Computer implemented method
The method uses access tokens to provide secure, delegated access to user account information, addressing the inefficiencies of shared video end-systems by enabling quick configuration and seamless switching, thus improving the setup process and collaboration in video conferencing.
Patent Information
- Authority / Receiving Office
- GB · GB
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-03-08
- Publication Date
- 2026-03-27
AI Technical Summary
Shared video end-systems lack intrinsic access to user account information, leading to laborious and time-consuming setup processes for conference calls, especially in cases of last-minute changes or ad-hoc meetings, and require manual intervention for each use.
A computer-implemented method using an access token to grant secure delegated access to user account information, enabling quick configuration of video end-systems by linking them to individual user accounts, allowing access to calendaring and contact information, and facilitating seamless switching between systems.
Enables rapid and secure access to user account information, reducing setup time and complexity, and enhancing collaboration across multiple video end-systems without the need for repeated authentication.
Smart Images

Figure 00000001_0000 
Figure 00000002_0000 
Figure 00000003_0000
Abstract
Description
Field of the Invention The present invention relates to a computer implemented method of accessing a user account from a video-end-system, and to a video end-system for video conferencing. Background Video conferencing systems typically comprise two or more endpoints, whereby each endpoint is configured to communicate with other endpoints through a data or telephony network or other connections for implementing a two-way or multiway video and / or audio conferencing call. An endpoint, which may also be referred to as a video end-system, is configured to enable users to communicate with other users over a network by sending data streams including audio, video and other content streams (e.g. data files, text, or screen sharing) from one endpoint to another in a two-party conference call. For a multiway conference call, the data streams may be transmitted to a centralised or distributed conferencing network where they are switched or transcoded allowing multiple participants to communicate and share information. A video end-system may comprise a single purpose endpoint device whose main function is to support video and / or audio conferencing calls. The video end-system may comprise separate video conferencing hardware including: one or more video monitors, video cameras, audio microphones, audio speakers, and a control interface for enabling users to control the video end-system. In some examples, a video end-system may be an all-in-one unit wherein the single purpose endpoint device and the video conferencing hardware are included in a same device, for example as a desktop unit or as a handheld device. In other examples, the video end-system may comprise an endpoint device (which may also be referred to as a main processor) which is connected to a large display screen, a control interface device, and a camera. This configuration may be suitable, e.g., for a small meeting room. In other examples, a video-end-system intended for larger rooms or lecture theatres may include an endpoint device which is connected to multiple display screens, one or more control interface devices, and multiple cameras and microphones. Often video end-systems are provided as shared video end-systems which are intended for use by multiple users in shared environments such as corporate meeting rooms. However, shared video endsystems traditionally do not have access to user accounts on a corporate computer infrastructure. Therefore, shared video end-systems typically do not have intrinsic access to information about meetings that users of the video end-system may need to attend or host. In one known example, a shared video end-system may be informed about a meeting by configuring the shared video end-system as a bookable resource in a corporate calendaring service. The shared video end-system may then be invited to meetings e.g. by email. The shared video end-system may then use the meeting invitation to display meeting details and provide fast access to the meeting, e.g. by providing a “Join Now” button on a control interface. However, this method of providing access to meeting information requires the shared video end-system (and a meeting room containing the shared video endsystem) to be strictly managed and allocated carefully to specific timeslots. This requires sufficient foreknowledge that a meeting will take place so that users can book the meeting room and invite it to the 5 meeting ahead of time. However, if a meeting requires a last-minute change of venue and of video end-system (for example when the allocation of a shared video end-system is not tightly controlled, or an ad-hoc conference call is required, or a meeting overruns) then it can be laborious and time consuming for the user to set up a new shared video end-system. Typically, the new video end-system will need to be chosen and a meeting ID 10 and password determined by the user and entered into the new video end-system to allow it to join the meeting. Additionally, a virtual meeting room may need to be created and the meeting ID and password communicated to the other participants in the conference call. Since the shared video end-system does not have intrinsic access to the user’s contact information this can be laborious and time consuming. Other examples of using a shared video end-system include establishing a temporary connection 15 between a user’s portable device and the shared video end-system. This connection may be established using a physical cable or adapter, or a using a temporary logical association e.g. via a wireless signal or the internet. For example, to create a temporary logical association, the shared video end-system may send a time or space-limited nonce to the user’s portable device to verify that an application running on the user’s device is in the physical vicinity of the video end-system. This may involve the use of QR 1 20 codes, Bluetooth, or ultrasonic signals to send the nonce. Once the nonce has been received, the logical connection may be established between in the shared video end-system and the personal device allowing LO the video end-system to access user account information (e.g. contact and calendar information). CM However, this method requires the user to set up the shared video end-system using an application on their personal device each time they wish to use the shared video end-system. This can be a complex 25 and time-consuming procedure. Accordingly, the present inventors have identified a desire a secure mechanism for granting a shared video end-system persistent access to user account information. The present invention has been devised in light of the above considerations. 30 Summary of the Invention According to a first aspect of the present invention there is provided a computer implemented method according to claim 1. Advantageously, by using an access token to access user account information the video end-system may be granted secure delegated access to user account information. In this way, the video end-system may 35 be configured more quickly by individual users who wish to securely link the video end-system to their user account for making conference calls. In the present invention the video-end-system is intended to refer to a dedicated video conferencing system which comprises function specific hardware and software for performing video conferencing calls. The video end-system may be a shared video end-system which is configured for use by multiple individual users. For example, the shared video end-system may be located in a corporate meeting room 5 which is available to be reserved and used by multiple users for making conference calls. The user account is one of a plurality of user accounts associated with users of the video end-system. For example, the user accounts may be corporate user accounts associated with users’ individual computer profiles which are accessible via a network. The computer implemented method may be a method of video conferencing. In this example, the 10 computer implemented method may further comprise: using the retrieved user account information to perform a conference call. For example, as discussed herein, the user account information may include information about planned meetings (e.g., included in calendaring information and / or contacts details associated with the user account). Therefore, the video end-system may be configured to use the information about planned meetings to configure a conference call. 15 The main processor may be a processing element of the video end-system which is configured to run system software for operating the video end-system and perform conference calls. The main processor may be configured to communicate with the video conferencing hardware and receive commands from the control interface. The main processor may be a separate end-point device such as a single-purpose computing device or a local server, which is connected (e.g. by wired or wireless connection) to the video conferencing hardware and a device including the control-interface. As such, the main processor may also be referred to as an endpoint device. In other examples, the main processor may form part of a single unit which also includes the control interface and / or the video conferencing hardware. The main processor may comprise a network interface for sending and receiving a content stream of a video conferencing call. 25 The main processor may be configured to perform some, or all, of the steps included in the computer implemented method of the first aspect. However, in some examples the video end-system may be in communication with a central server (which may also be referred to as a central configuration service). In these examples, some or all of the steps of the first aspect may be performed by the central server. This may be advantageous if the video end- 30 system is one of a plurality of video end-systems in communication with the central server. Therefore, a user may switch from one video end-system to another without needing to re-authenticate the second video end-system. For example, the central server may acquire a user access token configured to grant access to a user account. The central server may then use the access token to access the user account and provide the user account information to the video end-system. The central server may then use the 35 same access token provide the user account information to a second video end-system without needing to re-acquire the access token. Thus, by performing some or all of the steps the first aspect on a central server, a user may access their account from multiple video end-systems more quickly and efficiently. The video conferencing hardware may be devices which are in communication with the main processor for video conferencing. For example, the video conferencing hardware may comprise a camera and / or a display screen for sharing images and / or a video stream in a video conferencing call. Specifically, a video stream may be communicated from the camera to the video stream of a video conferencing call. One or 5 more additional video streams may be received from the video stream of the video conferencing call and displayed on the display screen. In some examples, the video end-system may comprise multiple cameras and display screens. The video conferencing hardware may also comprise a loudspeaker and a microphone for sending and receiving an audio stream of a conference call. Specifically, the video conferencing hardware may 10 comprise one or more loudspeakers (e.g. as area broadcasting speakers or as loudspeakers included in personal headphones) for producing audio content of a conferencing call. The video conferencing hardware may comprise one or more microphones from providing an audio stream for the content stream of a conferencing call. Each component of the video conferencing hardware (i.e., cameras, display screens, microphones, 15 loudspeakers, etc) may be provided as one or more integral units or as separate devices. The video conferencing hardware and the control interface may also be provided as one or more integral units or as separate devices. For example, a controller having a touch screen may serve as a display screen as well as the control interface. The control interface, which may also be referred to as a controller or a control interface device, may be any device comprising user input controls or a user interface for enabling users to control the video endsystem. For example, the control interface device may be a tablet comprising a touch-screen which a user may user to issue control signals to the video end-system by pressing buttons on the touch-screen. Other examples of control interface device may include a keyboard, a mouse, a control panel with mechanical buttons, a voice control device etc. For example, a user may use the control interface to 25 begin and end a conference call, add or remove parties from a conference call, adjust volume levels of speakers in the video end-system, configure display screen settings, etc. Multiple control interface devices may be provided which are connected to (e.g., via a wired or wireless connection) to the remainder of the video end-system. As mentioned above, the control interface and the video conferencing hardware may also be provided as 30 a single unit. In this example, the video end-system may be a single desktop or handheld unit which may also be referred to as a video end-device. In yet further examples, the control interface and video conferencing hardware may comprise separable units which are in communication with each other (e.g. via wired or wireless connections). A user account may be an identity or portion of resources which is allocated to an individual user or 35 resource on a computer or computing system (e.g., a computing system in a corporate account). The user account may be protected by security measures (e.g., a username and password) to prevent access by unwanted parties to the user account. The user account information may comprise any information or stored data which is associated with a user account. For example, the user account information may comprise login or authentication information associated with the user account. The user account information may also include a user’s emails, files, programs, account settings, and application status information stored within the user 5 account. In some examples, the user account information may include user calendar data. The user calendar data may include information about dates, times, and details of participants for conference calls which are scheduled in a user’s calendar. Therefore, by enabling the video end-system to access the user account information, a conference call which is scheduled in a user’s calendar may be configured automatically by 10 the