IP Library › Granted Patent US 11,797,363
Granted Patent B2
US 11,797,363 · App. 17/090,426 · Granted Oct 24, 2023

Application programming interface fingerprint data generation at a mobile device executing a native mobile application

Inventors: Charles Eric Smith (Dripping Springs, TX); Sergio Gustavo Ayestaran (Buenos Aires, AR)
Assignee: AppBrilliance, Inc.
G06F9/547G06F9/54G06F16/9577G06F40/221G06Q20/1085G06Q20/322G06Q20/401G06Q40/02H04L67/02H04L67/04H04L67/10H04L67/125H04L67/141H04L67/53H04L67/566G06F40/106
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,797,363
App. No.
17/090,426
Granted
Oct 24, 2023
Kind
B2
Abstract

Systems, methods, and computer-readable storage devices that enable secured data access from a mobile device executing a native mobile application and a headless browser. The technology includes interactions between an API, a secure connection, a headless browser, that utilize one or more of web site data, fingerprint data file locations and additional web page data.

Claims (88)

1. A mobile device comprising:

a wireless transceiver configured to communicate with a remote server that hosts a website;

a processor; and

a memory storing a native application that is executable by the processor to perform operations comprising:

receiving a user input identifying a name associated with the website;

sending, to a directory server, a request for application programming interface (API) fingerprint data associated with the name;

receiving, from the directory server, particular API fingerprint data associated with the name;

initiating a secured connection via the wireless transceiver from a headless browser of the native application to the remote server;

receiving first web page data of the website from the remote server via the secured connection;

parsing the first web page data based on the particular API fingerprint data associated with the name;

detecting an error condition associated with accessing the first website based on the received API fingerprint data;

parsing the first web page data to identify first locations of one or more elements of the website;

generating first application programming interface (API) fingerprint data indicating a mapping between the one or more elements of the website and the native application;

sending the first API fingerprint data to the directory server;

initiating a secured connection via the wireless transceiver from a headless browser of the native application to the remote server;

receiving second web page data of the website from the remote server via the secured connection;

parsing the second web page data to identify first locations of one or more elements of the website;

generating second application programming interface (API) fingerprint data indicating a mapping between the one or more elements of the website and the native application; and

sending the second API fingerprint data to the directory server.

2. The mobile device of claim 1 , wherein the first API fingerprint data indicates a mapping between the website and the native application for a collection of inputs including one or more of a username, a password, and a login button.

3. The mobile device of claim 1 , wherein the headless browser comprises a web browser not having a corresponding displayed graphical user interface.

4. The mobile device of claim 1 , wherein the website includes content formatted for presentation on a desktop computer, a laptop computer, or a mobile device.

5. The mobile device of claim 1 , wherein the operations further comprise:

sending, by the headless browser via the secured connection, access credential data to the remote server;

receiving second web page data of the website from the remote server via the secured connection;

parsing the second web page data to identify user-specific data; and

displaying, via a display device coupled to the processor, the user-specific data in a graphical user interface of the native application.

6. The mobile device of claim 5 , further comprising the display device and a user input device configured to receive the user input.

7. The mobile device of claim 5 , wherein the operations further comprise:

parsing the second web page data to identify locations of one or more transactional elements of the website;

generating second API fingerprint data indicating a mapping between transactional elements of the website and transactional elements of the native application; and

sending the second API fingerprint data to the directory server.

8. The mobile device of claim 7 , wherein the one or more transactional elements of the website are configured to enable a read operation with respect to secured data, a write operation with respect to the secured data, or both.

9. The mobile device of claim 7 , wherein the operations further comprise:

receiving a user command via a user input device; and

sending, by the headless browser via the secured connection, transaction data to the remote server to modify secured data based on the user command.

10. The mobile device of claim 1 , wherein the wireless transceiver includes or is coupled to radio frequency (RF) circuitry, a controller, an antenna, or a combination thereof.

11. The mobile device of claim 1 , wherein the operations further comprise:

in response to receiving the response indicating that no API fingerprint data has been found for the name, providing a prompt for an address of the website via a graphical user interface of the native application; and

receiving a second user input identifying the address of the website.

