IP Library Patent Application 19038239
Patent Application
App. No. 19/038,239

ANONYMOUS GUEST DEVICE TOKEN

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
19/038,239
Abstract

A guest control device communicates, to a first playback device, a self-signed authorization assertion. The guest control device then receives a signed local-access token. The signed local-access token is signed by the first playback device and allows the guest control device to access services provided by playback devices on the local area network. The guest control device communicates to a cloud network a cloud authorization grant assertion. The cloud authorization grant assertion comprises at least a portion of the signed local-access token. The at least the portion of the signed local-access token comprises an identifier for the first playback device. The guest control device then receives a cloud guest token. The cloud guest token is signed by the cloud network and allows the guest control device to access services on the local area network that are provided by the cloud network.

Claims (58)

1 . A guest control device comprising:

at least one processor; and

at least one non-transitory computer-readable medium comprising program instructions that are executable by the at least one processor such that the guest control device is configured to:

communicate, through a local area network to a media playback system comprising a first playback device, a self-signed authorization assertion;

receive, from the first playback device, a signed local-access token, wherein the signed local-access token is signed by the first playback device and allows the guest control device to access services via playback devices on the local area network;

communicate, to a cloud network, a cloud authorization grant assertion, wherein the cloud authorization grant assertion comprises:

at least a portion of the signed local-access token, wherein the at least the portion of the signed local-access token comprises an identifier for the first playback device; and

receive, from the cloud network, a cloud guest token, wherein the cloud guest token is signed by the cloud network and allows the guest control device to access cloud-based services associated with the playback devices on the local area network.

2 . The guest control device as recited in claim 1 , wherein the cloud authorization grant assertion comprises a signature associated with the guest control device.

3 . The guest control device as recited in claim 2 , wherein the identifier for the first playback device is relied upon to indicate that the guest control device is physically present on the same local area network as the first playback device.

4 . The guest control device as recited in claim 1 , wherein the signed local-access token comprises a first playback device identifier and a token expiration time.

5 . The guest control device as recited in claim 4 , wherein at least the token expiration time relies upon a network device relative time that is derived independent of an external time source, the network device relative time further comprising:

a first unique relative time identifier, and

a first relative time indicator that increments or decrements from a pre-determined event.

6 . The guest control device as recited in claim 5 , wherein the at least one non-transitory computer-readable medium further comprises program instructions that are executable by the at least one processor such that the guest control device is configured to:

communicate to a second playback device, through the local area network, a local command that is configured to cause the second playback device to perform a function, wherein the local command comprises the signed local-access token;

identify, at the second playback device, the first playback device identifier within the signed local-access token;

communicate, from the second playback device to the first playback device, a request for a second unique relative time identifier and a second relative time indicator; and

compare the first unique relative time identifier and the token expiration time within the signed local-access token with the second unique relative time identifier and the second relative time indicator.

7 . The guest control device as recited in claim 6 , wherein the at least one non-transitory computer-readable medium further comprises program instructions that are executable by the at least one processor such that the guest control device is configured to: when the first unique relative time identifier indicates that the token expiration time has lapsed, reject the local command.

8 . The guest control device as recited in claim 6 , wherein the at least one non-transitory computer-readable medium further comprises program instructions that are executable by the at least one processor such that the guest control device is configured to: when the first relative time indicator and the second relative time indicator fail to match, reject the local command.

9 . The guest control device as recited in claim 4 , wherein the at least one non-transitory computer-readable medium further comprises program instructions that are executable by the at least one processor such that the guest control device is configured to:

communicate, to the cloud network, a cloud command that is configured to cause the cloud network to provide information to be displayed at the guest control device or at the first playback device, wherein the cloud command comprises the cloud guest token;

identify, at the cloud network, the first playback device identifier within the cloud guest token; and

after determining that the cloud guest token has not expired, display the information at the guest control device.

10 . The guest control device as recited in claim 1 , wherein the local area network comprises a personal area network.