video end-system e.g., according to date, time and / or participant information include in the calendar data. In further examples, the user account information may include user contacts data. For example, the video end-system may be given access to contact details (e.g., email address, phone number, name etc) of contacts who the user may wish to include in a conference call. Therefore, the video end-system may use 15 the user contacts data to automatically establish a conference call, send virtual meeting IDs and passwords etc for more efficiently configuring a conference call without requiring the user to manually grant access to the user contacts data. The user account information is located on a centralised collaboration service and the video end-system is configured to retrieve or access the user account information from the centralised collaboration service 20 via a network interface. For example, the centralised collaboration service may be a local corporate _ network which has access to corporate user accounts or user account information (e.g. calendar LT) information) from the corporate user accounts. Therefore, multiple video end-systems may be connected to the centralised collaboration service and access the same user accounts. This is particularly useful for increasing collaboration between the video end-system and other shared video end-systems which are 25 connected to the centralised collaboration service. For example, if a user wishes to switch from a first video end-system to a second video end-system at short notice, then the second video end-system may be able to access the user account information on the centralised collaboration service quickly and conveniently in order to take over from the first video end-system with minimal interference from the user. Acquiring the access token may refer to receiving an access token for the first time (e.g. from an 30 authentication service), or to retrieving an access token that has already been created. For example, (as described in more detail below) the video end-system may include or be connected to a store of access tokens associated with user accounts. The access token may be configured to enable the video end-system to access user account information. In other words, the access token may be configured to grant the video end-system secure, delegated 35 access to a user account. This process may include using the access token to authenticate the video end-system. Advantageously, by providing an access token for accessing the user account information, the video end-system may be conveniently granted access to the user account information without a user needing to manually supply the video end-system with user login details or other credentials for accessing the user account. Storing the access token for later use can advantageously enable persistent delegated access by the video end-system to user accounts after a session has ended. 5 For example, the access token may be a key, a piece of code, or data containing an identifier corresponding to the video end-system and security permissions configured to enable the video endsystem to access user account information. The access token may be associated with a particular user account and may be configured to enable the video end-system to access that user account. The access token may be created using an authentication service and communicated to the video end-10 system for storage. For example, a user of the video end-system may login to an authentication service (e.g. which is provided on a website or server). The authentication service may then verify the user’s identity using a verification process such as requiring a password or multi-factor authentication. The authentication service may then send an access token (or a code that can be exchanged for an access token) associated with the user’s account to the video end-system. The video end-system may then store 15 the access token for use by the video end-system for accessing that user account. In some examples, the video end-system may be configured to receive the access token from an authentication service or framework configured to provide delegated secure access to a resource. For example, the authentication service for providing delegated secure access may be OAuth2 (such as is described in RFC6749), or SAML (such as is described in RFC7522). 20 For example, acquiring the access token may include sending user authentication data to a website or a server which is running OAuth or SAML, and receiving the access token from the website or service. In other examples, the user of the video end-system may use a personal device or the control interface of the video end-system to login into a server or website which is running an authentication service (e.g., OAuth or SAML). The access token may then be sent to the video end-system from the website or 25 service. Using the access token to access the user account information may include verifying the access token to prove that the video end-system has permission to access the user account. If the video end-system is successfully verified, then the video end-system may retrieve the user account information. The video end-system may use the access token to gain full access to the user account (i.e., to login to 30 the user account and have unrestricted access to all of the data in the user account). In other examples, the video end-system may use the access token to gain partial access to the user account or to retrieve data from the user account. For example, the access token may enable the video end-system to retrieve user calendar information and user contact information, but restrict access by the video end-system to other resources in the user account (e.g. a user’s sensitive files or documents). 35 The access token may be stored on the video end-system. Therefore, in this example, acquiring the access token may comprise retrieving the access token from non-volatile memory in the video end system. The video end-system may be configured to store multiple access tokens associated with multiple respective user accounts. The video end-system may comprise the secure storage module which is configured to store a plurality of access tokens. Accordingly, acquiring the access token may include providing authentication data to the 5 secure storage module and retrieving the access token from the secure storage module. The secure storage module may be a local storage module so that the plurality of access tokens can be stored locally without requiring remote access to a remote storage module. In other examples, the access token may be stored on a central server. For example, multiple video endsystems may be connected to a central server (e.g. a corporate server) which is configured to host 10 multiple access tokens associated with respective user accounts (e.g. employing accounts). Usefully, in this way multiple video end-systems may be able to access the same user accounts increasing the collaboration and ease of use of the video end-system. This may be desired, for example, if a user switches from using a first video end-system to a second video end-system at short notice. Therefore, the second video end-system may be used to access the same user account information and continue a 15 conference call which was begun on the first video end-system. The access token may be stored in a secure storage module on the central server. Therefore, acquiring the access token may include providing authentication data to the secure storage module and retrieving the access token from the secure storage module the central server. -j— In the examples above, the secure storage module may include encrypted storage. The secure storage '^“20 model is configured to securely store one or more access tokens associated with respective user LO accounts. Therefore, acquiring the access token may include decrypting or unlocking the access token. The access token may be individually encrypted (i.e., locked) and / or the secure storage module may be encrypted. Acquiring the access token may include requesting and receiving confirmation from a user via the control 25 interface that the access token should be made available. In some examples, the computer implemented method may comprise receiving a passcode from a user via the control interface. Therefore, acquiring the access token may include decrypting or unlocking the user access token using the passcode. In some examples, the video end-system may be configured to determine if a user associated with the user access token is located or detected within a given physical proximity to the video end-system. In this 30 case, the access token may only be acquired if the user associated with the access token is located within the given physical proximity to the video end-system. In this example, the computer implemented method may comprise the step of detecting a user in a given physical proximity to the video end-system. Accordingly, acquiring the access token may include: acquiring an access token which is associated with the detected user. 35 The given physical proximity may be a local area surrounding the video end-system in which the video end-system is able to locally detect the user. For example, the given physical proximity may be the room in which the video end-system is located, a certain distance around the video end-system, a field of view of a camera in which users can be detected, a zone in which a PAN (Personal Area Network) signal from a personal device can be detected, or any other area surrounding the video end-system in which a user may reasonably be expected to use the video end-system. In this way, a video end-system may be quickly configured for a particular user and obtain access to the user account without the user needing to manually inform the video end-system which user account 5 should be accessed. Moreover, this method may provide more secure delegated access to the user account information because there the likelihood of a user account being accessed by a malicious party may be reduced because the user must be detected by the video end-system in order to acquire the access token and access the user account information. For example, determining if the (or a) user associated with the (or an) access token is in proximity (i.e. 10 within the given physical proximity) to the video end-system may include detecting a personal area network (e.g. a Bluetooth or NFT signal) from a personal device associated with that user. In this way, the video end-system may be quickly and efficiently granted delegated access to a user account with less manually intervention by a user. In some examples, the video end-system may be configured to use a face recognition module to detect 15 and identify a user associated with the access token. Therefore, determining if the user associated with the access token is within the given physical proximity to the video end-system may include using a camera of the video conferencing hardware and a face recognition module to detect the user in a field of view of the camera. In this way, security of the video end-system may be improved because the user granting delegated access by the video end-system to their account must be within the field of view of the 20 camera or the access token may not be acquired. Thus, the access token is less likely to be obtained by a third-party who does not have permission to access the user account information. In some examples, the video end-system may be configured to use a biometric recognition module (i.e., biometric reader) to detect and identify a user associated with the access token. Therefore, determining if the user associated with the access token is within the given physical proximity to the video end-system 25 may include using a biometric recognition module to identify a user in proximity to the video end-system. for examples, the biometric recognition module may be a fingerprint scanner configured to identify users of the video end-system. In further examples, the video end-system may be in communication with a building management system. Therefore, determining if the / a user associated with the / an access token is within the given physical 30 proximity to the video end-system may include receiving a signal from the building management system indicating that the user is in proximity to the video end-system. For example, the building management system may be configured to detect if a smart card or key fob associated with that user has been detected within the given physical proximity to the video end-system (e.g., to access a room or area that the video end-system is in). 35 In some examples, the shared video end-system may be configured to detect a plurality of users located in physical proximity (i.e., within the given physical proximity) to the video end-system (e.g. by detecting a personal area network, using a face recognition or fingerprint recognition module, detecting multiple users’ smart cards, or via any other suitable method). Here, the shared video end-system may be configured to receive confirmation from the control interface of a selected user. Therefore, acquiring the access token may include acquiring an access token associated with the selected user. For example, a user may be prompted to select a user from a list of detected users which are displayed on the control interface. 