IP Library › Granted Patent US 12,744,775
Granted Patent B2
US 12,744,775 · App. 18/590,562 · Granted Sep 22, 2026

Zero-touch always-on user authentication from trusted multimedia sources

Inventors: Steven Michael Holl (Sarasota, FL); Matthew Robert Engle (Plano, TX); Jason A. Kuhne (Hopkinton, MA); Jason Michael Coleman (Hendersonville, NC)
Assignee: CISCO TECHNOLOGY, INC.
H04L63/0861H04L63/083
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,744,775
App. No.
18/590,562
Granted
Sep 22, 2026
Kind
B2
Abstract

A method comprises: at an identity provider, upon receiving a request for authentication of a user to a target application that is hosted on a user device and into which the user has logged-in: identifying one or more biometric tests to be applied to the user to satisfy the request; selecting, from a list of application services that have trust relationships with the identity provider, an application service which has an active session with the user and supports the one or more biometric tests; requesting the application service to perform multifactor authentication that includes the one or more biometric tests; receiving, from the application service, biometric test results that indicate whether each of the one or more biometric tests passed or failed; and determining that the authentication has passed or failed based on the biometric test results.

Claims (77)

1 . A method comprising:

at an identity provider, upon receiving a request for authentication of a user to a target application that is hosted on a user device and into which the user has logged-in:

storing a list of application services having trust relationships with the identity provider and that are mapped to biometric sensors provided by each application service;

identifying one or more biometric tests to be applied to the user to satisfy the request;

searching the list of application services based on the one or more biometric tests;

identifying, based on results of searching, an application service which has an active session with the user and supports the one or more biometric tests;

requesting the application service to perform multifactor authentication that includes the one or more biometric tests;

receiving, from the application service, biometric test results that indicate whether each of the one or more biometric tests passed or failed; and

determining that the authentication has passed or failed based on the biometric test results.

2 . The method of claim 1 , wherein:

determining that the authentication has passed or failed includes determining that the authentication has passed when the biometric test results indicate that each biometric test has passed; and

the method further comprises: when the authentication has passed, sending an authentication token to the user device.

3 . The method of claim 2 , further comprising:

verifying that the identity provider has a trust relationship with the target application,

wherein determining that the authentication has passed further includes determining that the authentication has passed when the application service and the target application have the trust relationship and the trust relationships with the identity provider and each biometric test has passed.

4 . The method of claim 2 , wherein:

determining that the authentication has passed or failed includes determining that the authentication has failed when the biometric test results indicate that the one or more biometric tests have failed; and

the method further comprises: when the authentication has failed, sending to the user device a device request to perform the multifactor authentication of the user that is to be satisfied through the user device.

5 . The method of claim 1 , wherein:

receiving the request includes receiving the request to include a user identity of the user; and

identifying the one or more biometric tests includes searching multifactor authentication user profiles that include mappings of biometric tests to user identities based on the user identity.

6 . The method of claim 1 , wherein:

identifying the one or more biometric tests includes identifying, as the one or more biometric tests, facial recognition that includes capturing video of the user and comparing the video to a faceprint of the user, voice recognition that includes capturing voice of the user and comparing the voice to a voiceprint of the user, or fingerprint recognition that includes capturing a fingerprint reading from the user and comparing the fingerprint reading to a known fingerprint of the user; and

requesting includes requesting the application service to perform the facial recognition, the voice recognition, or the fingerprint recognition.

7 . The method of claim 1 , wherein:

the request includes a first timestamp;

the biometric test results include a second timestamp; and

the method further comprises: upon determining that the first timestamp and the second timestamp both fall within a predetermined time period, performing determining that the authentication has passed or failed.

8 . The method of claim 7 , further comprising:

upon determining that the first timestamp and the second timestamp do not both fall within the predetermined time period, not performing determining that the authentication has passed or failed.

9 . The method of claim 1 , wherein:

the biometric test results further include digital signatures appended by the application service.

10 . The method of claim 1 , wherein:

each biometric test result that indicates that a biometric test has passed further includes a confidence that the biometric test has passed; and

determining that the authentication has passed or failed includes determining that the authentication has passed when each confidence exceeds a predetermined confidence threshold.

