System and method for authenticating multiple devices with a same credential

Inventors

Le Nerriec, Yohan • Bing, Jehan Gerard • Guion, Alexandre • Menter, Judah John • Tai, Daniel D.

Assignees

Qualcomm Inc • Qualcomm Atheros Inc • Orb Networks Inc

Interested in licensing this patent?

MTEC can help explore whether this patent might be available for licensing for your application.

Publication Number

US-9178962-B2

Patent

Publication Date

2015-11-03

Expiration Date


Abstract

A first device implements an application platform that is shared with a second device. The application platform can be implemented so that the first device and the second device operate to have a same identity to at least the network service. The first device provides a user interface in order to receive input for accessing or using the network service. Additionally, the first device communicates input received in response to providing the user interface to the network service. The first device can receive a token from the network service in response to communicating the input. Additionally, the first device can communicate a set of data items to the second device. The set of data items includes the token and one or more identifiers that enable the second device to access and use the network service while appearing as the first device to the network service.

Core Innovation

Describes a multi-device authentication and access architecture for a network service, where a first-in-time device and a follow on device access the network service using the set of credentials. The architecture identifies a device used to communicate the set of credentials and determines that the identified device is not a first-in-time device used to access the network service using the set of credentials.

It then determines whether a condition is satisfied for authenticating the identified device as a follow on device to the first-in-time device. The condition includes the identified device accessing the network service using the set of credentials within a defined time period following the first-in-time device accessing the network service using the set of credentials.

If the condition is satisfied, the system permits access to the network service for the identified device based on the set of user credentials. Also includes enabling access such that the first-in-time device and the identified device access the network service within the same session when permitted, and the disclosed credential set can include a password and/or an encrypted token.

Claims Coverage

The independent claims include four inventive features centered on device identification, first-in-time vs follow-on determination, conditional authentication based on a defined time period following first-in-time access, and permit/deny control of access using the set of user credentials. Four independent claim forms are presented: system (processor-based), method, non-transitory computer-readable medium, and system with means-plus-functions.

Device identification for credential communication

Identify a device used to communicate a set of credentials.

First-in-time determination

Determine that the identified device is not a first-in-time device used to access a network service using the set of credentials.

Condition-based follow-on authentication within a defined time period

Make a determination as to whether a condition is satisfied for authenticating the identified device as a follow on device to the first-in-time device, the condition including the identified device accessing the network service using the set of credentials within a defined time period following the first-in-time device accessing the network service using the set of credentials.

Permit access only if the follow-on condition is satisfied

If the condition is satisfied, permit access to the network service for the identified device based on the set of user credentials; else deny access to the network service.

Across the independent claims, access to a network service is governed by identifying a credential-communicating device, rejecting first-in-time status, authenticating the device only when a follow-on condition is satisfied, and permitting or denying access based on the set of user credentials.

Stated Advantages

Documented Applications

No documented applications found

JOIN OUR MAILING LIST

Stay Connected with MTEC

Keep up with active and upcoming solicitations, MTEC news and other valuable information.