IP Library Granted Patent US 12,137,090
Granted Patent B1
US 12,137,090 · App. 17/738,749 · Granted Nov 5, 2024

Secured automatic user log-in at website via personal electronic device

Inventors: Peter Manwiller (Chicago, IL); Lindsey Whitaker (Chicago, IL)
Assignee: WALGREEN CO.
H04L63/0815H04L63/0876H04L63/102H04W12/06H04W12/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,137,090
App. No.
17/738,749
Granted
Nov 5, 2024
Kind
B1
Abstract

Techniques for providing secured, automatic log-in and authentication of a user to a website via a browser executing at the user's personal electronic device (PED) include generating a token based on an identifier of the PED and a user identifier, and storing the token at the user's PED for use in validating and authenticating the user and device credentials against those stored at back-end system and/or in another memory location at the device. Based on the persisted token (and optionally on a user preference), the user may be automatically logged in as the user navigates across restricted and unrestricted portions of the website, and/or to other websites (e.g., without the user's knowledge). At least these features enable automatic log-in and authentication to be performed on an as-needed basis, and/or on a per-device basis, thereby providing significantly more secure access as compared to known techniques.

Claims (47)

1. A method for automatically providing, to a user using a mobile device, access to a website, the method comprising:

upon receiving, at a system corresponding to a website including a restricted portion, an indication of the user navigating, via the mobile device, to the restricted portion of the website:

when the mobile device stores an access token corresponding to the user and the website and the access token corresponds to (i) a user identifier associated with the user and the website, (ii) a first device identifier that is uniquely indicative of the mobile device and that is stored at the mobile device, and (iii) a user preference for persisting automatic access of the user at the website, automatically providing, by the system, the user access to the restricted portion of the website; and

when the mobile device does not store the access token:

providing, by the system, the user access to the restricted portion of the website when the first device identifier and a second device identifier indicated by a user profile that is associated with the website and that is stored at a back-end system are in accordance; and

requesting the user to log-in in order to access the restricted portion of the website when the first device identifier and the second device identifier are not in accordance.

2. The method of claim 1 , wherein:

the mobile device stores the access token;

automatically providing the user access to the restricted portion of the website includes automatically logging in the user at the website; and

the method further comprises deleting the access token from the mobile device upon the user explicitly logging off of the website.

3. The method of claim 2 , further comprising:

upon the user closing a browser at the mobile device via which the user navigated to the restricted portion of the website without the user explicitly logging off of the website, automatically logging the user off of the website and persisting the access token stored at the mobile device.

4. The method of claim 1 , wherein the mobile device stores the access token, and the method further comprises deleting the access token from the mobile device responsive to at least one of:

(i) a determination that the first device identifier does not correspond to the second device identifier,

(ii) a reception of an updated user preference for not persisting automatic access of the user at the website; or

(iii) a determination that the user has explicitly logged off of the website.

5. The method of claim 1 , wherein the access token is automatically generated responsive to obtaining the user preference for persisting the automatic access of the user at the website.

6. The method of claim 5 , wherein at least a portion of the access token is encrypted.

7. The method of claim 1 , wherein the restricted portion of the website corresponds to at least one of: account information of the user, contents of the user profile, prescription information corresponding to the user, or payment information corresponding to the user.

8. A system for automatically providing, to a user using a mobile device, access to a website, comprising:

computer-executable instructions that are stored on one or more memories of the mobile device and that, when executed by one or more processors of the mobile device, cause the mobile device to, upon receiving an indication of the user navigating, via the mobile device, to a restricted portion of the website:

when the mobile device stores an access token corresponding to the user and the website, and the access token corresponds to (i) a user identifier associated with the user and the website, (ii) a first device identifier that is uniquely indicative of the mobile device and that is stored at the mobile device, and (iii) a user preference for persisting automatic access of the user at the website, automatically provide the user access to the restricted portion of the website; and

when the mobile device does not store the access token corresponding to the user and the website:

provide the user access to the restricted portion of the website when the first device identifier and a second device identifier indicated by a user profile that is associated with the website and that is stored at a back-end system are in accordance; and

request the user to log-in in order to access the restricted portion of the website when the first device identifier and the second device identifier are not in accordance.

