IP Library › Granted Patent US 12,659,304
Granted Patent B2
US 12,659,304 · App. 18/770,051 · Granted Jun 16, 2026

Device authentication sharing

Inventors: James Pratt (Round Rock, TX); Yupeng Jia (South Pasadena, CA); Eric Zavesky (Austin, TX)
Assignee: AT&T Intellectual Property I, L.P.
H04L63/08H04L63/107
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,659,304
App. No.
18/770,051
Granted
Jun 16, 2026
Kind
B2
Abstract

Device authentication sharing can include detecting, at a gateway of a local network, authentication of a user device for communication with a first local device that is in communication with the gateway via the local network. The gateway can send, to a second local device operating on the local network, an authentication notice that indicates that the user device has authenticated for communication with the first local device. The gateway can receive from the second local device, a share request requesting sharing of the authentication of the user device with the second local device. The gateway can obtain a token that defines a permission associated with the authentication, a time limit associated with the authentication, and a location limit associated with the authentication. Delivery of the token to the gateway can be triggered, whereby the second local device communicates with the user device via a connection supported by the gateway.

Claims (58)

1 . A device comprising:

a processor; and

a memory that stores computer-executable instructions that, when executed by the processor, cause the processor to perform operations comprising

detecting, at a gateway of a local network, authentication of a user device for communication with a first local device, wherein the first local device is in communication with the gateway via the local network,

sending, by the gateway and to a second local device operating on the local network, an authentication notice that indicates that the user device has authenticated for communication with the first local device,

receiving, by the gateway and from the second local device, a share request requesting sharing of the authentication of the user device with the second local device,

obtaining, by the gateway, a token that defines a permission associated with the authentication, a time limit associated with the authentication, and a location limit associated with the authentication, and

triggering delivery of the token to the second local device to share the authentication of the user device with the second local device, whereby the second local device communicates with the user device via a connection supported by the gateway.

2 . The device of claim 1 , wherein the computer-executable instructions, when executed by the processor, cause the processor to perform operations further comprising:

monitoring, by the gateway, the connection to track a time duration of the connection and a location of the user device;

determining, by the gateway, if the connection should be terminated based on the time duration, the location of the user device, the time limit, and the location limit; and

in response to a determination that the connection should be terminated, revoking the authentication and terminating the connection.

3 . The device of claim 2 , wherein the location limit comprises a proximity between the user device and the first local device that must be maintained, and wherein the determination that the connection should be terminated comprises a determination that the location of the user device is outside the proximity.

4 . The device of claim 1 , wherein the computer-executable instructions, when executed by the processor, cause the processor to perform operations further comprising:

detecting a delegated device on the local network;

detecting the user device leaving the local network;

determining if the authentication of the user device should be delegated to the delegated device; and

in response to a determination that the authentication of the user device should be delegated to the delegated device, triggering delivery of the token to the delegated device.

5 . The device of claim 4 , wherein in response to detecting that the authentication of the user device has been delegated to the delegated device, notifications from the first local device and from the second local device are sent to the delegated device instead of the user device.

6 . The device of claim 1 , wherein obtaining the token comprises receiving, from the user device, the token, wherein the token comprises a data file generated by the user device, the data file identifying the permission, the time limit, content, and the location limit.

7 . The device of claim 1 , wherein the user device is authenticated by an authentication sharing service hosted by a server computer, and wherein obtaining the token comprises receiving, from the server computer, the token, wherein the token comprises a data file generated by the user device, the data file identifying the permission, the time limit, and the location limit.

8 . A method comprising:

detecting, at a gateway of a local network, authentication of a user device for communication with a first local device, wherein the first local device is in communication with the gateway via the local network;

sending, by the gateway and to a second local device operating on the local network, an authentication notice that indicates that the user device has authenticated for communication with the first local device;

receiving, by the gateway and from the second local device, a share request requesting sharing of the authentication of the user device with the second local device;

obtaining, by the gateway, a token that defines a permission associated with the authentication, a time limit associated with the authentication, and a location limit associated with the authentication; and

triggering delivery of the token to the second local device to share the authentication of the user device with the second local device, whereby the second local device communicates with the user device via a connection supported by the gateway.

9 . The method of claim 8 , further comprising:

monitoring, by the gateway, the connection to track a time duration of the connection and a location of the user device;

determining, by the gateway, if the connection should be terminated based on the time duration, the location of the user device, the time limit, and the location limit; and

in response to a determination that the connection should be terminated, revoking the authentication and terminating the connection.

10 . The method of claim 9 , wherein the location limit comprises a proximity between the user device and the first local device that must be maintained, and wherein the determination that the connection should be terminated comprises a determination that the location of the user device is outside the proximity.