5 The computer implemented method may further comprise: locking the access token to prevent further use until the access token is unlocked by the access token’s associated user. Specifically, the video endsystem (or a central server connected to the video end-system) may be configured to lock the access token. For example, locking the access token may include encrypting the access token, or encrypting a secure storage module which includes the access token. The effect of locking the access token is to 10 make it unavailable for use until the associated user has authorized unlocking of the access token. In one example, locking the access token is presented to the user as “logging out” from the video end-system. In another example the operation may be presented to the user as a “screen lock” operation. In another example, locking the access token may be presented to the user as a “switch from user mode to public mode” operation. A user may authorize unlocking of the access token using one of the unlock 15 mechanisms described herein. For example, the video end-system may be configured to lock or encrypt the access token using a key received via the control interface or from a separate device. For example, the key may be received from a personal device using a personal area network such as NFT or Bluetooth or via the internet, or the key may be a PIN received from the control interface. In this example, the video end-system may be 1 20 configured to delete the key from memory after the access token is encrypted. Therefore, the access token, and therefore the user account information, is secured from further access by the video end-LO system until a key is provided to decrypt the access key. CM The computer implemented method may further comprise locking the user access token upon detection of a predetermined event. In this way, the user account information may be secured against further use 25 by the video end-system after a current session is finished. For example, the video end-system may be configured to lock the access token when the conference call ends. In further examples, the video end-system (or a central server connected to the video end-system) may be configured to lock the access token if the video end-system is not used for a predetermined amount of 30 time. For example, the video end-system may be configured to monitor activity on the control interface. If the control interface is idle for the predetermined amount of time then the video end-system may lock the access token to prevent unauthorised users from accessing the user account information. Alternatively or additionally, the video end-system may be configured to lock the access token if a personal area network signal (e.g. Bluetooth, NFC) from a personal device of a user associated with the 35 access token is not detected within the predetermined amount of time. In this way, the access token may be secured if, e.g., the user leaves a room containing the video end-system with their personal device. Advantageously, the user account information may be secured even if a user forgets to manually lock access to their account by the video end-system. In further examples, the video end-system may be configured to lock the access token upon receiving a command from the control interface to lock the access token. For example, the user may press a button or key provided on the control interface to end a session and disable the access by the video end-system to the user account information. In this way, a user may have confidence that their account information is 5 secured when they have finished using the video end-system. In further examples, when the video conferencing hardware comprises a camera, the video end-system may be configured to detect movement in a field of view of the camera. Here, the video end-system may be configured to lock the access token when no movement is detected in the field of view for a predetermined amount of time. In this way, the video end-system may secure the access token when the 10 participant(s) of a conference call leave a room or area that the video end-system is in. In some examples, the video end-system may be configured to lock the access token upon receiving a signal from a second video end-system indicating that a user associated with the access token is using the second video end-system. For example, the video end-system may be connected to a central video end-system management 15 service which is configured to communicate with one or more additional video end-systems. Therefore, the signal indicating that the user is using a second video end-system may be received from the central video end-system management service. In other examples, the video end-system and the second video end-system may be configured to communicate via the internet or a local network. In this way, user account information may be secured if a user switches from a first video end-system to a second video-20 end-system without needing to manually lock access to their user account on the first video end-system. LO The second video end-system may also be a shared video end-system for use by multiple users. For the avoidance of doubt, the second video end-system may be configured to perform each of the optional features described herein with respect to the (first) video end-system. The video end-system may be connected to a building management service which is configured to 25 indicate to the video end-system if the user is detected away from (i.e., in a different location to) the video end-system. In this way, the user account information accessible by the video end-system may be secured. The building management service may be configured to detect if a room containing the video end-system is empty (i.e., contains no occupants). In this example, the video end-system may be configured to lock 30 the access token upon receiving a signal from the building management service indicating that the room is empty. The building management service may be configured to detect whether there are occupants in the room by receiving signals, for example, from a passive infra-red (PIR) sensor(s) installed in the room. The PIR sensor may be installed for controlling lights in the room in response to detecting occupants moving. 35 In some examples, the building management service may be configured to detect whether a user associated with the access token has logged into an alternative computing system. Therefore, the video end-system may be configured to lock the access token upon receiving a signal from the building management service indicating that the user has logged into an alternative system. For example, the alternative computing system may be a users personal computer, a different video end-system, a printer, or a server in communication with the building management service. The video end-system may be configured to run a third-party application. For example, the video endsystem may be configured to run presentation software or video editing software. An output of the third-party application may be included in a content stream of the conferencing call. The third-party application may be provided in an application environment which is configured to provide an interface between the third-party application and the remainder of the video end-system. The computer implemented method may further comprise storing application status information associated with the third-party application. The application status information may be stored on a central configuration service. Therefore, the application status information may be accessed from multiple video end-systems. The application status may be associated with a user account and stored (and optionally encrypted) with the access token associated with that user account. For example, the application status information may be stored in a secure storage module which also includes the user access token. Therefore, the computer implemented method may comprise retrieving application status information associated with the third-party application. The application status information may be retrieved at the same time that the access token is acquired. For example, when a user is detected in proximity to the shared video end-system as described above, the video end-system may be configured to acquire the access token and the application status information associated with a user account of that user. The video end-system may be configured to use the application status information to configure a third-party application running on the video end-system. In this way, a third-party application being run by the video end-system may be configured to run according to a previous state of that third-party application which is recorded the application status information. This is particularly useful if a user wishes to move between a first video end-system and a second video end-system. By storing the application status information in association with a user account, the second video end-system may be able to restart the third-party application from a state in which the third-party application was left on the first video end-system improving thus user experience and saving time by avoiding the need for a user to manually save a transfer the application status information between the video end-systems. The computer implemented method may further comprise: providing an application environment for a third-party application to run on, the application environment configured to: route control signals from the control interface device to the third-party application; and route media signals between the third-party application and the video conferencing hardware and / or a content stream of a video conferencing call. Advantageously, by providing an application environment for running the third-party application, the third-party application may be used with a video end-system without experiencing issues owing to incompatibilities of the third-party application with the video-end-system. This enables users of the video-end-system (which may, for example, be a meeting room device) to use the video end-system for additional functionality beyond video conferencing. For example, the video-end-system may be used for hosting local and / or in-conference collaboration applications to enhance the meeting experience of users. Additionally, the method of the first aspect may also provide the opportunities for third-party application developers to develop new applications which are specifically tailored for video conferencing meetings 5 using a video end-system. The computer implemented method may additionally comprise running the third-party application in the application environment. Accordingly, the functionality of the video end-system may be expanded by running new applications. In one or more embodiments, the application environment may include a control signals interface, that is 10 to say programming configured to route control signals from the control interface device to the third-party application. In one or more embodiments, the application interface may include a media signals interface, that is programming configured to route media signals between the third-party application and the video conferencing hardware and / or a content stream of a video conferencing call. 15 The video-end-system may comprise system software which is configured to operate the video endsystem and enable the performance of a conference call using the video end-system. Therefore, the M computer implemented method may comprise operating the video end-system to conduct a video and / or CM audio conferencing call using system software. The system software may be an application or a computer -j— program which includes proprietary software which is provided with and configured to operate with the '^“20 video end-system. LO The video-end-system may be managed by a standard operating system. For example, the standard CM operating system may be a mass-market operating system such as Android. The operating system may be configured to support a collection of mass-market applications produced by third-parties designed to run on mass-market hardware such as tablets or smart phones. Other examples of standard operating 25 systems may include Huawei’s HarmonyOS or Apple’s iOS. The third-party application may be an application, computer program, or software package which provides additional functionality. Specifically, the third-party application may have a function which is a function other than supporting a video conferencing call. For example, the third-party application may include a collaborative application. For example, the application may be one or more of a document sharing, 30 whiteboarding, multimedia presentation, training, reviewing, polling or question submission application. The application may be configured to operate locally or remotely via the internet to include other parties in a video call. The third-party application may be provided by or downloaded from an external source (i.e. the third-party application is not the part of system software which was originally provided with the video end-system for enabling conferencing calls). 35 The third-party application may be configured to run on mass-market hardware such as tablets or smart phones (i.e. the third-party application may be configured to be compatible with hardware other than the video-end-system). The application environment is intended to refer to a framework or platform which has been configured to accept the deployment of a single application. The application environment comprises a predefined collection of computing resources that host an application. The application environment may be configured to provide the third-party application with virtualised or normalised device interfaces for 5 enabling the third-party application to run even if physical devices (originally intended for use with the application) are disconnected or are different from what the application expects. For example, the virtualised device interfaces may be configured to re-routed data to different physical devices whilst the application is running. In some examples, multiple application environments may be provided to operate multiple respective 10 third-party applications. The application environment may be provided on the video end-system. However, in other examples, the video end-system may be in communication with a cloud service (or a separate server on a local network) and the application environment may be provided on the cloud service (or the separate server). Advantageously, hosting the application environment on a cloud service can improve the performance of 15 the video end-system because the potentially resource-intensive third-party environment need not be hosted and run on the local hardware of the video end-system. In addition, if provided by a cloud service, the application may be completely isolated from a corporate network in which the video end-system is located. This enables untrusted applications to be run without risk to the corporate network. The application environment may be provided on the main processor (or endpoint device) of the video end-system or on a processing element which is connected to the main processor (e.g. via an internet connection to a cloud service). In some examples, the application environment may be provided on the control interface device. Here, the control interface device may be configured to perform the computer implemented method of the first aspect. In this example, the control interface device may also be considered as an endpoint device for 25 operating the video end-system to enable conference calls. In other words, the control interface device and the endpoint device may be provided as a single unit. In this example, the single unit may comprise system software for operating the video end-system and enabling the performance of a conference call. This example is useful for scenarios where one participant of the video call wishes to download and run a third-party application without allocating other resources of the video end-system to running the third- 30 party application. This example may also be advantageous if the video end-system is running an OS which is incompatible with the third-party application, but the control interface is running a different OS which may be compatible with the third-party application. As mentioned above, the control interface device and the video conferencing hardware may also be provided as a single unit. In this example, the video end-system may be a single desktop or handheld unit 35 which may also be referred to as a video end device. In yet further examples, the control interface device and video conferencing hardware may comprise separable units which are in communication with each other (e.g. via wired or wireless connections). The control interface device and the endpoint device may