Mobile device authentication

US12418794B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12418794-B2
Application numberUS-201615175927-A
CountryUS
Kind codeB2
Filing dateJun 7, 2016
Priority dateJul 15, 2011
Publication dateSep 16, 2025
Grant dateSep 16, 2025

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A desktop is unlocked or locked using a mobile client device, such as a smart phone, tablet, smart watch, etc. The authentication mechanism of the mobile client device, such as fingerprint, facial recognition, voice recognition, username and password, is leveraged for faster, less-cumbersome user authentication on the desktop. In this vein, a client device is added to an authentication agent on the desktop, and the desktop recognizes successful attempts to access the mobile client device as a method of unlocking or locking the desktop.

First claim

Opening claim text (preview).

We claim: 1. A method, comprising: prior to authorizing a client device to access a desktop: registering the client device with an authentication agent of the desktop, the authentication agent obtaining information for an authentication mechanism from the client device, the authentication mechanism configured to authenticate a user on the client device to unlock the desktop, the desktop hosted by a hypervisor running on the client device; receiving an indication on the client device corresponding to the authentication mechanism; determining that the indication is an authorized unlocking indication; upon determining that the indication is an authorized unlocking indication, transmitting client device credentials to a desktop management server, wherein the desktop management server is configured to compare the client device credentials with an enterprise administrative policy to determine whether the client device satisfies the enterprise administrative policy, the enterprise administrative policy comprising the client device being within (i) a given location and (ii) a time of day at which the indication is received; and upon the client device being determined to satisfy the enterprise administrative policy, transmitting the authorized unlocking indication from a desktop agent of the client device to the desktop in a side channel between the desktop agent and the desktop, the side channel authorized for non-display traffic by the desktop management server, wherein the desktop is configured to determine that the client device has been registered with the authentication agent, and determine, based on the authorized unlocking indication, whether the client device is authorized to access the desktop, before unlocking the desktop. 2. The method of claim 1 , wherein the client device is provided with a token to access the desktop management server. 3. The method of claim 1 , wherein the indication comprises sequentially touching specifically displayed elements on the client device. 4. The method of claim 1 , wherein the enterprise administrative policy includes rules associated with one or more of an access level and an access frequency. 5. The method of claim 1 , wherein the authentication mechanism includes one or more of a thermogram and gait recognition. 6. The method of claim 1 , wherein the indication includes a sequence of a plurality of related events that satisfies the enterprise administrative policy. 7. The method of claim 1 , further comprising: receiving the indication on a smart watch; and transmitting the indication from a smart phone to the desktop to unlock the desktop. 8. The method of claim 1 , wherein authenticating the user on the client device includes receiving authentication data comprising one or more of voice recognition information and facial recognition information. 9. A system, comprising: one or more memories storing computer-executable instructions; and one or more processors operationally coupled to the one or more memories and configured to execute the computer-executable instructions to: prior to authorizing a client device to access a desktop: register the client device with an authentication agent of the desktop, the authentication agent obtaining information for an authentication mechanism from the client device, the authentication mechanism configured to authenticate a user on the client device unlock the desktop, the desktop hosted by a hypervisor running on the client device; receive an indication, on the client device, corresponding to the authentication mechanism; determine that the indication is an authorized unlocking indication; upon determining that the indication is an authorized unlocking indication, transmit client device credentials of the client device to a desktop management server, wherein the desktop management server is configured to compare the client device credentials with an enterprise administrative policy to determine whether the client device satisfies the enterprise administrative policy, the enterprise administrative policy comprising the client device being within (i) a given location and (ii) a time of day at which the indication is received; and upon the client device being determined to satisfy the enterprise administrative policy, transmit the authorized unlocking indication from a desktop agent of the client device to the desktop in a side channel between the desktop agent and the desktop, the side channel authorized for non-display traffic by the desktop management server, wherein the desktop is configured to determine that the client device has been registered with the authentication agent, and determine, based on the authorized unlocking indication, whether the client device is authorized to access the desktop, before unlocking the desktop. 10. The system of claim 9 , wherein the client device is provided with a token to access the desktop management server. 11. The system of claim 9 , wherein the indication comprises sequentially touching specifically displayed elements on the client device. 12. The system of claim 9 , wherein the indication includes a sequence of a plurality of related events that satisfies the enterprise administrative policy. 13. The system of claim 9 , wherein the authentication mechanism includes one or more of: a thermogram and gait recognition. 14. The system of claim 9 , wherein authenticating a user on a client device includes receiving authentication data comprising one or more of voice recognition information and facial recognition information. 15. A non-transitory computer-storage memory embodied with instructions executable by one or more processors to enable remote authentication of a desktop by a client device, the instructions comprising: prior to authorizing the client device to access a desktop: registering the client device with an authentication agent of the desktop, the authentication agent obtaining information for an authentication mechanism from the client device, the authentication mechanism configured to authenticate a user on the client device to unlock the desktop, the desktop hosted by a hypervisor running on the client device; receiving an indication on the client device corresponding to the authentication mechanism; determine whether the indication is an authorized unlocking indication; upon determining that the indication is an authorized unlocking indication, transmitting client device credentials to a desktop management server, wherein the desktop management server is configured to compare the client device credentials with an enterprise administrative policy to determine, whether the client device satisfies the enterprise administrative policy, the enterprise administrative policy comprising the client device being within (i) a given location and (ii) a time of day at which the indication is received; and upon the client device being determined to satisfy the enterprise administrative policy, transmitting the authorized unlocking indication from a desktop agent of the client device to the desktop in a side channel between the desktop agent and the desktop. the side channel authorized for non-display traffic by the desktop management server, wherein the desktop is configured to determine that the client device has been registered with the authentication agent, and determine, based on the authorized unlocking indication, whether the client device is authorized to access the desktop, before unlocking the desktop. 16. The non-transitory computer-storage memory of claim 15 , wherein the client device is provided with a token to access the desktop management server.

Assignees

Inventors

Classifications

  • Indicating network or usage conditions on the user display · CPC title

  • using an additional device, e.g. smartcard, SIM or a different communication terminal (cryptographic mechanisms or cryptographic arrangements for entity authentication involving additional secure or trusted devices H04L9/3234) · CPC title

  • specially adapted for terminal emulation, e.g. Telnet · CPC title

  • Remote windowing, e.g. X-Window System, desktop virtualisation (protocols for virtual reality H04L67/131) · CPC title

  • using biometric data, e.g. fingerprints, iris scans or voiceprints · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12418794B2 cover?
A desktop is unlocked or locked using a mobile client device, such as a smart phone, tablet, smart watch, etc. The authentication mechanism of the mobile client device, such as fingerprint, facial recognition, voice recognition, username and password, is leveraged for faster, less-cumbersome user authentication on the desktop. In this vein, a client device is added to an authentication agent on…
Who is the assignee on this patent?
Omnissa Llc
What technology area does this patent fall under?
Primary CPC classification H04W12/06. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Sep 16 2025 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 10 related publications on this page (citations in our corpus or others sharing the same primary CPC).