11 . The method of claim 8 , further comprising:

detecting a delegated device on the local network;

detecting the user device leaving the local network;

determining if the authentication of the user device should be delegated to the delegated device; and

in response to a determination that the authentication of the user device should be delegated to the delegated device, triggering delivery of the token to the delegated device.

12 . The method of claim 11 , wherein in response to detecting that the authentication of the user device has been delegated to the delegated device, notifications from the first local device and from the second local device are sent to the delegated device instead of the user device.

13 . The method of claim 8 , wherein obtaining the token comprises receiving, from the user device, the token, wherein the token comprises a data file generated by the user device, the data file identifying the permission, the time limit, and the location limit.

14 . A computer storage medium having computer-executable instructions stored thereon that, when executed by a processor, cause the processor to perform operations comprising:

detecting, at a gateway of a local network, authentication of a user device for communication with a first local device, wherein the first local device is in communication with the gateway via the local network;

sending, by the gateway and to a second local device operating on the local network, an authentication notice that indicates that the user device has authenticated for communication with the first local device;

receiving, by the gateway and from the second local device, a share request requesting sharing of the authentication of the user device with the second local device;

obtaining, by the gateway, a token that defines a permission associated with the authentication, a time limit associated with the authentication, and a location limit associated with the authentication; and

triggering delivery of the token to the second local device to share the authentication of the user device with the second local device, whereby the second local device communicates with the user device via a connection supported by the gateway.

15 . The computer storage medium of claim 14 , wherein the computer-executable instructions, when executed by the processor, cause the processor to perform operations further comprising:

monitoring, by the gateway, the connection to track a time duration of the connection and a location of the user device;

determining, by the gateway, if the connection should be terminated based on the time duration, the location of the user device, the time limit, and the location limit; and

in response to a determination that the connection should be terminated, revoking the authentication and terminating the connection.

16 . The computer storage medium of claim 15 , wherein the location limit comprises a proximity between the user device and the first local device that must be maintained, and wherein the determination that the connection should be terminated comprises a determination that the location of the user device is outside the proximity.

17 . The computer storage medium of claim 14 , wherein the computer-executable instructions, when executed by the processor, cause the processor to perform operations further comprising:

detecting a delegated device on the local network;

detecting the user device leaving the local network;

determining if the authentication of the user device should be delegated to the delegated device; and

in response to a determination that the authentication of the user device should be delegated to the delegated device, triggering delivery of the token to the delegated device.

18 . The computer storage medium of claim 17 , wherein in response to detecting that the authentication of the user device has been delegated to the delegated device, notifications from the first local device and from the second local device are sent to the delegated device instead of the user device.

19 . The computer storage medium of claim 14 , wherein obtaining the token comprises receiving, from the user device, the token, wherein the token comprises a data file generated by the user device, the data file identifying the permission, the time limit, and the location limit.

20 . The computer storage medium of claim 14 , wherein the user device is authenticated by an authentication sharing service hosted by a server computer, and wherein obtaining the token comprises receiving, from the server computer, the token, wherein the token comprises a data file generated by the user device, the data file identifying the permission, the time limit, and the location limit.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 12, 2024
From: JIA, YUPENG; PRATT, JAMES; ZAVESKY, ERIC
To: AT&T INTELLECTUAL PROPERTY I, L.P.
Reel/Frame 067971/0801 →
Continuity (1)
Related Publication 20260019408A1 · Jan 15, 2026
References Cited (22)
US 9270603B2 · Thodupunoori · 2016 [cited by examiner]
US 9397989B1 · Ramalingam · 2016 [cited by examiner]
US 9571485B2 · Le · 2017 [cited by examiner]
US 9635010B2 · Counterman · 2017 [cited by examiner]
US 11038838B2 · Lau · 2021 [cited by examiner]
US 11705585B2 · Ha · 2023 [cited by examiner]
US 11855999B1 · Gurinaviciute et al. · 2023 [cited by examiner]
US 20110179478A1 · Flick · 2011 [cited by examiner]
US 20140157389A1 · Mardikar · 2014 [cited by examiner]
US 20140181951A1 · Birkhofer · 2014 [cited by examiner]
US 20160380997A1 · Blasi · 2016 [cited by examiner]
US 20170264597A1 · Pizot · 2017 [cited by examiner]
US 20180332016A1 · Pandey · 2018 [cited by examiner]
US 20180367340A1 · Shaw · 2018 [cited by examiner]
US 20190289016A1 · Malan · 2019 [cited by examiner]
US 20190327098A1 · Hart · 2019 [cited by examiner]
US 20200211002A1 · Steinberg · 2020 [cited by examiner]
US 20200259667A1 · Garnier · 2020 [cited by examiner]
US 20200287726A1 · Garnier · 2020 [cited by examiner]
US 20220385656A1 · Gujarathi · 2022 [cited by examiner]
US 20220407867A1 · Rathi · 2022 [cited by examiner]
CN 117955674A · 2024 [cited by examiner]