12. A method of mobile device operation, the method comprising:

receiving, at a mobile device executing a native application, a user input identifying a name associated with a website hosted by a remote server;

sending, to a directory server, a request for application programming interface (API) fingerprint data associated with the name;

receiving, from the directory server, particular API fingerprint data associated with the name;

initiating a secured connection via the wireless transceiver from a headless browser of the native application to the remote server;

receiving first web page data of the website from the remote server via the secured connection;

parsing the first web page data based on the particular API fingerprint data associated with the name;

detecting an error condition associated with accessing the first website based on the received API fingerprint data;

parsing the first web page data to identify one or more elements of the website;

generating first API fingerprint data indicating a mapping between the one or more elements of the website and the native application;

sending the first API fingerprint data to the directory server;

receiving a second user input identifying a second name associated with a second website hosted by a second remote server;

sending, to the directory server, a request for API fingerprint data associated with the second name;

receiving, from the directory server, particular API fingerprint data associated with the second name;

detecting an error condition associated with logging onto the second website based on the particular API fingerprint data;

sending, to the directory server, a request for additional API fingerprint data associated with the second website;

receiving, from the directory server, second particular API fingerprint data associated with a different website; and

logging in to the second website via the headless browser based on the second particular API fingerprint data and access credential data.

13. The method of claim 12 , wherein parsing the first web page data comprises performing a screen scraping operation, a Javascript injection operation or other supported language interpreted by a web browser, a document object model (DOM) inspection operation, or a combination thereof, on the first web page data to identify the one or more elements.

14. The method of claim 12 , further comprising logging in to the second website via the headless browser based on the particular API fingerprint data and access credential data.

15. The method of claim 12 , further comprising:

detecting an error condition associated with logging into the second website based on the particular API fingerprint data;

parsing second web page data of the second website to identify locations of one or more elements of the second website;

generating updated API fingerprint data indicating a mapping between one or more elements of the second website and the native application; and

sending the additional API fingerprint data to the directory server.

16. A non-transitory, computer-readable medium storing instructions that, when executed by a processor, cause the processor to perform operations comprising:

receiving, at a mobile device executing a native application, a user input identifying a name associated with a website hosted by a remote server;

sending, to a directory server, a request for application programming interface (API) fingerprint data associated with the name;

receiving, from the directory server, particular API fingerprint data associated with the name;

initiating a secured connection via the wireless transceiver from a headless browser of the native application to the remote server;

receiving first web page data of the website from the remote server via the secured connection;

parsing the first web page data based on the particular API fingerprint data associated with the name;

detecting an error condition associated with accessing the first website based on the received API fingerprint data;

parsing the first web page data to identify locations of one or more elements of the website;

generating first API fingerprint data indicating a mapping between the one or more elements of the website and the native application;

sending the first API fingerprint data to the directory server;

receiving a second user input identifying a second name associated with a second website hosted by a second remote server;

sending, to the directory server, a request for API fingerprint data associated with the second name;

receiving, from the directory server, particular API fingerprint data associated with the second name;

detecting an error condition associated with logging onto the second website based on the particular API fingerprint data;

sending, to the directory server, a request for additional API fingerprint data associated with the second website;

receiving, from the directory server, second particular API fingerprint data associated with a different website; and

logging in to the second website via the headless browser based on the second particular API fingerprint data and access credential data.

17. The non-transitory, computer-readable medium of claim 16 , wherein the operations further comprise:

determining, based on the user input, a plurality of websites potentially associated with the name;

receiving, from the directory server, API fingerprint data associated with each of the plurality of websites; and

attempting to login to each of the plurality of websites based on the API fingerprint data and based on access credential data.

18. The non-transitory, computer-readable medium of claim 17 , wherein the name includes a full name or a partial name of an institution associated with the website.

Continuity (4)
Continuation 15987783 · May 23, 2018
Continuation In Part 15474981 · Mar 30, 2017
Provisional Application 62316373 · Mar 31, 2016
Related Publication 20210133009A1 · May 6, 2021
Cited By (1)
US 12,314,788