IP Library › Granted Patent US 12,598,180
Granted Patent B2
US 12,598,180 · App. 18/123,023 · Granted Apr 7, 2026

Paired device multi-factor authentication using bluetooth

Inventors: Jay Prakash Tiwari (Princeton, NJ); Praveen Kumar Sheena Poojary (Jersey city, NJ); Senthil Kumar Chadramohan (Karnataka, IN)
Assignee: Cisco Technology, Inc.
H04L63/0869H04L63/083H04W4/80H04W12/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,598,180
App. No.
18/123,023
Filed
Mar 17, 2023
Granted
Apr 7, 2026
Kind
B2
Examiner
LE, CHAU D
Art Unit
2408
USPC
726/6
Abstract

Techniques for determining whether to send an MFA push notification are described. An indication of a request for a user account to access the application service via a primary device is received at an MFA service from an application service. Using a PAN protocol, determine whether the primary device and the secondary device are within a threshold proximity. When the primary device and the secondary device are within the threshold proximity, allows a push notification to be transmitted to the secondary device requesting authentication to grant access to the user account by the primary device, and when the primary device and the secondary device are not within the threshold, refrain from transmitting the push notification.

Claims (55)

1 . A method comprising:

receiving, by a Multi-Factor Authentication (MFA) service and from an application service, an indication of a request for a user account to access the application service via a primary device, the request including login credentials associated with the user account;

determining, using a personal area networking (PAN) protocol, that the primary device and a secondary device are not within a threshold proximity to each other;

and

in response to determining that the primary device and the secondary device are not within the threshold proximity to each other, refraining from transmitting a push notification to the secondary device, wherein the push notification includes an authentication request generated by the MFA service requesting that the user account authenticate to gain access to the application service.

2 . The method of claim 1 , further comprising:

transmitting a notification to the secondary device that the login credentials associated with the user account may have been stolen; and

prompting for a change to a password associated with the user account.

3 . The method of claim 1 , further comprising receiving, from an agent running on the primary device, information indicating whether the primary device and secondary device are paired via the PAN protocol.

4 . The method of claim 3 , further comprising:

monitoring the PAN protocol pairing information received from the agent running on the primary device; and

terminating a communication session between the primary device and the application service when the PAN protocol pairing information indicates the primary device and secondary device are not paired via the PAN protocol.

5 . The method of claim 1 , wherein the request for the user account to access the application service via the primary device, also includes a Universally Unique Identifier (UUID) for the primary device and further comprising receiving, from the secondary device, PAN protocol pairing information indicating whether the secondary device is paired with the primary device having the UUID included in the request.

6 . The method of claim 5 , further comprising:

monitoring the PAN protocol pairing information received from the secondary device; and

terminating a communication session between the primary device and the application service when the PAN protocol pairing information indicates the primary device and secondary device are not paired via the PAN protocol.

7 . The method of claim 1 , further comprising:

determining, using the personal area networking (PAN) protocol, that the primary device and a secondary device have moved within a threshold proximity to each other; and

in response to the primary device and the secondary device being within the threshold proximity to each other, determining, at the MFA service, to allow a push notification to be transmitted to the secondary device requesting user input to grant access to the user account by the primary device.

8 . A system comprising:

one or more processors; and

one or more non-transitory computer-readable media storing instructions that, when executed, cause the one or more processors to perform operations comprising:

receiving, by a Multi-Factor Authentication (MFA) service and from an application service, an indication of a request for a user account to access the application service via a primary device, the request including login credentials associated with the user account;

determining, using a personal area networking (PAN) protocol, that the primary device and a secondary device are not within a threshold proximity to each other;

and

in response to determining that the primary device and the secondary device are not within the threshold proximity to each other, refraining from transmitting a push notification to the secondary device, wherein the push notification includes an authentication request generated by the MFA service requesting that the user account authenticate to gain access to the application service.

9 . The system of claim 8 , the operations further comprising:

transmitting a notification to the secondary device that the login credentials associated with the user account may have been stolen; and

prompting for a change to a password associated with the user account.

10 . The system of claim 8 , the operations further comprising receiving, from an agent running on the primary device, information indicating whether the primary device and secondary device are paired via the PAN protocol.

11 . The system of claim 10 , the operations further comprising:

monitoring the PAN protocol pairing information received from the agent running on the primary device; and

terminating a communication session between the primary device and the application service when the PAN protocol pairing information indicates the primary device and secondary device are not paired via the PAN protocol.

