Secondary device as key for authorizing access to resources

US9401915B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9401915-B2
Application numberUS-201314083718-A
CountryUS
Kind codeB2
Filing dateNov 19, 2013
Priority dateMar 15, 2013
Publication dateJul 26, 2016
Grant dateJul 26, 2016

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A secondary device may be used to provide access to resources to a primary device. Upon receiving an authorization indication at a device, a registration key based on the authorization indication, a user identifier, and a property of the device may be created. Upon determining whether access to at least one resource is permitted according to the registration key the device may be permitted to access the at least one resource.

First claim

Opening claim text (preview).

What is claimed is: 1. A method comprising: transmitting, from a device, a request to an authorization service for access to at least one resource; receiving from the authorization service an indication that the device must comply with a distribution rule associated with the at least one resource, wherein the distribution rule requires a specified secondary device to be in proximity to the device as a prerequisite to accessing the at least one resource; transmitting an indication that the device is in proximity to the secondary device; receiving an authorization indication at the device in response to transmitting the indication that the device is in proximity to the secondary device; creating a registration key based on the authorization indication, a user identifier, and a property of the device; determining whether access to at least one resource is permitted according to the registration key; obtaining an authorization credential from the secondary device, the authorization credential being associated with the at least one resource; and in response to determining that access to the at least one resource is permitted according to the registration key and receiving the authentication credential, permitting the device to access the at least one resource. 2. The method of claim 1 , wherein the authorization indication is received in response to a user-initiated action. 3. The method of claim 1 , wherein the authorization indication is received from a second device operative to transmit the authorization indication. 4. The method of claim 1 , further comprising: receiving the authorization indication in response to determining that a compliance rule associated with the authorization indication has been satisfied. 5. The method of claim 1 , wherein determining whether access to the at least one resource is permitted according to the registration key comprises: retrieving an identifier associated with the at least one resource; submitting the registration key and the identifier associated with the at least one resource to a verification service; and determining whether an access key for the at least one resource has been received from the verification service. 6. The method of claim 1 , wherein the authorization indication comprises a unique identifier associated with the device. 7. The method of claim 1 , wherein the registration key is associated with a plurality of compliance rules. 8. The method of claim 7 , wherein at least one of the plurality of compliance rules comprises a required proximity between the device and at least one second device. 9. The method of claim 7 , wherein at least one of the plurality of compliance rules comprises an expiration time for the registration key. 10. The method of claim 1 , further comprising: displaying an indication on a user interface of the device associated with the registration key. 11. An apparatus comprising: a memory storage; and a processor coupled to the memory storage operative to execute instructions for: obtaining a request for an indication associated with access to a resource from a user device, determining whether the resource is associated with a distribution rule, the distribution rule specifying that the user device be in proximity to a secondary device as a prerequisite for accessing the resource, obtaining an indication that the user device is in proximity to the secondary device, providing an authorization indication to the user device, the authorization indication authorizing access to the resource, receiving a registration key from the user device and an authorization credential provided by the secondary device, the registration key being generated by the user device based upon the authorization indication and the authorization credential obtained from the secondary device by the user device, creating a profile for the user device according to the registration key, associating a plurality of compliance rules with the profile for the user device, receiving a request to access a resource from the user device, determining whether the user device is in compliance with the plurality of compliance rules, and in response to determining that the user device is in compliance with the plurality of compliance rules, providing access to the resource to the user device. 12. The apparatus of claim 11 , wherein the processor is further operative to execute instructions for: detecting an arrival of the user device within a geographic location served by the apparatus; and providing the authorization indication to the user device automatically. 13. The apparatus of claim 11 , wherein the processor is further operative to execute instructions for: receiving a request from the user device; and providing the authorization indication to the user device in response to the request. 14. The apparatus of claim 11 , wherein the processor is further operative to execute instructions for: providing at least one restriction on the resource to the user device. 15. A client device comprising: a network connectivity interface for enabling communication between the client device and an authorization service via a network; a memory for storing a client side application; and a processor communicatively coupled to the memory for executing said client side application, wherein said client side application comprises executable instructions for: transmitting a request to an authorization service for access to at least one resource; receiving from the authorization service an indication that the client device must comply with a distribution rule associated with the resource, wherein the distribution rule requires a second device to be in proximity to the client device as a prerequisite to accessing the at least one resource; obtaining an authorization credential from the second device; transmitting to the authorization service an indication that the client device is in proximity to the second device and the authorization credential; receiving an authorization indication associated with a geographic location from the second device located within the geographic location in response to transmitting the indication that the device is in proximity to the second device; creating a registration key based on the authorization indication, a user identifier, and a property of the client device; providing the registration key to the second device; determining whether the second device approved the registration key; and in response to determining that the second device approved the registration key, requesting access to the at least one resource. 16. The client device of claim 15 , wherein requesting access to the at least one resource comprises providing the authorization credential to the authorization service associated with the at least one resource. 17. The client device of claim 15 , wherein the authorization credential comprises at least one compliance restriction. 18. The client device of claim 15 , wherein the authorization indication is received as a broadcast signal from the second device. 19. The client device of claim 15 , wherein the property of the client device comprises a unique identifier associated with the client device.

Assignees

Inventors

Classifications

  • wherein the data content is protected, e.g. by encrypting or encapsulating the payload · CPC title

  • using an additional device, e.g. smartcard, SIM or a different communication terminal (cryptographic mechanisms or cryptographic arrangements for entity authentication involving additional secure or trusted devices H04L9/3234) · CPC title

  • Entity profiles · CPC title

  • for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title

  • wherein the security policies are location-dependent, e.g. entities privileges depend on current location or allowing specific operations only from locally connected terminals · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9401915B2 cover?
A secondary device may be used to provide access to resources to a primary device. Upon receiving an authorization indication at a device, a registration key based on the authorization indication, a user identifier, and a property of the device may be created. Upon determining whether access to at least one resource is permitted according to the registration key the device may be permitted to a…
Who is the assignee on this patent?
Skysocket Llc, Airwatch Llc
What technology area does this patent fall under?
Primary CPC classification H04L63/0853. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jul 26 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 2 related publications on this page (citations in our corpus or others sharing the same primary CPC).