be in communication via a cloud-based relay service. Therefore, in this example, the application environment may be located on an endpoint device and the application environment may receive the control signals from the control interface device via the cloud-based relay service. Here, the endpoint device may, itself, be a first control interface device and a 5 second control interface device may be in communication with the first control interface device via the cloud based relay service. An advantage of the endpoint device and the control interface device communicating via the cloud may be that a wireless network to which the controller is connected may be different to and firewalled from a network to which the video end-system is connected to. Therefore, there may be no direct communication 10 between the two devices. Accordingly, by communicating via the cloud the endpoint device and the control interface device may be able to communicate even if they are connected to separate networks. The application environment may comprise a data mapping interface which is configured to relay control signals from the control interface device to the third-party application; and relay media signals between the third-party application and the video conferencing hardware and / or a content stream of a video 15 conferencing call. The data mapping may be a virtual interface which defines a boundary to the application environment and act as a virtualisation layer by relaying data between the third-party application inside the application environment and software and hardware which is external to the application environment. The media signals may include video data, and / or audio data (e.g., an audiovisual signal operating in a mode with a camera turned “off’) which forms the content stream of a video conferencing call. In some examples the media signals may include other types of data which may pass to and from the third-party application. For example, the media signals may include computer files, or text (e.g. other types of audiovisual related data, for example stills, computer files, text that can be shared over a video link). The control signals may comprise signals for selectively enabling and disabling the routing of the media 25 signals between the third-party application and the video conferencing hardware and / or the content stream of the video conferencing call. For example, the media signals may comprise video from the third-party application for enabling remoteview of the third-party application via the video conferencing hardware and / or the content stream of the video conferencing call. Therefore, the computer implemented method may comprise receiving remote 30 view control signals from the control interface device, and enabling or disabling remote view of the third-party application on one or more video conferencing hardware units and / or enabling or disabling remote view of the third-party application for one or more channels of a video conferencing call based on the remote view control signals. In this way, a user of the video end-system may decide which display screens to display the third-party application on and which remote participants of the video conferencing 35 call can view the third-party application. The application environment may be configured to transform the control signals from the control interface device having a first format to application control signals for controlling the third-party application having a second format (i.e. using a data mapping interface). In other words, the computer implemented method may comprise: using the data mapping interface to transform (i.e., reformat) the control signals from the control interface device having a first format to application control signals for controlling the third-party application having a second format. For example, the application environment may be configured to emulate gestures or key-presses in the application upon receipt of user control signals from the control 5 interface. This may include emulating function buttons, a virtual keyboard, a dial pad, a directory lookup, or other navigation elements for the third-party application in the virtual environment. For example, the control interface device (or one or the control interface devices) may comprise a keyboard for sending control signals which are keyboard events. The application environment may be configured to transform the keyboard events into application control signals for controlling the third-party 10 application. In other words, the computer implemented method may comprise the step of transforming the control signals comprising keyboard events from the control interface device having a first format to application control signals for controlling the third-party application having a second format. The application control signals may be configured to mimic control signals expected by the third-party application. For example, the key board events may be transformed into function signals corresponding to 15 function buttons normally provided by the third-party application. The control interface device may comprise a touch screen having a first size for sending control signals, and the third-party application may be configured to receive application control signals from a touch screen having a second size. For example, the application may be intended to be fun on a smart phone and the control interface device may be a much larger screen. In this case, the application environment 1 20 may be configured to scale or map the control signals from the control interface device to the application control signals for controlling the third-party application. In other words, the computer implemented LO method may comprise the step of scaling the control signals from the control interface device to form CM application control signals for controlling the third-party application. For example, the application environment may be configured receive position and movement information from the control interface 25 device touchscreen and scale the position and movement information proportionally to correspond to the application touchscreen. The control interface device may comprise a user interface environment for running an application user interface associated with the third-party application. For example, the control interface device may comprise a screen or a touch screen and the application user interface may be configured to display a 30 representation of the third-party application on the screen. The representation of the third-party application may include function buttons, a virtual keyboard, a dial pad, a directory lookup, or other navigation elements for navigating and / or controlling the third-party application. Similarly, the application environment may be configured to transform video signals from the third-party application having a first format to media signals for the content stream of the video conferencing call 35 and / or the video conferencing hardware having a second format. In other words, the computer implemented method may comprise the step of transforming media signals from the third-party application having a first format to media signals for the content stream of the video conferencing call and / or the video conferencing hardware having a second format. For example, the media signals may include video signals and the application environment may be configured reformat video data to map screen sizes, video formats (e.g. compressed vs uncompressed), numbers of pixels etc between formats compatible with the application and the video conferencing hardware and / or the content stream of the video conferencing call. In other examples, the media signals may include audio signals, images, or file data etc which are transformed from a first format compatible with the third-party application to a second 5 format. The application environment may comprise a data mapping interface which is formed from an application programming interface (API) provided by the third-party application. In some examples, the application environment may comprise customised instructions corresponding to the third-party application. The customised instructions may be stored in a centralised configuration 10 service. The centralised configuration service may be located on a remote server which is accessible by the video end-system. In this case, the computer implemented method may comprise retrieving the customised instructions from the centralised configuration service and implementing or creating the data mapping interface based on the customised instructions. The video end-system may be in communication with a centralised monitoring service, and the computer 15 implemented method may comprise the step of monitoring the third-party application from the centralised monitoring service. The centralised monitoring service may be located on a remote server. M The video end-system may comprise a management interface for enabling administrators to enable or CM disable authorisation for the download of third-party applications. For example, if a user wishes to install -j— as new third-party application the computer implemented method may comprise first requesting '^“20 authorisation from a user to download the new third-party application. The authorisation may then be LO received as a password inputted via the control interface device. CM The video end-system may be configured to communicate with a management server or cloud service to retrieve a list of authorised applications. The video end-system may then download the third-party application only if the third-party application is included in the list. In some examples, a user may be 25 presented with the list of authorised applications from which an application may be chosen for installation for operation by the video end-system. The application environment containing the third-party application may be sandboxed whereby access by the third-party application to computer resources is restricted. For example, the third-party application may be restricted from full access to CPU, Memory, File-system, Network, audio or display resources. In 30 this way, potential malicious activities of an untrusted third-party application may be reduced. Sandboxing may be performed by hosting the third-party application on a Guest Virtual LAN or by hosting the application environment on a cloud server to further isolate the third-party application from a corporate network or the remainder of the video end-system. In other examples, the third-party application may be a trusted application and may be provided with 35 direct access to computing resources such as CPU, Memory, File-system, network, audio or display resources. This is useful for increasing the efficiency and performance of trusted third-party applications by removing delays which may be introduced by virtualisation layers. In some examples, installing a third-party application for use by a video end-system may include installing the third-party application on the video end-system. In other examples, installing a third-party application for use by a video end-system may include installing the third-party application on a cloud server which is in communication with the video end-system. 5 The computer implemented method may further comprise: downloading customised instructions corresponding to the third-party application from a centralised configuration service for forming the application environment. In some examples the computer implemented method may further comprise communicating with a management server or cloud service to retrieve a list of authorised applications, and downloading the 10 third-party application, only if the third-party application is included in the list. Therefore, instances of potentially malicious third-party applications may be reduced. In addition, owners of the video end-system may control whether potentially resource intensive third-party applications may be downloaded to the video end-system. The computer implemented method may include receiving user authentication information to enable the 15 installation of the third-party application. Therefore, the video end-system has improved security and may be protected from the download of potentially malicious third-party applications by unauthorised users. According to a further aspect of the present invention there is provided a computer implemented method of operating a third-party application using a video-end-system, the video end-system for performing video conferencing calls; the video end-system comprising video conferencing hardware and a control interface device; the computer-implemented method comprising: providing an application environment for the third-party application to run on, the application environment configured to: route control signals from the control interface device to the third-party application; and 25 route media signals between the third-party application and the video conferencing hardware and / or a content stream of a video conferencing call. In a further aspect of the present invention there may be provided: a computer implemented method of installing a third-party application for use by a video end-system, the video end-system for video conferencing, the method comprising: 30 creating an application environment; the application environment configured to: relay control signals from a control interface device to the third-party application, and relay media signals between the third-party application and the video conferencing hardware and / or a content stream of a video conferencing call; and 35 installing the third-party application inside the application environment. In another aspect of the present invention there may be provided an application environment configured to host a third-party application for operation by a video end-system, wherein the application environment is configured to: route control signals from a control interface device of the video end-system to the third-party application; and route media signals between the third-party application and video conferencing hardware and / or a content stream of a video conferencing call. 5 In some examples, the application environment may be configured to run on the video end-system. In other examples, the application environment may be configured to run on a cloud service in communication with a video end-system. In a further aspect of the present invention there may be provided: a video end-system according to claim 27. The video end-system may be configured to use the user account information to perform a 10 conference call. For the avoidance of doubt, the video end-system may have any of the optional features described above in relation to the first aspect. In a further aspect of the present invention there may be provided: a network of video end-systems comprising a plurality of video end-systems according to the previous aspect. The plurality of video end-15 systems may be connected to a centralised configuration service comprising user account information. In a further aspect of the present invention there may be provided a computer program comprising instructions which, when the computer program is executed by a computer, cause the computer to carry out the method of any one of the previous aspects. The computer program product may take the form of a non-tangible computer program product comprising instructions. 