11 . The method of claim 1 , further comprising, by the identity provider:

establishing the trust relationships with the application service; and

establishing a trust relationship with the target application.

12 . The method of claim 1 , wherein:

the application service includes a collaboration service supported by a meeting server and an endpoint device that operates under control of the meeting server and supports the one or more biometric tests.

13 . An apparatus comprising:

a network interface to communicate with a network; and

a processor of an identity provider, wherein the processor is coupled to the network interface and is configured to perform, upon receiving a request for authentication of a user to a target application that is hosted on a user device and into which the user has logged-in:

storing a list of application services having trust relationships with the identity provider and that are mapped to biometric sensors provided by each application service;

identifying one or more biometric tests to be applied to the user to satisfy the request;

searching the list of application services based on the one or more biometric tests;

identifying, based on results of searching, an application service which has an active session with the user and supports the one or more biometric tests;

requesting the application service to perform multifactor authentication that includes the one or more biometric tests;

receiving, from the application service, biometric test results that indicate whether each of the one or more biometric tests passed or failed; and

determining that the authentication has passed or failed based on the biometric test results.

14 . The apparatus of claim 13 , wherein:

the processor is configured to perform determining that the authentication has passed or failed by determining that the authentication has passed when the biometric test results indicate that each biometric test has passed; and

the processor is further configured to perform: when the authentication has passed, sending an authentication token to the user device.

15 . The apparatus of claim 14 , wherein the processor is further configured to perform:

verifying that the identity provider has a trust relationship with the target application,

wherein the processor is configured to perform determining that the authentication has passed by determining that the authentication has passed when the application service and the target application have the trust relationship and the trust relationships with the identity provider and each biometric test has passed.

16 . The apparatus of claim 14 , wherein:

the processor is configured to perform determining that the authentication has passed or failed by determining that the authentication has failed when the biometric test results indicate that the one or more biometric tests have failed; and

the apparatus further comprises: when the authentication has failed, sending to the user device a device request to perform the multifactor authentication of the user that is to be satisfied through the user device.

17 . The apparatus of claim 13 , wherein:

the processor is configured to perform receiving the request by receiving the request to include a user identity of the user; and

the processor is configured to perform identifying the one or more biometric tests by searching multifactor authentication user profiles that include mappings of biometric tests to user identities based on the user identity.

18 . A non-transitory computer readable medium encoded with instructions that, when executed by a processor of an identity provider, cause the processor to perform:

upon receiving a request for authentication of a user to a target application that is hosted on a user device and into which the user has logged-in:

storing a list of application services having trust relationships with the identity provider and that are mapped to biometric sensors provided by each application service;

identifying one or more biometric tests to be applied to the user to satisfy the request;

searching the list of application services based on the one or more biometric tests;

identifying, based on results of searching, an application service which has an active session with the user and supports the one or more biometric tests;

requesting the application service to perform multifactor authentication that includes the one or more biometric tests;

receiving, from the application service, biometric test results that indicate whether each of the one or more biometric tests passed or failed; and

determining that the authentication has passed or failed based on the biometric test results.

19 . The non-transitory computer readable medium of claim 18 , wherein:

the instructions to cause the processor to perform determining that the authentication has passed or failed include instructions to cause the processor to perform determining that the authentication has passed when the biometric test results indicate that each biometric test has passed; and

the instructions further comprise instructions to cause the processor to perform: when the authentication has passed, sending an authentication token to the user device.

20 . The non-transitory computer readable medium of claim 19 , further comprising instructions to cause the processor to perform:

verifying that the identity provider has a trust relationship with the target application,

