authenticate devices using remote mutual identification. The method comprises determining that a network device requires management, where the network device is deployed in a location. The method also comprises identifying a trusted device, where the trusted device is within a range of the location of the network device. The method further comprises establishing a trust relationship between the trusted device and the network device. Lastly, the method comprises enabling management access to the network device based on the trust relationship.

Claims (71)

1 . A computer-implemented method for authenticating devices using remote mutual identification, the computer-implemented method comprising:

determining that a network device requires management, wherein the network device is deployed in a location;

obtaining profile information about the network device and the location;

identifying a trusted device using a machine learning model to select the trusted device from the profile information, wherein the trusted device is within a range of the location of the network device;

establishing a trust relationship between the trusted device and the network device; and

enabling management access to the network device based on the trust relationship.

2 . The computer-implemented method of claim 1 , further comprising:

notifying network management that the management access to the network device is enabled.

3 . The computer-implemented method of claim 1 , further comprising:

displaying an identified trusted device to network management;

monitoring the network management with the identified trusted device; and

updating the trusted device based on the monitoring of the network management with the identified trusted device.

4 . The computer-implemented method of claim 1 , further comprising:

capturing an image of the network device using a camera associated with the trusted device, wherein the network device displays a unique visual identifier;

authenticating the unique visual identifier based on the image of the network device; and

establishing the trust relationship between the trusted device and the network device based on an authenticated visual identifier.

5 . The computer-implemented method of claim 1 , further comprising:

capturing a unique audio signal using a microphone associated with the trusted device, wherein the network device transmits the unique audio signal;

authenticating the unique audio signal from the network device; and

establishing the trust relationship between the trusted device and the network device based on an authenticated audio signal.

6 . The computer-implemented method of claim 1 , further comprising:

determining the location of the network device using one or more of: a wireless network service set identifier (SSID), Bluetooth device identifier, and radio frequency identifier (RFID) tag.

7 . A computer system for authenticating devices using remote mutual identification, the computer system comprising:

a processor set;

one or more computer readable storage media; and

program instructions stored on the one or more computer readable storage media to cause the processor set to perform operations comprising:

determining that a network device requires management, wherein the network device is deployed in a location;

obtaining profile information about the network device and the location;

identifying a trusted device using a machine learning model to select the trusted device from the profile information, wherein the trusted device is within a range of the location of the network device;

establishing a trust relationship between the trusted device and the network device; and

enabling management access to the network device based on the trust relationship.

8 . The computer system of claim 7 , wherein the operations further comprise:

notifying network management that the management access to the network device is enabled.

9 . The computer system of claim 7 , wherein the operations further comprise:

displaying an identified trusted device to network management;

monitoring the network management with the identified trusted device; and

updating the trusted device based on the monitoring of the network management with the identified trusted device.

10 . The computer system of claim 7 , wherein the operations further comprise:

capturing an image of the network device using a camera associated with the trusted device, wherein the network device displays a unique visual identifier;

authenticating the unique visual identifier based on the image of the network device; and

establishing the trust relationship between the trusted device and the network device based on an authenticated visual identifier.

11 . The computer system of claim 7 , wherein the operations further comprise:

capturing a unique audio signal using a microphone associated with the trusted device, wherein the network device transmits the unique audio signal;

authenticating the unique audio signal from the network device; and

establishing the trust relationship between the trusted device and the network device based on an authenticated audio signal.

12 . The computer system of claim 7 , wherein the operations further comprise:

determining the location of the network device using one or more of: a wireless network service set identifier (SSID), Bluetooth device identifier, and radio frequency identifier (RFID) tag.

13 . A computer program product for authenticating devices using remote mutual identification, the computer program product comprising:

one or more computer readable storage media; and

program instructions stored on the one or more computer readable storage media to perform operations comprising:

determining that a network device requires management, wherein the network device is deployed in a location;

obtaining profile information about the network device and the location;

identifying a trusted device using a machine learning model to select the trusted device from the profile information, wherein the trusted device is within a range of the location of the network device;

establishing a trust relationship between the trusted device and the network device; and

enabling management access to the network device based on the trust relationship.

14 . The computer program product of claim 13 , wherein the operations further comprise;

notifying network management that the management access to the network device is enabled.