20 Further aspects of the invention may provide a computer-readable storage medium, having stored thereon the computer program of the previous aspect of the invention. The invention includes the combination of the aspects and preferred features described except where such a combination is clearly impermissible or expressly avoided. 25 Summary of the Figures Embodiments and experiments illustrating the principles of the invention will now be discussed with reference to the accompanying figures in which: Fig. 1 shows a diagram of a typical video end-system according to the prior art; Fig. 2 is a flowchart illustrating an exemplary process for video conferencing using a video end-system 30 according to at least one aspect of the present invention; Fig. 3 is a flowchart illustrating another exemplary process for video conferencing using a video endsystem according to at least one aspect of the present invention; Fig. 4 shows a diagram of a video end-system according to an embodiment of the present invention; Fig. 5 shows a diagram of a video end-system according to another embodiment of the present invention; Fig. 6 shows a diagram of a video end-system according to another embodiment of the present invention; Fig. 7 shows a diagram of a video end-system according to another embodiment of the present invention; Fig. 8 shows a network of two video end-systems according to another embodiment of the present invention; 5 Fig. 9 shows a diagram of a video end-system according to another embodiment of the present invention; Fig. 10 shows a diagram of the video end-system of Fig. 9; Fig. 11 shows a diagram of a video end-system according to another embodiment of the present invention; Fig. 12 shows a diagram of a video end-system according to another embodiment of the present 10 invention; Fig. 13 shows a diagram of a video end-system according to another embodiment of the present invention; and Fig. 14 shows a diagram of a video end-system according to another embodiment of the present invention. ^-15 Detailed Description of the Invention Aspects and embodiments of the present invention will now be discussed with reference to the 1— accompanying figures. Further aspects and embodiments will be apparent to those skilled in the art. LO Fig. 1 shows a diagram of a typical video end-system 1 according to the prior art. 20 The video end-system 1, comprises a main processor 3 (which may also be referred to herein as an endpoint device 3). The main processor 3 is connected to a control interface 2, and to video conferencing hardware. The video conferencing hardware comprises a display screen 5, and a camera 4. In this example, the video end-system 1, is connected to a network 6, for example the internet, for enabling two-way or multiple-way communication in a conference call. Using the network, video footage 25 from the camera 4 or other media content (e.g. audio, computer files, text) may be sent and received over the network 6 and displayed on the screen 5. The video end-system 1 is a dedicated video conferencing system for performing video conferencing calls. Specifically, the video end-system 1 is a shared video end-system which is configured for use by multiple individual users. For example, the shared video end-system 1 may be located in a corporate 30 meeting room. The main processor 3 is a local processing resource such as a computer or server comprising proprietary software for controlling the remainder of the video end-system 1 and performing video conferencing calls. In other examples, the video end-system 1 may comprise multiple local processing resources which are spread across multiple devices. The control interface 2 comprises a user interface for receiving user inputs. The control interface 2 is configured to receive the user inputs and relay the user inputs as control signals to the main processor 3 for controlling the video end-system 1. The control interface 2 may optionally be a separate control interface device or built into a same unit as the main processor 3. For example, the entire video end- 5 system may be a personal touch-screen device or, in the case of a conference room system, the control interface 2 may be one of several touch-screens located around a conference room table. Other examples of control interface 2 may include a keyboard, a mouse, bespoke function buttons, or other user controls. The control interface 2, the camera 4 and the display screen 5 are connected to the main processor 3 via 10 wired or wireless data connections. For example, the data connections may be wired connection including USB or Powered Ethernet, such as 802.3at, or wireless connections including Wi-Fi or Bluetooth. The data connections between each device in the video end-system 1 may be direct point-to-point connections or indirect connections which include data relays via a server or servers on the internet 6. The video end-system may be one video end-system included in a network of video end-systems 15 managed by a centralised management service within an organisation. Typically, a computing system within such an organisation comprises user accounts allocated to individual users. By logging in to a user account a user can access user account information such as emails, programs, files, calendar, etc. -j— A user of a video end-system may wish to access their calendar, contacts, or other data from their '^“20 personal user account. Accordingly, the present inventors have devised a method for granting secure LO delegated access by a video end-system to user account information. CM In the examples that follow, alike features have been given corresponding reference numerals, and corresponding descriptions may apply except where such a description is clearly impermissible or expressly avoided. 25 Fig. 2 shows a flowchart illustrating an exemplary process for video conferencing using a video endsystem according to at least one aspect of the present invention. In the following examples, the processes are described as being performed by the video end-system. However, in some examples, some or all of the steps described herein may be performed by a central server which is in communication with the video end-system(s). 30 In step S100, the video end-system acquires an access token associated with a user account. The access token is configured to grant delegated access by the video end-system to a user account (or information from a user account) within an organisation. For example, the access token may comprise user credentials and permissions. For example, the video end-system may request access to a user account and provide the access token 35 to an organisation’s user account management service for verification. The user account management service can then verify the access token to ensure that the video end-system has permission to access the requested user account. In this step, “acquiring the access token” may refer to an initial procedure for creating an access token associated with a user account for the first time or to retrieving the user access token from a secure storage module. To create the access token, a user is required to perform a grant of delegated access by the video end-5 system to a particular user account. For example, in one embodiment, each user of the video end-system may perform a one-time grant of delegated access by the video end-system to their user account. The user associated with an account will perform the necessary procedure to inform the collaboration system that the video end-system should be permitted to access to a set of collaboration resources. The procedure may for example involve entering 10 a username and password and a multi-factor authentication code, followed by explicitly accepting a set of requested permissions. This procedure may therefore grant restricted access to contact and calendaring information in the user account. In another embodiment, an IT administrator within an organisation may grant delegated access by the video end-system to multiple user accounts (or information from those user accounts). 15 In the above examples, granting delegated access to the video end-system may include using an authentication service such as OAuth2 or SAML. This process may be performed on the video end-system itself, for example by requiring a user to use the control interface to provide user credentials. CM In other examples, the delegated access may be created using a proxy authentication service such as the 1 OAuth device flow running on a website. In this example, the user may use a second device such as a 20 mobile phone or a laptop to visit a website that is running the OAuth flow. LO After the user or IT administrator has provided their credentials, the authentication service may then provide an access token to the video end-system or provide a code to the video end-system that can be exchanged for an access token by the video end-system. For example, when OAuth is used as the authentication service, there may be an additional step wherein the authentication server initially gives the 25 video end-system a Code which the video end-system may combine with an Application ID associated with the video end-system and an Application Secret. The combination may then be sent back to the authentication service to receive an access token and a refresh token. The video end-system may then use the access token to access a user account associated with that access token. After the access token has been created, the video end-system may be configured to 30 securely store the access token in a secure storage module (which may also be referred to as a secure enclave) for later retrieval by the video end-system. Alternatively the video end-system may be configured to store the access token in a centralised management service which itself may make use of a secure storage module. The secure storage module may be in a physically secure area such as a server room, or may be built 35 around a hardware encryption device such as a Trusted Platform Module (TPM). For example, the secure storage module may include a device configured to store encrypted data and won't divulge the data without a key being provided. The secure storage module may be configured to lock and unlock the access token depending on if a user associated with that access token is determined to be present. Therefore, as discussed in more detail below in relation to the following figures, acquiring the access token may first include detecting a user, identifying the user as a valid user and unlocking their associated access token. 5 In step S102, the video end-system uses the access token acquired in step S100 to access user account information. This may include accessing a user account via an organisation’s centralised collaboration service. For example, the video end-system may provide the access token when communicating with a collaboration service to attest that the video end-system has authorization to act on behalf of the user to retrieve user 10 account information from the user account. In another example the token grant operation and subsequent accesses of the collaboration service may be performed by the centralised management service on behalf of the video end-system such that the video end-system itself has no knowledge of the access tokens. In other words, acquiring the access token, the access token being configured to grant access by the video end-system to user account 15 information associated with the user account; and using the access token to retrieve the user account information may be performed by the central collaboration service. The user account information may comprise any information or stored data which is associated with the CM user account. In particular, the user account information may include calendaring and / or contacts -j— information. For example, the calendaring information may include information about dates, times, and '^“20 details of participants for conference calls which are scheduled in the user’s calendar. The contacts LO information may include the contact details (e.g., email address, phone number, name etc) of contacts who the user may wish to include in a conference call. In step S104, the video end-system uses the user account information to perform a conference call. For example, the video end-system may perform a conference call based on a meeting scheduled in the 25 calendar of the user account. In other examples, the video end-system may use the user contacts information to send a meeting invite or a link to a virtual meeting room to remote participants of the conference call. Fig. 3 is a flowchart illustrating another exemplary process for video conferencing using a video endsystem according to at least one aspect of the present invention. 30 In this example, the video end-system is configured to determine whether a user is identified before unlocking the access token. In addition the video end-system is configured to lock the access token upon detecting a particular end condition. When the access token is locked, the video end-system (or collaboration service) is prevented from accessing the access token without prior authorisation from a user associated with that access token. 35 In step S200, the video end-system detects if a user is present. This may include first detecting the presence of a user and then identifying the user as a known user of the video end-system. The video end-system comprises a list of expected users for whom there is an access token available for accessing their user account. By detecting and identifying a user of the video end-system as a user belonging to the list of expected users, the video end-system may automatically acquire the appropriate access token for accessing that user’s account. 5 In some examples, detecting the user may involve a user simply logging in to the video end-system using a unique login (e.g., using a username and password). The user may log in via the control interface or using a personal device which is connected the video end-system (e.g. via a Bluetooth, NFT, Ethernet cable, etc.) The video end-system is configured to receive the unique login and identify the user as belonging to the list of expected users. 