wherein the instructions to cause the processor to perform determining that the authentication has passed further include instructions to cause the processor to perform determining that the authentication has passed when the application service and the target application have the trust relationship and the trust relationships with the identity provider and each biometric test has passed.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 1, 2024
From: HOLL, STEVEN MICHAEL; ENGLE, MATTHEW ROBERT; KUHNE, JASON A.; COLEMAN, JASON MICHAEL
To: CISCO TECHNOLOGY, INC.
Reel/Frame 066759/0150 →
Continuity (1)
Related Publication 20250274449A1 · Aug 28, 2025
References Cited (97)
US 6061791A · Moreau · 2000 [cited by applicant]
US 6301658B1 · Koehler · 2001 [cited by applicant]
US 6766160B1 · Lemiläinen et al. · 2004 [cited by applicant]
US 6857072B1 · Schuster et al. · 2005 [cited by applicant]
US 7242923B2 · Perera et al. · 2007 [cited by applicant]
US 7443817B2 · Farnham · 2008 [cited by applicant]
US 7590418B1 · Thomson · 2009 [cited by applicant]
US 7673004B1 · Sherstinsky et al. · 2010 [cited by applicant]
US 7814311B2 · Convery et al. · 2010 [cited by applicant]
US 8887243B2 · Thomson et al. · 2014 [cited by applicant]
US 9038157B1 · Santiago, Jr. et al. · 2015 [cited by applicant]
US 9363108B2 · Bell et al. · 2016 [cited by applicant]
US 9432339B1 · Bowness · 2016 [cited by applicant]
US 9467811B2 · Nilsson · 2016 [cited by applicant]
US 9717106B2 · Bell et al. · 2017 [cited by applicant]
US 9871791B2 · Blinn · 2018 [cited by applicant]
US 9967750B1 · Fernandez et al. · 2018 [cited by applicant]
US 10382413B1 · Friel et al. · 2019 [cited by applicant]
US 11265302B2 · Friel et al. · 2022 [cited by applicant]
US 11449589B2 · Gehrmann · 2022 [cited by examiner]
US 11750583B2 · Friel et al. · 2023 [cited by applicant]
US 12010513B2 · Hanley · 2024 [cited by examiner]
US 20020044658A1 · Wasilewski et al. · 2002 [cited by applicant]
US 20020126701A1 · Requena · 2002 [cited by applicant]
US 20020141586A1 · Margalit et al. · 2002 [cited by applicant]
US 20030014372A1 · Wheeler et al. · 2003 [cited by applicant]
US 20040002902A1 · Muehlhaeuser · 2004 [cited by applicant]
US 20050010780A1 · Kane et al. · 2005 [cited by applicant]
US 20050086300A1 · Yeager et al. · 2005 [cited by applicant]
US 20050239453A1 · Vikberg et al. · 2005 [cited by applicant]
US 20050286466A1 · Tagg et al. · 2005 [cited by applicant]
US 20060007920A1 · Michel et al. · 2006 [cited by applicant]
US 20060083187A1 · Dekel · 2006 [cited by applicant]
US 20060110011A1 · Cohen · 2006 [cited by examiner]
US 20060233166A1 · Bou-Diab et al. · 2006 [cited by applicant]
US 20060293028A1 · Gadamsetty et al. · 2006 [cited by applicant]
US 20070016444A1 · Holkkola · 2007 [cited by applicant]
US 20070030824A1 · Ribaudo et al. · 2007 [cited by applicant]
US 20070178882A1 · Teunissen et al. · 2007 [cited by applicant]
US 20070274270A1 · Jones et al. · 2007 [cited by applicant]
US 20070277230A1 · Hawkins et al. · 2007 [cited by applicant]
US 20080140868A1 · Kalayjian et al. · 2008 [cited by applicant]
US 20080159266A1 · Chen et al. · 2008 [cited by applicant]
US 20080226070A1 · Herz · 2008 [cited by applicant]
US 20090081999A1 · Khasawneh et al. · 2009 [cited by applicant]
US 20090119762A1 · Thomson et al. · 2009 [cited by applicant]
US 20090170519A1 · Wilhoite et al. · 2009 [cited by applicant]
US 20090198997A1 · Yeap et al. · 2009 [cited by applicant]
US 20090201917A1 · Maes et al. · 2009 [cited by applicant]
US 20090247194A1 · Tarrago et al. · 2009 [cited by applicant]
