Online authentication and security management using device-based identification
Techniques are disclosed to provide enhanced online security. A network server actively monitors data between a network server hosting a website and a computing device. Some of the disclosed techniques leverage “cookie stitchers” to associate user data, which may include a website identifier, to the user's computing devices. These techniques allow the network server to block access to explicitly identified computing devices, or to trigger two-factor authentication.
1. A computer-implemented method in a network server, comprising:
actively monitoring, by the network server hosting a website, web traffic between the network server and a computing device of a user currently navigating the website, wherein the web traffic is generated from the computing device visiting the website;
receiving, by the network server, user authenticating information that is provided via the computing device attempting to access a secure content that is hosted by the network server;
identifying a first attribute associated with the user authenticating information, wherein the first attribute is a first website identification that is used by the network server to uniquely identify the user and the website during a browsing session;
receiving, by the network server from an external computing device, user data for the user based upon an identified association of the computing device with the user, wherein the external computing device is external from the network server and distinct from the computing device;
identifying a second attribute included in the user data, wherein the second attribute is a second website identification that uniquely identifies the user and the website;
determining whether the first website identification matches the second website identification;
when the first website identification and the second website identification match one another, granting, by the network server, the computing device access to the secure content; and
when the first website identification and the second website identification do not match one another, triggering, by the network server, execution of a two-factor authentication (2FA).
2. The computer-implemented method of claim 1 , wherein receiving the user data comprises:
receiving, by the network server from a cookie-stitching server, the user data.
3. The computer-implemented method of claim 2 , wherein the cookie-stitching server identifies the user data by determining which one of several sets of user data is associated with the computing device.
4. The computer-implemented method of claim 3 , wherein the cookie-stitching server identifies the user data using one or more of (i) cookie data, (ii) unique device identifiers, and (iii) browser information.
5. The computer-implemented method of claim 1 , wherein the secure content includes one or more of payment information, prescription information, and health-related information.
6. A computer-readable non-transitory storage medium comprising instructions that, when executed, cause one or more processors to:
actively monitor web traffic between a network server hosting a website and a computing device of a user currently navigating the website, wherein the web traffic is generated from the computing device visiting the website;
receive, by the one or more processors, user authenticating information that is provided via the computing device attempting to access a secure content that is hosted by the network server;
identify, by the one or more processors, a first attribute associated with the user authenticating information, wherein the first attribute is a first website identification that is used by the network server to uniquely identify the user and the website during a browsing session;
receive, by the one or more processors from an external computing device, user data for the user based upon an identified association of the computing device with the user, wherein the external computing device is external from the network server and distinct from the computing device;
identify, by the one or more processors, a second attribute included in the user data, wherein the second attribute is a second website identification that uniquely identifies the user and the website;
determine, by the one or more processors, whether the first website identification matches the second website identification;
when the first website identification and the second website identification match one another, grant, by the one or more processors, the computing device access to the secure content; and
when the first website identification and the second website identification do not match one another, trigger, by the one or more processors, execution of a two-factor authentication (2FA), and grant the computing device access to the secure content upon satisfaction of one or more conditions associated with the 2FA.
7. The computer-readable non-transitory storage medium of claim 6 , wherein the external computing device is a cookie-stitching server.
8. The computer-readable non-transitory storage medium of claim 7 , wherein a processor of the cookie-stitching server identifies the user data by determining which one of several sets of user data is associated with the computing device.
9. The computer-readable non-transitory storage medium of claim 7 , wherein a processor of the cookie-stitching server identifies the user data including one or more of (i) data from a cookie, (ii) unique device identifiers, and (iii) browser information.
10. The computer-readable non-transitory storage medium of claim 6 , wherein the secure content includes one or more of payment information, prescription information, and health-related information.
11. A system for providing access to a secure content, comprising:
a memory storing a set of instructions; and
a processor interfaced with the memory and configured to execute the set of instructions to cause the processor to:
actively monitor web traffic between a network server hosting a website and a computing device of a user currently navigating the website, wherein the web traffic is generated from the computing device visiting the website;
receive user authenticating information that is provided via the computing device attempting to access the secure content that is hosted by the network server;
identify a first attribute associated with the user authenticating information, wherein the first attribute is a first website identification that is used by the network server to uniquely identify the user and the website during a browsing session;
receive, from an external computing device, user data for the user based upon an identified association of the computing device with the user, wherein the external computing device is external from the network server and distinct from the computing device;
identify a second attribute included in the user data, wherein the second attribute is a second website identification that uniquely identifies the user and the website;
determine whether the first website identification matches the second website identification;
when the first website identification and the second website identification match one another, grant the computing device access to the secure content; and
when the first website identification and the second website identification do not match one another, trigger execution of a two-factor authentication (2FA).
12. The system of claim 11 , wherein the external computing device is a cookie-stitching server.
13. The system of claim 11 , wherein the secure content includes one or more of payment information, prescription information, and health-related information.