10 In other examples, the video end-system may be configured to determine if a user is in proximity to the video end-system. If a user is identified in proximity to the video end-system, then the video end-system will add that user to a list of candidate users for access token unlock. For example, an application running on a personal device belonging to a user may be configured to use a personal-area network (e.g., Bluetooth) to connect to the video end-system and determine whether the 15 personal device is in physical proximity to the video end-system. If the personal device connects to the video end-system via the PAN, then the application running on the personal device may then provide an indication to the video end-system that the user is present. The video end-system will then add that user to the list of candidate users for access token unlock. -j— In another example, the video end-system may be configured to monitor a field of view of the camera and '^“20 use facial recognition to determine the identities of users present in the field of view. The video end- LO system can then add users identified in the field of view to the list of candidate users for access token unlock. In another example, the video end-system may comprise a fingerprint or other biometric reader. The video end-system may be configured to use a correct match of a fingerprint or other biometric 25 measurement as authorization to unlock the access token for a user. In other examples, the video end-system may be configured to detect a PAN signal from a user’s personal device such as a mobile phone or laptop. If the video end-system recognises the personal device as belonging to a potential user of the video end-system, then that user may be added to the list of candidate users for access token unlock. 30 In further examples, the video end-system may be connected to a building management or access control system that is configured to indicate to the video end-system if a user is present. For example, the building management system may be configured to detect the use of smart cards or key fobs which are registered to users of the video end-system. If a smart card or key fob associated with a particular user is used to access the video end-system (or a room containing the video end-system) then the building 35 management system may send a trigger signal to the video end-system indicating that the owner of that smart card or key fob should be added to the list of candidates for access token unlock. In further examples, the video end-system may be configured to store a list of frequent or favourite users of the video end-system which are included in the list of candidates for access token unlock. In step S202, the video end-system requests confirmation of which candidate user wishes to grant delegated access by the video end-system to their user account. 5 In one example, this step may include presenting the list of candidate users detected in step S200 on the display screen. A user may then use the control interface to select a user from the list for access token unlock. In another example, the video end-system may request confirmation of a user by sending a confirmation request (i.e. a push notification) to multiple personal devices which are connected to the video end- 10 system (e.g. by Bluetooth). In this example, the first user to respond to the request confirming that they wish to use the video end-system is designated as the confirmed user for access token unlock. In another example, the video end-system may be configured to assume consent based on policy settings configured forthat video end-system. The policy settings may be based on a certainty of the video endsystem that a particular user is present. For example, the policy settings may include a policy that dictates 15 that a user who has recently used a smart card to gain access to a room containing the video end-system and who is the only detected occupant in the room may be designated as the confirmed user for access token unlock without requiring further confirmation. CM In step S204, the video end-system unlocks the access token associated with the user that was 1 confirmed in step S202. 1— 20 Unlocking the access token may include retrieving the access token from a secure storage module. As described below in relation to Figs. 4 to 8 the secure storage module may be provided locally on the video end-system or remotely on a server connected to the video end-system. In step S206, the video end-system uses the access token to access user account information as in step S102 of Fig. 2. 25 In step S208, the video end-system uses the user account information to perform a conference call as in step S104 of Fig.2. In step S210, the video end-system determines whether an end condition is detected indicating that the video end-system should cease accessing the user account information and securely store (i.e., lock) the access token for future use. 30 The end condition may include multiple different events which the video end-system is configured to detect and thus trigger lock of the access token. For example, in one embodiment a button may be provided on the control interface of the video endsystem wherein the button is configured to issue a command the video end-system to lock the access token when it is pressed. In other examples, the end condition may include the conclusion of a conference call. Accordingly, the video end-system may be configured to lock the access token when the conference call of step S208 ends. In further examples, the video end-system may be configured to lock the access token if the video end-5 system is not used for a predetermined amount of time. For example, the video end-system may be configured to monitor activity on the control interface. Here, the end condition may include the control interface being idle for a predetermined amount of time. In other examples, the video end-system may be configured to lock the access token if a personal area network signal (e.g. Bluetooth, NFC) from a personal device of the user is not detected within the 10 predetermined amount of time. In some examples, the video end-system may be configured to use image analysis to detect movement in a field of view of the camera. In this example, the end condition may include determining a lack of movement in the field of view of the camera for a predetermined amount of time. In this way, the video end-system may secure the access token when the participant(s) of a conference call leave a room or an 15 area that the video end-system is in. In a further example, the video end-system may be linked to a building management system that includes a presence sensor for detecting room occupancy. In this example, the end condition may include receiving a signal from the building management system that a room containing the video end-system has been vacated. 20 Ina further example, the video end-system may be linked to a building management system that sends an indication if a logged-in user is detected away from the video end-system indicating that the user is no longer present with the video end-system and triggering an end condition. In some examples, the video end-system may be configured to lock the access token upon receiving a signal from a second video end-system which indicates that the user associated with the access token is 25 using the second video end-system. In this case, the video end-system may be connected to a central video end-system management service which is configured to communicate with one or more additional video end-systems. In some examples, the video end-system may be managed by a central management service via a corporate network or the internet. This central management service may enable the configuration of 30 policy settings across a multiplicity of video end-systems for configuring which of the above described end conditions should be detected by the video end-system for determining when the access token should be locked. In step S212, the video end-system locks the user access token. This step includes storing the access token locally in a secure enclave in the video end-system (as shown 35 in Fig. 4). The secure enclave may be configured to use a Trusted Platform Module or similar encrypting storage device to prevent or defend against physical extraction of the access token if the video endsystem is physically compromised or infected with malware. In another example, the access token may be stored remotely on a server. The server may be provided on a corporate network or on the internet. In the above examples, the access token may be encrypted using a key provided by an application on or in communication with a personal device belonging to the user, or by a trusted corporate service provider. 5 After encryption, the video end-system will then delete the key from the video end-system’s memory such that the access token cannot be decrypted without help from the personal device or the trusted corporate service provider that provided the key. In some examples, (e.g., if the access token is created using an authentication service such as OAuth) the access token may have an associated lifespan. In these examples, the access token may be provided 10 to the video end-system with a refresh token. The access tokens can be used many times during the access token’s life-span until it expires. When the access token expires the refresh token may be provided to the authentication service to retrieve a new access token and a new refresh token. The video end-system may be configured to perform the refresh mechanism in the background. For example, if the current access token is valid then the system may use it, and if not then the video end-system may 15 perform the refresh mechanism to acquire a new access token. Fig. 4 shows a diagram of a video end-system 201 according to an embodiment of the present invention. The video end-system 201 comprises a main processor 203, a display screen 205, a camera 204, and a control interface 202 as in Fig. 1. The main processor 203 is connected to the internet for exchanging a content stream of a video conferencing call with remote parties. 20 In this example, the video end-system 201 comprises a security module 220 including a secure storage module. The security module 220 is configured to acquire access tokens associated with respective user accounts and store the access tokens in the secure storage module according to the processes described above. The access tokens comprise user credentials for enabling secure delegated access by the video end-25 system 201 to a user account associated with that access token. The security module 220 is configured to lock and unlock the access tokens based on trigger signals from external sources as described above in relation to Fig. 3. When an access token is locked, the remainder of the video end-system 201 is restricted from accessing the access token. When an access token is unlocked by the security module 220 then the video end-system 201 may use the user credentials in the 30 access token to access the user account associated with that access token. In this example, the main processor 203 is connected to a building management system 230. The building management system 230 is configured to communicate information to the video end-system 201 about the location of users of the video-end-system 201. For example, the building management system 230 may include a door access system for a corporate building. If a smart card associated with a 35 particular user is used to access the video end-system 201 (or a room containing the video end-system 201) then the building management system 230 may send a trigger signal to the video end-system 201 indicating that an access token associated with that user should be unlocked. Also shown in this example is a personal device 240 belonging to a user of the video end-system 201. For example, the personal device 240 may be a mobile phone or a laptop. In this example, the video endsystem 201 is configured to receive a personal area network (PAN) signal from the personal device 240. A user may issue commands or received notifications from the video end-system 201 using the personal 5 device. In addition, the security module 220 is configured to detect the PAN signal from the personal device 240 in order to detect the presence of a user associated with that personal device 240 in proximity to the video end-system 201. The security module 220 may then unlock the access token associated with that user. Fig. 5 shows a diagram of a video end-system 201 according to another embodiment of the present 10 invention. In this example, the video end-system 201 is connected to a central server 250 via the network 206. In this example, the secure storage module containing access tokens is provided on a central server 250. Therefore, the secure storage module and the access tokens within the secure storage modules may be accessed by multiple video end-systems 201. 15 Fig. 5 also shows a connection between the main processor 203 and a cloud collaboration service 260 that contains the user account information. In particular, the user account information includes an address book (i.e. user contacts data) and calendar information that may be accessed by the video end-system 201 using a relevant access token from the secure storage module. -j— Fig. 6 shows a diagram of a video end-system 201 according to another embodiment of the present ■^“20 invention. LO In this example, a third-party application 210 or plugin software is provided on the main processor 203 of CM the video end-system 201. The third-party application 210 is configured run inside of an application environment 211 which is configured to provide an interface between the third-party application 210 and the remainder of the video end-system 201. 25 In this example, the security module 220 is also configured to retrieve and stored application status data associated with that third-party application 210 in the secure storage module along with the access tokens. Specifically, application status data associated with a particular user of the video end-system 201 is stored alongside an access token associated with that user. In some examples, the third-party application 210 may use the access token to access user account 30 information including user credentials and state information including recently accessed documents or other data owned by the user of the video end-system 201. The video end-system 201 may be configured to treat the application state information of any running applications in a similar manner as the access token for the current user. Therefore, when a user triggers the locking of the access token through any of the mechanisms described above, not only the access 35 token, but also the application state data may be locked in the secure enclave by the security module 220. The third-party application may then be reset to remove the application’s ability to access the user- owned documents or data such that subsequent users of the video end-system may not be able to view or make use of the user-owned documents or data. Fig. 7 shows a diagram of a video end-system 201 according to another embodiment of the present invention. 5 In this example, the concepts of Fig. 5 and Fig. 6 are shown in combination wherein a central server 250 is provided for storing application state date and access tokens associated with a particualer user account. In this example, the security module 220 is configured to transmit the application state data to the central server 250 when the user logs off of the video end-system 201 (i.e., when the access token is locked). 