11 . The guest control device as recited in claim 1 , wherein the signed local-access token is not associated with a user account.

12 . A cloud network comprising:

at least one processor; and

at least one non-transitory computer-readable medium comprising program instructions that are executable by the at least one processor such that the cloud network is configured to:

receive, at the cloud network, a cloud authorization grant assertion from a guest control device, wherein the cloud authorization grant assertion comprises at least a portion of a signed local-access token, wherein:

the signed local-access token was generated in response to a self-signed authorization assertion sent from the guest control device to a first playback device on a local area network shared by the guest control device,

the signed local-access token is signed by the first playback device and allows the guest control device to access services via playback devices on the local area network, and

the at least the portion of the signed local-access token comprises an identifier for the first playback device;

verify the signed local-access token is valid; and

send, to the guest control device, a cloud guest token, wherein the cloud guest token is signed by the cloud network and allows the guest control device to access cloud-based services associated with the playback devices on the local area network.

13 . The cloud network as recited in claim 12 , wherein the cloud authorization grant assertion comprises a signature associated with the guest control device.

14 . The cloud network as recited in claim 13 , wherein the identifier for the first playback device is relied upon to indicate that the guest control device is physically present on the same local area network as the first playback device.

15 . The cloud network as recited in claim 12 , wherein the signed local-access token comprises a first playback device identifier and a token expiration time.

16 . The cloud network as recited in claim 15 , wherein at least the token expiration time relies upon a network device relative time that is derived independent of an external time source, the network device relative time further comprising:

a first unique relative time identifier, and

a first relative time indicator that increments or decrements from a pre-determined event.

17 . The cloud network as recited in claim 16 , further comprising a second playback device, wherein the second playback device comprises another non-transitory computer-readable medium that comprises program instructions that are executable by another at least one processor such that the second playback device is configured to:

receive at the second playback device, from the guest control device, a local command that is configured to cause the second playback device to perform a function, wherein the local command comprises the signed local-access token;

identify, at the second playback device, the first playback device identifier within the signed local-access token;

communicate, from the second playback device to the first playback device, a request for a second unique relative time identifier and a second relative time indicator; and

compare the first unique relative time identifier and the token expiration time within the signed local-access token with the second unique relative time identifier and the second relative time indicator.

18 . The cloud network as recited in claim 17 , when the first unique relative time identifier indicates that the token expiration time has lapsed, reject the local command.

19 . The cloud network as recited in claim 15 , wherein the at least one non-transitory computer-readable medium further comprises program instructions that are executable by the at least one processor such that the cloud network is configured to:

receive, at the cloud network, a cloud command that is configured to cause the cloud network to provide information to be displayed at the guest control device or at the first playback device, wherein the cloud command comprises the cloud guest token;

identify, at the cloud network, the first playback device identifier within the cloud guest token; and

after determining that the cloud guest token has not expired, communicate the information to the guest control device.

20 . A computer-implemented method for authenticating a guest control device, the computer-implemented method comprising:

communicating, through a local area network to a media playback system comprising a first playback device, a self-signed authorization assertion;

receiving, from the first playback device, a signed local-access token, wherein the signed local-access token is signed by the first playback device and allows the guest control device to access services via playback devices on the local area network;

communicating, to a cloud network, a cloud authorization grant assertion, wherein the cloud authorization grant assertion comprises:

at least a portion of the signed local-access token, wherein the at least the portion of the signed local-access token comprises an identifier for the first playback device; and

receiving, from the cloud network, a cloud guest token, wherein the cloud guest token is signed by the cloud network and allows the guest control device to access cloud-based services associated with the playback devices on the local area network.

Assignments (2)
SECURITY INTEREST Recorded Jan 30, 2026
From: SONOS, INC.
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 074533/0615 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 3, 2025
From: ANELLO, DOMINIC; GREENBERG, BENJAMIN
To: SONOS, INC.
Reel/Frame 070385/0608 →