IP Library Granted Patent US 11,645,377
Granted Patent B1
US 11,645,377 · App. 17/035,960 · Granted May 9, 2023

Online authentication and security management using device-based identification

Inventor: Peter Manwiller (Chicago, IL)
Assignee: WALGREEN CO.
G06F21/34G06F21/316H04L63/0876H04L63/10H04L63/126H04L63/1408H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,645,377
App. No.
17/035,960
Granted
May 9, 2023
Kind
B1
Abstract

Techniques are disclosed to provide enhanced online security. A network server actively monitors data between a network server hosting a website and a computing device. Some of the disclosed techniques leverage “cookie stitchers” to associate user data, which may include a website identifier, to the user's computing devices. These techniques allow the network server to block access to explicitly identified computing devices, or to trigger two-factor authentication.

Claims (40)

1. A computer-implemented method in a network server, comprising:

actively monitoring, by the network server hosting a website, web traffic between the network server and a computing device of a user currently navigating the website, wherein the web traffic is generated from the computing device visiting the website;

receiving, by the network server, user authenticating information that is provided via the computing device attempting to access a secure content that is hosted by the network server;

identifying a first attribute associated with the user authenticating information, wherein the first attribute is a first website identification that is used by the network server to uniquely identify the user and the website during a browsing session;

receiving, by the network server from an external computing device, user data for the user based upon an identified association of the computing device with the user, wherein the external computing device is external from the network server and distinct from the computing device;

identifying a second attribute included in the user data, wherein the second attribute is a second website identification that uniquely identifies the user and the website;

determining whether the first website identification matches the second website identification;

when the first website identification and the second website identification match one another, granting, by the network server, the computing device access to the secure content; and

when the first website identification and the second website identification do not match one another, triggering, by the network server, execution of a two-factor authentication (2FA).

2. The computer-implemented method of claim 1 , wherein receiving the user data comprises:

receiving, by the network server from a cookie-stitching server, the user data.

3. The computer-implemented method of claim 2 , wherein the cookie-stitching server identifies the user data by determining which one of several sets of user data is associated with the computing device.

4. The computer-implemented method of claim 3 , wherein the cookie-stitching server identifies the user data using one or more of (i) cookie data, (ii) unique device identifiers, and (iii) browser information.

5. The computer-implemented method of claim 1 , wherein the secure content includes one or more of payment information, prescription information, and health-related information.

6. A computer-readable non-transitory storage medium comprising instructions that, when executed, cause one or more processors to:

actively monitor web traffic between a network server hosting a website and a computing device of a user currently navigating the website, wherein the web traffic is generated from the computing device visiting the website;

receive, by the one or more processors, user authenticating information that is provided via the computing device attempting to access a secure content that is hosted by the network server;

identify, by the one or more processors, a first attribute associated with the user authenticating information, wherein the first attribute is a first website identification that is used by the network server to uniquely identify the user and the website during a browsing session;

receive, by the one or more processors from an external computing device, user data for the user based upon an identified association of the computing device with the user, wherein the external computing device is external from the network server and distinct from the computing device;

identify, by the one or more processors, a second attribute included in the user data, wherein the second attribute is a second website identification that uniquely identifies the user and the website;

determine, by the one or more processors, whether the first website identification matches the second website identification;

when the first website identification and the second website identification match one another, grant, by the one or more processors, the computing device access to the secure content; and

when the first website identification and the second website identification do not match one another, trigger, by the one or more processors, execution of a two-factor authentication (2FA), and grant the computing device access to the secure content upon satisfaction of one or more conditions associated with the 2FA.

7. The computer-readable non-transitory storage medium of claim 6 , wherein the external computing device is a cookie-stitching server.

8. The computer-readable non-transitory storage medium of claim 7 , wherein a processor of the cookie-stitching server identifies the user data by determining which one of several sets of user data is associated with the computing device.

9. The computer-readable non-transitory storage medium of claim 7 , wherein a processor of the cookie-stitching server identifies the user data including one or more of (i) data from a cookie, (ii) unique device identifiers, and (iii) browser information.

10. The computer-readable non-transitory storage medium of claim 6 , wherein the secure content includes one or more of payment information, prescription information, and health-related information.

11. A system for providing access to a secure content, comprising:

a memory storing a set of instructions; and

a processor interfaced with the memory and configured to execute the set of instructions to cause the processor to:

actively monitor web traffic between a network server hosting a website and a computing device of a user currently navigating the website, wherein the web traffic is generated from the computing device visiting the website;

receive user authenticating information that is provided via the computing device attempting to access the secure content that is hosted by the network server;

identify a first attribute associated with the user authenticating information, wherein the first attribute is a first website identification that is used by the network server to uniquely identify the user and the website during a browsing session;

receive, from an external computing device, user data for the user based upon an identified association of the computing device with the user, wherein the external computing device is external from the network server and distinct from the computing device;

identify a second attribute included in the user data, wherein the second attribute is a second website identification that uniquely identifies the user and the website;

determine whether the first website identification matches the second website identification;

when the first website identification and the second website identification match one another, grant the computing device access to the secure content; and

when the first website identification and the second website identification do not match one another, trigger execution of a two-factor authentication (2FA).

12. The system of claim 11 , wherein the external computing device is a cookie-stitching server.

13. The system of claim 11 , wherein the secure content includes one or more of payment information, prescription information, and health-related information.

Assignments (3)
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 28, 2025
From: WALGREEN CO.
To: SIXTH STREET LENDING PARTNERS, AS COLLATERAL AGENT
Reel/Frame 072606/0878 →
SECURITY INTEREST Recorded Aug 28, 2025
From: WALGREEN CO.; DUANE READE; WALGREENS SPECIALTY PHARMACY LLC; WALGREENS BOOTS ALLIANCE, INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 072679/0926 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2020
From: MANWILLER, PETER
To: WALGREEN CO.
Reel/Frame 053912/0791 →
Continuity (1)
Division 15679776 · Aug 17, 2017