12 . The system of claim 8 , wherein the request for the user account to access the application service via the primary device, also includes a Universally Unique Identifier (UUID) for the primary device and the operations further comprising receiving, from the secondary device, PAN protocol pairing information indicating whether the secondary device is paired with the primary device having the UUID included in the request.

13 . The system of claim 12 , the operations further comprising:

monitoring the PAN protocol pairing information received from the secondary device; and

terminating a communication session between the primary device and the application service when the PAN protocol pairing information indicates the primary device and secondary device are not paired via the PAN protocol.

14 . The system of claim 8 , the operations further comprising:

determining, using the personal area networking (PAN) protocol, that the primary device and a secondary device have moved within a threshold proximity to each other; and

in response to the primary device and the secondary device being within the threshold proximity to each other, determining, at the MFA service, to allow a push notification to be transmitted to the secondary device requesting user input to grant access to the user account by the primary device.

15 . One or more non-transitory computer-readable media storing instructions that, when executed, cause one or more processors to perform operations comprising:

receiving, by a Multi-Factor Authentication (MFA) service and from an application service, an indication of a request for a user account to access the application service via a primary device, the request including login credentials associated with the user account;

determining, using a personal area networking (PAN) protocol, that the primary device and a secondary device are not within a threshold proximity to each other;

in response to determining that the primary device and the secondary device are not within the threshold proximity to each other, refraining from transmitting a push notification to the secondary device, wherein the push notification includes an authentication request generated by the MFA service requesting that the user account authenticate to gain access to the application service.

16 . The one or more non-transitory computer-readable media of claim 15 , the operations further comprising:

transmitting a notification to the secondary device that the login credentials associated with the user account may have been stolen; and

prompting for a change to a password associated with the user account.

17 . The one or more non-transitory computer-readable media of claim 15 , the operations further comprising receiving, from an agent running on the primary device, information indicating whether the primary device and secondary device are paired via the PAN protocol.

18 . The one or more non-transitory computer-readable media of claim 17 , the operations further comprising:

monitoring the PAN protocol pairing information received from the agent running on the primary device; and

terminating a communication session between the primary device and the application service when the PAN protocol pairing information indicates the primary device and secondary device are not paired via the PAN protocol.

19 . The one or more non-transitory computer-readable media of claim 15 , wherein the request for the user account to access the application service via the primary device, also includes a Universally Unique Identifier (UUID) for the primary device and the operations further comprising receiving, from the secondary device, PAN protocol pairing information indicating whether the secondary device is paired with the primary device having the UUID included in the request.

20 . The one or more non-transitory computer-readable media of claim 19 , the operations further comprising:

monitoring the PAN protocol pairing information received from the secondary device; and