15 . The computer program product of claim 13 , wherein the operations further comprise:

displaying an identified trusted device to network management;

monitoring of the network management with the identified trusted device; and

updating the trusted device based on the monitoring of the network management with the identified trusted device.

16 . The computer program product of claim 13 , wherein the operations further comprise:

capturing an image of the network device using a camera associated with the trusted device, wherein the network device displays a unique visual identifier;

authenticating the unique visual identifier based on the image of the network device; and

establishing the trust relationship between the trusted device and the network device based on an authenticated visual identifier.

17 . The computer program product of claim 13 , wherein the operations further comprise:

capturing a unique audio signal using a microphone associated with the trusted device, wherein the network device transmits the unique audio signal;

authenticating the unique audio signal from the network device; and

establishing the trust relationship between the trusted device and the network device based on an authenticated audio signal.

18 . The computer program product of claim 13 , wherein the operations further comprise:

determining the location of the network device using one or more of: a wireless network service set identifier (SSID), Bluetooth device identifier, and radio frequency identifier (RFID) tag.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 13, 2024
From: CESARANO, DAVID M.; LIU, SU; BAILEY, LOGAN; ALI, MIR FARHAN
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 066447/0351 →
Continuity (1)
Related Publication 20250260980A1 · Aug 14, 2025
References Cited (22)
US 8224354B2 · De Vries · 2012 [cited by applicant]
US 9438440B2 · Burns · 2016 [cited by applicant]
US 10262334B2 · Heeter · 2019 [cited by applicant]
US 11405789B1 · Wei · 2022 [cited by examiner]
US 11431561B2 · Smith · 2022 [cited by applicant]
US 11449857B2 · Han · 2022 [cited by applicant]
US 20110010543A1 · Schmidt · 2011 [cited by examiner]
US 20210334925A1 · Peacock · 2021 [cited by examiner]
US 20220050982A1 · Spivack · 2022 [cited by applicant]
US 20220159461A1 · Maass · 2022 [cited by examiner]
US 20230216947A1 · Bernardi · 2023 [cited by applicant]
CA 2936586A1 · 2015 [cited by applicant]
CA 3060697A1 · 2021 [cited by applicant]
“Research & Product Testing”, Mount Washington Observatory, © 2023, 4 pages, <https://web.archive.org/web/20230304212327/https:/mountwashington.org/research-and-product-testing/>. [cited by applicant]
Adil, M. et al., “An Intelligent HybridMutual Authentication Scheme for Industrial Internet of Thing Networks”, Accepted: Nov. 30, 2020, DOI:10.32604/cmc.2021.014967, 24 pages. [cited by applicant]
Das, S. et al., “Lightweight and efficient privacy-preserving mutual authentication scheme to secure Internet of Things-based smart healthcare”, Accepted: Nov. 30, 2022, DOI: 10.1002/ett.4716, 16 pages. [cited by applicant]
Disclosed Anonymously “The Network of Interaction between Intelligent Devices basing on Context Awareness in Internet of Things”, An IP.com Prior Art Database Technical Disclosure, IP.com No. IPCOM000251809D, IP.com Ele… [cited by applicant]
Disclosed Anonymously, “Proximity based authentication method for internal WiFi networks”, An IP.com Prior Art Database Technical Disclosure, IP.com No. IPCOM000265162D, IP.com Electronic Publication Date: Mar. 5, 2021,… [cited by applicant]
Khan, S. et al., “Efficient Mutual Authentication mechanism to Secure Internet of Things (IoT)”, Downloaded on Sep. 10, 2023, 4 pages. [cited by applicant]
Kushwaha et al., “Internet of Things Secured Onboarding Mechanism”, An IP.com Prior Art Database Technical Disclosure, IP.com No. IPCOM000252429D, IP.com Electronic Publication Date: Jan. 10, 2018, 6 pages. [cited by applicant]
Wang, H. et al., “Lightweight and Anonymous Mutual Authentication Protocol for Edge IoT Nodes with Physical Unclonable Function”, Published Jan. 4, 2022, 11 pages, <https://doi.org/10.1155/2022/1203691>. [cited by applicant]
International Searching Authority, “Notification of Transmittal of the International Search Report and the Written Opinion of the International Searching Authority, or Declaration,” Patent Cooperation Treaty, Mar. 32, 2… [cited by applicant]