10 Therefore, if the same user logs on to another video end-system 201, the application state data may be retrieved from the central server by the new video end-system 201 enabling the third-party application to resume operation from the point at which the user logged off from the original video end-system 201. Fig. 8 shows a network of two video end-systems 201,201’ according to an embodiment of the present invention. In this example, the video end-system 201 is configured to run a third-party application in an 15 application environment as described above for Figs. 6 and 7. The two video end-systems 201,201 ’ according comprise a first video end-system 201 and a second video end-system 201 ’ which are connected by a network 206. Fig. 8 shows a migration of a third-party application 210 from the first video end-system 201 to the second video end-system 201 ’. First, a user logs into and runs the third-party application 210 in an application environment 211 as shown 20 in the first video end-system 201. In this example, the first video end-system 201 is configured to identify the user by detecting the user’s personal device 240 via a PAN (e.g. Bluetooth) signal. However, when the user leaves a room containing the first video end-system 201 the first video endsystem 201 ceases to detect the personal device 240. When the video end-system 201 ceases to detect the personal device 240, the security module 220 is configured to retrieve the application state 25 information from the application environment 211 and store the application state information in the central server 250. The security module is also configured to lock the access token currently being used. The third-party application 210 running on the first video end-system 201 is then reset. The user is then detected entering another room containing the second video end-system 20T. In this example, the user is detected by the building management system 230 (e.g. by detecting a smart card 30 associated with that user) which informs the second video end-system 201 ’. Upon detection of the user, the security module 220’ of the second video end-system 201’ then unlocks the access token associated with that user and retrieves the application state information associated with that user from the central server 250. The application state information from the central server 250 is provided to the application environment 35 211’ of the second video end-system 201 ’ thus enabling the third-party application 210’ to resume operation from where the third-party application 210 was saved in the first video end-system 201. The following Figs. 9 to 14 show video end-systems according to further embodiments of the present invention in which the video end-system is configured to operate a third-party application. The skilled person would understand that each of the features described herein in relation to Figs. 9 to 14 may be combined with any or all of the features described above in relation to Figs. 1 to 8. For example, a video 5 end-system according to the present invention may be configured to operate a third-party application and / or access a user account. Fig. 9 shows a diagram of a video end-system 300 according to an embodiment of the present invention which is configured to operate a third=party application. In this example, the video end-system 300 comprises a video endpoint device 310 connected video 10 conferencing hardware 330 and a control interface device 320. The endpoint device 310 is connected to the internet 360 for exchanging a content stream of a video conferencing call with remote parties. The endpoint device 310 is configured to send and receive media signals from the video conferencing hardware which may form part of the content stream of the video conferencing call. Inn Fig. 9 the video conferencing hardware includes a camera 3332 and a display screen 3334 for recording and displaying 15 video footage. The endpoint device 310 is also configured to receive control signals from the control interface device 320 for controlling the video end-system 300. CM In this example, the endpoint device 310 is configured to run a third-party application 314 which is hosted 1 inside an application environment 312 provided on the endpoint device 310. 1— 20 In this example, an additional user interface environment 322 is provided on the control interface device 320 for hosting an application user interface of the third-party application. For example, if the control interface device 320 comprises a touchscreen, then a video feed from the third-party application 314 may be provided to an application user interface running in the user interface environment 322 so that a remote view of the third-party application 314 can be displayed on the touchscreen. 25 Additionally, the application environment 312 on the endpoint device 310 is connected to a management agent service 370 via the internet 360. The management agent service 370 contains information regarding the identities and permitted behaviour of each video end-system 300 under its control. Examples of permitted behaviour may include a list of authorized third-party applications that may be run on the video end-system 300, details regarding the manner in which each application 314 may be run 30 such as whether user authorisation from a user is required, whether the application 314 may be shared with any or specific remote parties, and / or whether the application 314 must be restricted in terms of device or network access. The management agent service 370 is configured to send configuration management controls to the application environment 312. Fig. 10 shows another diagram of the video end-system 300 of Fig. 9. In Fig. 30 the video conferencing 35 hardware 330 additionally includes a speaker 3336 and a microphone 3338 for playing and recording audio data for the content stream of a video call. Additionally, the video end-system 300 comprises a network interface 350 for connecting to the internet 360. As shown in Fig. 30, the application environment 312 comprises an environment interface 316 for relaying signals between the third-party application 312 and other components of the video end-system 300. The environment interface 316 (which may also be referred to as a data mapping interface 316) is configured to route control signals 324 from the control interface device 320 to the third-party application 5 314. The environment interface 316 is also configured to route media signals 340 between the third-party application 312 and the video conferencing hardware 330 and / or the content stream of a video conferencing call via the network interface 350. In some examples, the application environment 312 may be configured to relay other types of data between the third-party application 314 and the remainder of the video end-system such as data files, text, etc. 10 In the example shown, the media signals 340 includes a video stream 342 received from a camera which is relayed to the third-party application 312 via the data mapping interface 316 and to the network interface 350 to form part of the content stream of a video call. In addition, a video stream 344 received from the third-party application 312 via the data mapping interface 316 (or from the network interface 350) as part of the content stream of a video call is relayed to a display screen 3134. Likewise an audio stream 15 348 received from a microphone 3338 is relayed to the third-party application 312 via the data mapping interface 316 to the network interface 350 to form part of the content stream of a video call, and an audio steam 346 received from the third-party application 312 (or from the network interface 350) is provided to a speaker 3336. In use, a user may request installation of the third-party application 312 (e.g. an Android application) on the video end-system 300 via the user interface of the control interface device 320. The control interface device 320 then contacts the intended application hosting device (i.e. the endpoint device 310 in this example) and instructs the hosting device to create an application environment 312 for the third-party application 314 to run on and then downloads the third-party application 314 into the application environment 312. 25 The third-party application 314 may have pre-requisite requirements for running on a typical device. Creating the application environment 312 includes allocating CPU and memory resources as well as virtual devices and / or interfaces such as a display, keyboard and touch-screen for the application 314. When the third-party application 314 is launched into the created application environment 312, the prerequisite requirements of the third-party application 314 are provided such that the application 30 environment 312 emulates a typical device such as a conventional mass-market tablet or phone from the point of view of the third-party application 314. The user interface of the video end-system 300 located on the control interface device 320 may then be used to connect to the third-party application 312 in a variety of ways described herein. In one example, a virtual video stream may be relayed across the connection between the endpoint 35 device 310 and the control interface device 320 such that an application video output of the third-party application 314 may be displayed on the control interface device 320. The video view may be displayed full-screen if the aspect ratio and resolution of a screen provided on the control interface device 320 is similar to the requirements of the third-party application 320. In other examples, the user interface environment 322 on the control interface device 320 may be configured to display the application video output in a window on a screen of the control interface device 320. In some examples, a user of the control interface device 320 may make use of zoom gestures such as two-finger pinch to zoom the video. This example is useful for setting up a third-party application 314, e.g. by entering user credentials, where 5 the information should not be shared with the other attendees in a meeting room. In another example, a video output from the third-party application 314 may be connected to or redirected to the display screen 3334 or to the content stream of a video conferencing call. If the display screen 3334 includes a touch-screen, the touch-screen gestures may be relayed back to the third-party application 314. 10 In some examples, when the endpoint device 310 includes a graphics processing unit (GPU), and / or a screen, and / or a touch screen on a same unit, the third-party application 312 hosted on the endpoint device 310 may be given direct access to the GPU, the display and / or the touch-screen (i.e., without a virtualisation layer). This can be useful for improving the efficiency and performance of the third-party application 314. 15 The data mapping interface 316 may be configured to transform control signals 324 from the control interface device 320 having a first format to application control signals 324’ for controlling the third-party application 312 having a second format. CM For example, the control interface device 320 may include a physical touch-pad or a virtual touch-pad -j— emulated by a touch-screen of the control interface device 320. Touch gestures from the touch-pad of the ■^“20 virtual touch-pad may be relayed over the connection between the control interface device 320 and the LO endpoint device 310 to the third-party application 312 via the data mapping interface 316 as touch gestures. In this example, the application environment 312 may be configured to correctly map the gesture positions between the touchpad or virtual touchpad of the control interface device 320 and a target virtual display of the third-party application 312 which has a different size, taking into account any 25 active crop, zoom, screen size differences and aspect ratios between the touch screen of the control interface device 320 and the target virtual display of the third-party application 312. In another example, the endpoint device 310 or the control interface device 320 may be programmed with customised instructions associated with a specific third-party application 312 for forming the application environment and / or the user interface environment 322. The customised instructions may be configured 30 to provide an enhanced user interface on the control interface device 320 to replace a conventional user interface of that third-party application 312. In this way a user interface that is more appropriate for the hardware of the video end-system 300 may be provided, in place of the user interface of the third-party application which may be better suited to different hardware (e.g. a smart phone). For example, the enhanced user interface provided on the control interface device 320 may include 35 application specific function buttons, a virtual keyboard, a dial pad, a directory lookup, or navigation elements which are configured for controlling the third-party application 314. The application environment 312 may be configured to convert control signals 324 from the enhanced user interface into control signals 324’ which emulate gestures and key-presses expected by the third-party application 314. The customised instructions for a particular third-party application 312 may be provided by a central server, (e.g., on the internet 360) which may be downloaded by the endpoint device 310 and / or the control interface device 320. The customised instructions may include a combination of structured data, code, and / or portable code. In some examples, the customized instructions may comprise an application 5 programming interface (API) provided by the third-party application 314. In some examples, a list of authorised third-party applications that are permitted to be operated by the video end-system 311 may be centrally managed by a management server or cloud service. The video end-system 300 may connect to the management server or cloud service to retrieve the list of authorised applications. If a desired third-party application is included in the list of authorised applications, then the 10 endpoint device 310 may download the third-party application 314 from a publicly accessible repository (for example from the Google Play Store) or a from private repository such as a private server or from the management server itself or from the cloud service. This is useful for reducing the likelihood of malicious third-party applications 312 being installed on the video end-system 300. Additionally or alternatively, a management interface may be provided (e.g. on the control interface 15 device 320) to enable administrators to enable or disable authorisation for specific third-party applications 314. In some examples, a user login or video end-system device identifier may be required to enable or disable the download of a third-party application 314. In another embodiment, the management server or the management interface may be configured to permit guest applications that are not included in the list of authorized applications to be operated by the 20 video end-system 300. This may be permitted based on a user login or based on a video end-system __ device identifier. ID In further examples, the management server or cloud service may be