US 20090325491A1 · Bell et al. · 2009 [cited by applicant]
US 20100241748A1 · Ansari et al. · 2010 [cited by applicant]
US 20110113245A1 · Varadarajan · 2011 [cited by applicant]
US 20120212323A1 · Skaaksrud et al. · 2012 [cited by applicant]
US 20130117801A1 · Shieh et al. · 2013 [cited by applicant]
US 20130254858A1 · Giardina et al. · 2013 [cited by applicant]
US 20130262863A1 · Yoshino et al. · 2013 [cited by applicant]
US 20130326614A1 · Truskovsky et al. · 2013 [cited by applicant]
US 20130339722A1 · Krendelev et al. · 2013 [cited by applicant]
US 20140201517A1 · Corrion · 2014 [cited by applicant]
US 20140359722A1 · Schultz · 2014 [cited by examiner]
US 20140380425A1 · Lockett et al. · 2014 [cited by applicant]
US 20150007279A1 · Hattori · 2015 [cited by applicant]
US 20150256338A1 · Roberts · 2015 [cited by applicant]
US 20150281184A1 · Cooley · 2015 [cited by applicant]
US 20150281185A1 · Cooley · 2015 [cited by applicant]
US 20160036808A1 · Li · 2016 [cited by applicant]
US 20160337131A1 · de Andrada · 2016 [cited by examiner]
US 20160364559A1 · Bali · 2016 [cited by examiner]
US 20170126404A1 · Unagami et al. · 2017 [cited by applicant]
US 20170126661A1 · Brannon · 2017 [cited by applicant]
US 20170127276A1 · Koo et al. · 2017 [cited by applicant]
US 20170266562A1 · Hong · 2017 [cited by applicant]
US 20170279733A1 · Marshall et al. · 2017 [cited by applicant]
US 20180096118A1 · Perotti · 2018 [cited by examiner]
US 20190058989A1 · Park et al. · 2019 [cited by applicant]
US 20190089702A1 · Bhatt · 2019 [cited by examiner]
US 20200007333A1 · Young · 2020 [cited by examiner]
US 20200250664A1 · Kumar et al. · 2020 [cited by applicant]
US 20200322330A1 · Lynn · 2020 [cited by examiner]
US 20210037009A1 · Yang · 2021 [cited by examiner]
US 20220255923A1 · Szigeti et al. · 2022 [cited by applicant]
US 20220321556A1 · Gandhi · 2022 [cited by examiner]
US 20230014970A1 · Gujarathi et al. · 2023 [cited by applicant]
US 20230065478A1 · Lee · 2023 [cited by examiner]
CN 105074716A · 2015 [cited by applicant]
GB 2457491A · 2009 [cited by applicant]
WO 2012142354A1 · 2012 [cited by applicant]
WO 2013128470A1 · 2013 [cited by applicant]
WO 2023147459A2 · 2023 [cited by applicant]
Baygin, S., et al., “Authenticated Access into Secure Meetings for Video Conferencing Systems,” Technical Disclosure Commons, Defensive Publications Series, www.tdcommons.org/dpubs_series/3477/, Jul. 31, 2020, 7 pages. [cited by applicant]
Bluetooth, “Simple Pairing Whitepaper,” Special Interest Group, Released Version, https://docplayer.net/21765191-Simple-pairing-whitepaper.html, Aug. 3, 2006, 23 pages. [cited by applicant]
Bluetooth, “Specification of the Bluetooth System, Wireless Connections Made Easy,” Master Table of Contents & Compliance Requirements, Bluetooth Specification version 2.1+EDR, Jul. 26, 2007, 1415 pages. [cited by applicant]
Mcgrew D., et al., “Encrypted Key Transport for Secure RTP,” AVT Working Group, https://datatracker.ietf.org/doc/draft-ietf-avtcore-srtp-ekt/00/, Jul. 9, 2012, 51 pages. [cited by applicant]
Microsoft, “End to End Trust Progress,” https://web.archive.org/web/20140223011230/https://www.microsoft.com/mscorp/twc/endtoendtrust/vision/reputation.aspx, retrieved Mar. 13, 2014, 2 pages. [cited by applicant]
MIT Kerberos Consortium, “The Role of Kerberos in Modern Information Systems,” https://www.kerberos.org/software/rolekerberos.pdf, retrieved Feb. 13, 2024, 53 pages. [cited by applicant]
Perspecsys, “Cloud Data Encryption Primer,” Cloud Data Encryption & SaaS Protection, retrieved on Jan. 24, 2014, 6 pages. [cited by applicant]