9. The system of claim 8 , wherein the computer-executable instructions are further executable to cause the mobile device to delete the access token from the mobile device when at least one of: (i) the user explicitly logs off of the website, (ii) the first device identifier is determined to not correspond to the second device identifier, or (iii) the user indicates an updated preference for not persisting automatic access of the user at the website.

10. The system of claim 8 , wherein the computer-executable instructions are executable to cause the mobile device further to persist the access token stored at the mobile device when at least one of: (i) the user does not explicitly log off of the website before closing a browser via which the user accessed the website at the mobile device, or (ii) the user is passively logged off of the website.

11. The system of claim 8 , wherein at least one of the first device identifier or the second device identifier corresponds to at least one of: an IMEI of the mobile device, a UUID corresponding to the user, a GUID corresponding to the user, a phone number corresponding to the mobile device, a MAC address indicative of the mobile device, an IP address indicative of the mobile device, another indicator of a communicative connection established between a browser executing at the mobile device and the website, a type and/or version of an operating system operating on the mobile device, a type and/or version of the browser, or other data stored by the browser.

12. The system of claim 8 , wherein the restricted portion of the website corresponds to at least one of: account information of the user, contents of the user profile, prescription information corresponding to the user, or payment information corresponding to the user.

13. The system of claim 9 , wherein the access token is stored in conjunction with a browser at the mobile device.

14. The system of claim 8 , wherein the computer-executable instructions are executable to cause the mobile device further to automatically generate the access token upon obtaining the user preference for persisting automatic access of the user at the website.

15. The system of claim 8 , wherein at least a portion of the access token is encrypted.

16. A method for automatically providing, to a user operating a mobile device, access to a restricted portion of a website of an enterprise, the method comprising:

receiving an indication of the user navigating, via the mobile device, to a restricted portion of a website;

responsive to receiving the indication of the user navigating to the restricted portion of the website, automatically providing the user access to the restricted portion of the website when:

the mobile device stores an access token corresponding to (i) a user identifier associated with the user and the website, (ii) a first device identifier uniquely indicative of the mobile device and stored at the mobile device, and (iii) a user preference for persisting automatic access of the user at the website; or

the first device identifier and a second device identifier indicated by a user profile indicating one or more user access credentials corresponding to the website are in accordance; and

responsive to receiving the indication of the user navigating to the restricted portion of the website, requesting the user to log-in in order to access the restricted portion of the website when the mobile device does not store the access token and the first device identifier and the second device identifier are not in accordance.

17. The method of claim 16 , further comprising:

automatically generating the access token based on the first device identifier responsive to obtaining the user preference for persisting the automatic access of the user at the website; and

deleting the access token from the mobile device responsive to at least one of:

(i) a determination that the first device identifier does not correspond to the second device identifier;

(ii) an updated user preference for not persisting automatic access of the user at the website; or

(iii) a determination that the user has explicitly logged off of the website.

18. The method of claim 17 , further comprising persisting the access token stored at the mobile device when at least one of: (i) the user does not explicitly log off of the website before closing a browser via which the user accessed the website at the mobile device, or (ii) the user is passively logged off of the website.

19. The method of claim 16 , wherein at least one of the first device identifier or the second device identifier corresponds to at least one of: an IMEI of the mobile device, a UUID corresponding to the user, a GUID corresponding to the user, a phone number corresponding to the mobile device, a MAC address indicative of the mobile device, an IP address indicative of the mobile device, another indicator of a communicative connection established between a browser executing at the mobile device and the website, a type and/or version of an operating system operating on the mobile device, a type and/or version of the browser, or other data stored by the browser.

20. The method of claim 16 , wherein the restricted portion of the website corresponds to at least one of: account information of the user, contents of the user profile, prescription information corresponding to the user, or payment information corresponding to the user.

Assignments (3)
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 28, 2025
From: WALGREEN CO.
To: SIXTH STREET LENDING PARTNERS, AS COLLATERAL AGENT
Reel/Frame 072606/0878 →
SECURITY INTEREST Recorded Aug 28, 2025
From: WALGREEN CO.; DUANE READE; WALGREENS SPECIALTY PHARMACY LLC; WALGREENS BOOTS ALLIANCE, INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 072679/0926 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 21, 2022
From: MANWILLER, PETER; WHITAKER, LINDSEY
To: WALGREEN CO.
Reel/Frame 059977/0313 →
Continuity (2)
Continuation 16935975 · Jul 22, 2020
Continuation 15406152 · Jan 13, 2017