configured monitor the usage and behaviour of the third-party applications 314. In some examples, the endpoint device 310 may be configured to sandbox the third-party application 312 25 whereby access by the third-party application 312 to computer resources of the video end-system 300 is restricted. For example, the third-party application 312 may be restricted from full access to CPU, Memory, File-system, Network, audio or display resources. The access of the third-party application 312 to network resources may be restricted by hosting the third-party application 312 on a Guest Virtual LAN so that network traffic related to the sandboxed third-party application may be separated from other 30 network traffic. In another example, the aforementioned sandboxing may take place on a cloud server to further isolate the third-party application 312 from the corporate network. In this example, the third-party application 312 may only have access to selected media and control signals of the video end-system 300. Fig. 11 shows a diagram of a video end-system 400 according to another embodiment of the present 35 invention. In this example, the application environment 412 containing the third-party application 414 is provided on the control interface device 420 which also hosts the environment user interface 422. A remote view (i.e. a video stream) of the third-party application 414 is routed by the application environment 412 to the display screen 4334 via the endpoint device 410. Fig. 12 shows a diagram of a video end-system 500 according to another embodiment of the present invention. In this example, the application environment 514 containing the third-party application 512 is provided on a cloud service 580. An application user interface 522 running on the control interface device 520 is connected via the 5 endpoint device 510 to the application environment 512 on the cloud service 580 via the internet 560 for controlling the third-party application 512. A video stream from the third-party application 514 in the application environment 512 is routed from the cloud service 580 via the internet 560 to the video endpoint device 510 and on to the display screen 5334. If the application user interface 522 requires a video feed from the third-party application 514 then the video stream may also be routed via the same 10 connections to the control interface device 522 for enabling the application 512 to be viewed (e.g. as part of a user interface) on the control interface device 522. Fig. 13 shows a diagram of a video end-system 600 according to another embodiment of the present invention in which the control interface device 620 is not directly connected to the endpoint device 610 by a wired or a wireless link but is instead connected to the endpoint device 610 indirectly via the internet 15 660 using a control relay service 690. Control signals from the application user interface 622 running on the control interface device 320 may be routed to via the control relay service 690 to the application environment 612. If the application user interface 622 requires a video feed from the application environment 612 then the video feed may be routed back across the same connections for enabling the third-party application 612 to be viewed (e.g. as part of a user interface) on the control interface device 1 20 622. Fig. 14 shows a diagram of a video end-s,stem 700 according to an embodiment of the present invenhen wherein the video end-system 700 is participating in a conference call with a remote video end-system 700’. In this example, a video output from the third-party application 714 is provided by the application environment 712 as a content stream for the video call enabling the video output of the third-party 25 application 714 to be sent both to the local display 7334 and to a remote video end-system 700’ to be displayed on a remote display screen 7334’. *** The features disclosed in the foregoing description, or in the following claims, or in the accompanying drawings, expressed in their specific forms or in terms of a means for performing the disclosed function, 30 or a method or process for obtaining the disclosed results, as appropriate, may, separately, or in any combination of such features, be utilised for realising the invention in diverse forms thereof. While the invention has been described in conjunction with the exemplary embodiments described above, many equivalent modifications and variations will be apparent to those skilled in the art when given this disclosure. Accordingly, the exemplary embodiments of the invention set forth above are considered to be 35 illustrative and not limiting. For the avoidance of any doubt, any theoretical explanations provided herein are provided for the purposes of improving the understanding of a reader. The inventors do not wish to be bound by any of these theoretical explanations. Any section headings used herein are for organizational purposes only and are not to be construed as limiting the subject matter described. Throughout this specification, including the claims which follow, unless the context requires otherwise, the word “comprise” and “include”, and variations such as “comprises”, “comprising”, and “including” will be 5 understood to imply the inclusion of a stated integer or step or group of integers or steps but not the exclusion of any other integer or step or group of integers or steps. It must be noted that, as used in the specification and the appended claims, the singular forms “a,” “an,” and “the” include plural referents unless the context clearly dictates otherwise. Ranges may be expressed herein as from “about” one particular value, and / or to “about” another particular value. When such a range 10 is expressed, another embodiment includes from the one particular value and / or to the other particular value. Similarly, when values are expressed as approximations, by the use of the antecedent “about,” it will be understood that the particular value forms another embodiment. The term “about” in relation to a numerical value is optional and means for example + / -10%. 15 25 11 24 25 06 25
Claims
1. A computer implemented method of accessing a user account from a video end-system,the video end-system for performing video conferencing calls; the video end-system comprising:a main processor, a control interface, and video conferencing hardware, and the user account being one5 of a plurality of user accounts accessible by the video end system via a network;wherein the computer implemented method comprises:acquiring an access token, the access token being configured to grant access by the video end-system to user account information associated with the user account, wherein the user account information is located on a centralised collaboration service, the centralised collaboration service being10 connectable to a plurality of video end-systems;using the access token to retrieve or access the user account information from thecentralised collaboration service via a network interface; andstoring the access token in a secure storage module for later retrieval by the video endsystem, the secure storage module being configured to store a plurality of access tokens associated with15 respective user accounts of the plurality of user accounts.
2. The computer implemented method of claim 1 further comprising: using the retrieved user account information and the video end-system to perform a conference call.20 3. The computer implemented method of claims 1 or 2 wherein the secure storage module for laterretrieval of the access token is located in the video end-system.
4. The computer implemented method of claims 1 or 2 wherein the secure storage module is located on a central server which is accessible by a plurality of video end-systems.
255. The computer implemented method of any preceding claim wherein the later retrieval of the access token includes:determining if a user associated with the user access token is detected within a given physical proximity to the video end-system,30 wherein the access token is only retrieved if the user associated with the access token isdetected within the physical proximity to the video end-system.
6. The computer implemented method of claim 5 wherein determining if the user associated with the access token is within the given physical proximity to the video end-system includes detecting a Personal35 Area Network signal from a personal device associated with that user.
7. The computer implemented method of claims 5 or 6 wherein determining if the user associated with the access token is in the given physical proximity to the video end-system includes using a camera included in the video conferencing hardware and a face recognition module to detect the user in a field of view of40 the camera.25 06 258. The computer implemented method of any of claims 5 to 7 wherein determining if the user associated with the access token is in the given physical proximity to the video end-system includes receiving a notification from a biometric recognition module that the user has been identified.5 9. The computer implemented method of any of claims 5 to 8 wherein determining if the user associatedwith the access token is within the given physical proximity to the video end-system includes receiving a signal from a building management system indicating that a smart card associated with that user has been detected in the given physical proximity to the video end-system.10 10. The computer implemented method of any of claims 5 to 9 wherein the method comprises:detecting a plurality of users within the given physical proximity to the video end-system, and receiving confirmation from the control interface of a selected user of the plurality of users within the given physical proximity, wherein acquiring the access token incudes acquiring the access token associated with the15 selected user.
11. The computer implemented method of any preceding claim wherein acquiring the access token includes sending user authentication data to a website running an authentication service and receiving the access token from the website.2012. The computer implemented method of any preceding claim wherein the video end-system is configured to lock the access token to prevent unauthorized use of the access token.
13. The computer implemented method of claim 12 wherein the video end-system is configured to lock 25 the access token if the video end-system is not used for a predetermined amount of time.
14. The computer implemented method of claims 12 or 13 wherein the video end-system is configured to lock the access token if a personal area network signal from a personal device of a user associated with the access token is not detected by the video end-system for a predetermined amount of time.3015. The computer implemented method of any of claims 12 to 14 wherein the video end-system is configured to lock the access token when the conference call ends.
16. The computer implemented method of any of claims 12 to 15 wherein the video end-system is 35 configured to lock the access token upon receiving a command from the control interface to lock the access token.
17. The computer implemented method of any of claims 12 to 16 wherein the video conferencing hardware comprises a camera, and the video end-system is configured to detected movement in a field of 40 view of the camera, wherein the video end-system is configured to lock the access token when no movement is detected in the field of view for a predetermined amount of time.25 06 2518. The computer implemented method of any of claims 11 to 17 wherein the video end-system is configured to lock the access token upon receiving a signal from a second video end-system indicating that a user associated with the access token is using the second video end-system.5 19. The computer implemented method of any of claims 11 to 18 wherein the video end-system is incommunication with a building managements service, the building management service being configured to detect if a room containing the video end-system is empty, wherein the video end-system is configured to lock the access token upon receiving a signal from the building management service indicating that the room is empty.1020. The computer implemented method of any of claims 11 to 19 wherein the video end-system is in communication with a building management service, the building management service being configured to detect whether a user associated with the access token has logged into an alternative computing system, wherein the video end-system is configured to lock the access token upon receiving a signal from 15 the building management service indicating that the user has logged into an alternative system.
21. The computer implemented method of any of claims 11 to 20 wherein the video end-system is configured to lock the access token by encrypting the access token using a key wherein the video endsystem is configured to delete the key from a memory of the video end-system after the access token is 20 encrypted;wherein the key may be received from the control interface or from a personal device of a user associated with the access token.
22. The computer implemented method of any preceding claim wherein the video end-system is25 configured to run a third-party application.
23. The computer implemented method of claim 22 further comprising: providing an application environment for a third-party application to run on, the application environment being configured to:30 route control signals from the control interface to the third-party application; androute video signals between the third-party application and the video conferencing hardware and / or a content stream of the conference call.
24. The computer implemented method of claims 22 or 23 further comprising storing application status 35 information associated with the third-party application, wherein the application status information is stored with the access token.
25. The computer implemented method of any of claims 22 to 24 further comprising using the access token to retrieve application status information associated with the third-party application; and40 using the application status information to configure the third-party application running on thevideo end-system.
26. A computer program comprising instructions which, when the computer program is executed by a computer, cause the computer to carry out the method of any one of the preceding claims.
27. A video end-system comprising a main processor, the main processor being configured to5 communicate with a control interface and video conferencing hardware for performing a conference call; wherein the main processor of the video end-system is configured to perform the computer implemented method of any one of claims 1 to 25.
28. A network of video end-systems comprising a plurality of video end-systems according to claim 27;10 wherein the plurality of video end-systems are connected to the centralised collaboration servicecomprising user account information.25 06 25
Citation Information
Patent Citations
Personalized services based on confirmed proximity of user
US20190372988A1