terminating a communication session between the primary device and the application service when the PAN protocol pairing information indicates the primary device and secondary device are not paired via the PAN protocol.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 17, 2023
From: TIWARI, JAY PRAKASH; POOJARY, PRAVEEN KUMAR SHEENA; CHADRAMOHAN, SENTHIL KUMAR
To: CISCO TECHNOLOGY, INC.
Reel/Frame 063021/0327 →
Continuity (1)
Related Publication 20240314123A1 · Sep 19, 2024
References Cited (63)
US 8467770B1 · Ben Ayed · 2013 [cited by examiner]
US 8595810B1 · Ben Ayed · 2013 [cited by applicant]
US 9075979B1 · Queru · 2015 [cited by applicant]
US 9525972B2 · Raounak · 2016 [cited by applicant]
US 9571282B1 · Aggarwal et al. · 2017 [cited by applicant]
US 9722984B2 · Burch et al. · 2017 [cited by applicant]
US 10097538B1 · Sanchez · 2018 [cited by applicant]
US 10142794B1 · Diamanti et al. · 2018 [cited by applicant]
US 10206099B1 · Trinh · 2019 [cited by examiner]
US 10212591B1 · Queru · 2019 [cited by examiner]
US 10657242B1 · Xia · 2020 [cited by examiner]
US 10701067B1 · Ziraknejad · 2020 [cited by examiner]
US 10771458B1 · Xia · 2020 [cited by examiner]
US 10812476B2 · Alexander · 2020 [cited by applicant]
US 10887307B1 · Newstadt et al. · 2021 [cited by applicant]
US 11140157B1 · Xia · 2021 [cited by examiner]
US 11140175B2 · Zhong · 2021 [cited by examiner]
US 11483707B2 · Leblang et al. · 2022 [cited by applicant]
US 11496462B2 · Lee et al. · 2022 [cited by applicant]
US 11805112B2 · Zacks et al. · 2023 [cited by applicant]
US 12003512B2 · Anani et al. · 2024 [cited by applicant]
US 20100278345A1 · Alsina et al. · 2010 [cited by applicant]
US 20130169434A1 · McCown et al. · 2013 [cited by applicant]
US 20150106900A1 · Pinski et al. · 2015 [cited by applicant]
US 20150215299A1 · Burch et al. · 2015 [cited by applicant]
US 20150256973A1 · Raounak · 2015 [cited by examiner]
US 20150371026A1 · Gnanasekaran · 2015 [cited by examiner]
US 20150381633A1 · Grim · 2015 [cited by examiner]
US 20160021103A1 · Koneru · 2016 [cited by applicant]
US 20160286393A1 · Rasheed et al. · 2016 [cited by applicant]
US 20170032111A1 · Johansson et al. · 2017 [cited by applicant]
US 20170126640A1 · Vincent · 2017 [cited by examiner]
US 20180007060A1 · Leblang et al. · 2018 [cited by applicant]
US 20180013782A1 · Choyi et al. · 2018 [cited by applicant]
US 20180293367A1 · Urman · 2018 [cited by applicant]
US 20190166118A1 · Lee et al. · 2019 [cited by applicant]
US 20190188368A1 · Hastings · 2019 [cited by applicant]
US 20190213318A1 · Gnanasekaran · 2019 [cited by examiner]
US 20190305955A1 · Verma et al. · 2019 [cited by applicant]
US 20190372959A1 · Pattar et al. · 2019 [cited by applicant]
US 20200186520A1 · Oberheide et al. · 2020 [cited by applicant]
US 20200233949A1 · Xia et al. · 2020 [cited by applicant]
US 20200404003A1 · Alameh · 2020 [cited by examiner]
US 20210136060A1 · Raounak · 2021 [cited by applicant]
US 20210350013A1 · Lakhani et al. · 2021 [cited by applicant]
US 20220027498A1 · Vandanapu · 2022 [cited by examiner]
US 20220255913A1 · Zacks et al. · 2022 [cited by applicant]
US 20220255922A1 · Zacks et al. · 2022 [cited by applicant]
US 20220272101A1 · Cuan et al. · 2022 [cited by applicant]
US 20220345464A1 · Davenport · 2022 [cited by examiner]
US 20220385656A1 · Gujarathi · 2022 [cited by applicant]
US 20220408259A1 · Adel · 2022 [cited by examiner]
US 20230041559A1 · Burgess et al. · 2023 [cited by applicant]
US 20240137365A1 · Neighbour et al. · 2024 [cited by applicant]
US 20240195797A1 · Miel et al. · 2024 [cited by applicant]
US 20240314118A1 · Keshet · 2024 [cited by applicant]
US 20240314138A1 · Tiwari et al. · 2024 [cited by applicant]
WO WO2019191394A1 · 2019 [cited by applicant]
Ghose et al., “ZITA: Zero-Interaction Two-Factor Authentication Using Contact Traces and In-Band Proximity Verification”, IEEE Transactions on Mobile Computing (vol. 23, Issue: 5, 2024, pp. 6318-6333), Electronic Public… [cited by examiner]
Shah et al., “Wi-Access: Second Factor User Authentication leveraging WiFi Signals,” 2018 IEEE International Conference on Pervasive Computing and Communications Workshops (PerCom Workshops), Athens, Greece, 2018, pp. 3… [cited by examiner]
Search Report and Written Opinion for International Application No. PCT/US2024/019696, Dated May 16, 2024, 14 pages. [cited by applicant]
Office Action for U.S. Appl. No. 18/122,990, Dated Feb. 10, 2025, Tiwari, “Global Positioning System Based Multi-Factor Authentication for Zero Trust Network Access ,” 19 pages. [cited by applicant]
Search Report and Written Opinion for International Application No. PCT/US2024/019666, Dated May 13, 2024, 13 pages. [cited by applicant]