IP Library Granted Patent US 12,362,936
Granted Patent B2
US 12,362,936 · App. 18/120,774 · Granted Jul 15, 2025

Methods and systems for authenticating a candidate user of a first and as second electronic service

Inventors: Sergey Vyacheslavovich Baibik (Sankt-Peterburg, RU); Oleg Vitalevich Isupov (Novosibirsk, RU); Evgeny Mikhailovich Primako (Moscow, RU); Eldar Timurovich Zaitov (Sankt-Peterburg, RU); Pavel Nikolaevich Vorobkalov (Volgograd, RU); Vitaly Borisovich Kholyavin (Balashikha, RU)
Assignee: Y.E. Hub Armenia LLC
H04L9/3213H04L9/0637H04L9/0643
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,362,936
App. No.
18/120,774
Granted
Jul 15, 2025
Kind
B2
Abstract

Method and system for authenticating a candidate user are disclosed. The method includes acquiring, by a second service from a first service, a request for a candidate User-Service Unique Identifier (USUID) associated with the candidate user. The candidate USUID is unique for a candidate user-first service pair. The method includes generating, by the second service, the candidate USUID, and sending a token indicative of the candidate USUID. In response to the candidate USUID matching a target USUID, the first service authenticates the candidate user as a target user without prompting the candidate user to provide additional information.

Claims (34)

1. A method of authenticating a candidate user associated with a first service and a second service, the first service and the second service being executed on respective backend servers, an electronic device of the candidate user being communicatively couplable to the respective back-end servers over a communication network, the method comprising,

at a given moment in time:

acquiring, by the second service from the first service, a request for a candidate User-Service Unique Identifier (USUID) associated with the candidate user currently attempting to access the first service, the first service being associated with a Service Unique Identifier (SUID),

the candidate USUID being unique for a candidate user-first service pair, the SUID being unique for the first service;

in response to the candidate user having been previously authenticated in the second service, generating, by the second service, the candidate USUID by encrypting (i) user information of the candidate user authenticating the candidate user in the second service and (ii) the SUID;

acquiring, by the first service from the second service, a token indicative of the candidate USUID and a signature;

in response to validating the signature, comparing the candidate USUID acquired at the given moment in time against a target USUID associated with a target user of the first service acquired at an other moment in time, the other moment in time being before the given moment in time; and

in response to the candidate USUID matching the target USUID, authenticating, by the first service, the candidate user as the target user without prompting the candidate user to provide additional information.

2. The method of claim 1 , wherein the target user has been authenticated with the first service at the other moment in time, the target USUID having been stored by the first service in response to authentication at the other moment in time.

3. The method of claim 2 , wherein the target user has been authenticated directly with the first service.

4. The method of claim 2 , wherein the target user has been authenticated with the first service indirectly in the second service.

5. The method of claim 1 , wherein the encrypting comprises encrypting, by the second service, the user information using a first secret key and the SUID as an initialization vector for a Galois/Counter Mode (GCM) algorithm.

6. The method of claim 1 , wherein the method further comprises generating, by the second service, the signature using a second secret key with a Hash Message Authentication Code (HMAC) algorithm.

7. The method of claim 1 , wherein the token is a JSON Web Token (JWT) having a header portion, a payload portion, and a signature portion, the USUID being inserted into the payload portion and the signature being inserted into the signature portion.

8. The method of claim 7 , wherein a timestamp value is further inserted into the payload portion, the timestamps being indicative a period of time during which the USUID is valid.

9. The method of claim 1 , wherein the first service and the second service have a same operator.

10. The method of claim 1 , wherein an operator of the first service is different from an operator of the second service.

11. A system for authenticating a candidate user associated with a first service and a second service, the first service and the second service of the system being executed on respective backend servers, an electronic device of the candidate user being communicatively couplable to the respective back-end servers over a communication network, the system being configured to:

at a given moment in time:

acquire, by the second service from the first service, a request for a candidate User-Service Unique Identifier (USUID) associated with the candidate user currently attempting to access the first service, the first service being associated with a Service Unique Identifier (SUID),

the candidate USUID being unique for a candidate user-first service pair, the SUID being unique for the first service;

in response to the candidate user having been previously authenticated in the second service, generate, by the second service, the candidate USUID by encrypting (i) user information of the candidate user authenticating the candidate user in the second service and (ii) the SUID;

acquire, by the first service from the second service, a token indicative of the candidate USUID and a signature;

in response to validating the signature, compare the candidate USUID acquired at the given moment in time against a target USUID associated with a target user of the first service acquired at an other moment in time, the other moment in time being before the given moment in time; and

in response to the candidate USUID matching the target USUID, authenticate, by the first service, the candidate user as the target user without prompting the candidate user to provide additional information.

12. The system of claim 11 , wherein the target user has been authenticated with the first service at the other moment in time, the target USUID having been stored by the first service in response to authentication at the other moment in time.

13. The system of claim 12 , wherein the target user has been authenticated directly with the first service.

14. The system of claim 12 , wherein the target user has been authenticated with the first service indirectly in the second service.

15. The system of claim 11 , wherein to encrypt comprises the system configured to encrypt, by the second service, the user information using a first secret key and the SUID as an initialization vector for a Galois/Counter Mode (GCM) algorithm.

16. The system of claim 11 , wherein the system is further configured to generate, by the second service, the signature using a second secret key in a Hash Message Authentication Code (HMAC) algorithm.

17. The system of claim 11 , wherein the token is a JSON Web Token (JWT) having a header portion, a payload portion, and a signature portion, the USUID being inserted into the payload portion and the signature being inserted into the signature portion.

18. The system of claim 17 , wherein a timestamp value is further inserted into the payload portion, the timestamps being indicative a period of time during which the USUID is valid.

19. The system of claim 11 , wherein the first service and the second service have a same operator.

20. The system of claim 11 , wherein an operator of the first service is different from an operator of the second service.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 9, 2024
From: DIRECT CURSUS TECHNOLOGY L.L.C
To: Y.E. HUB ARMENIA LLC
Reel/Frame 068534/0818 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 15, 2023
From: YANDEX EUROPE AG
To: DIRECT CURSUS TECHNOLOGY L.L.C
Reel/Frame 065692/0720 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2023
From: YANDEX.TECHNOLOGIES LLC
To: YANDEX LLC
Reel/Frame 064121/0041 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2023
From: YANDEX LLC
To: YANDEX EUROPE AG
Reel/Frame 064121/0052 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2023
From: BAIBIK, SERGEY VYACHESLAVOVICH; ISUPOV, OLEG VITALEVICH; PRIMAKO, EVGENY MIKHAILOVICH; ZAITOV, ELDAR TIMUROVICH; VOROBKALOV, PAVEL NIKOLAEVICH; KHOLYAVIN, VITALY BORISOVICH
To: YANDEX.TECHNOLOGIES LLC
Reel/Frame 064178/0113 →
Priority Claims (1)
RU 2022106749 · Mar 15, 2022 · national
Continuity (1)
Related Publication 20230299958A1 · Sep 21, 2023
References Cited (15)
US 10902016B2 · Shamsutdinov · 2021 [cited by applicant]
US 10931461B2 · Dilles et al. · 2021 [cited by applicant]
US 11012374B2 · Momchilov et al. · 2021 [cited by applicant]
US 11064047B1 · Stegall et al. · 2021 [cited by applicant]
US 20110179469A1 · Blinn · 2011 [cited by examiner]
US 20150249540A1 · Khalil · 2015 [cited by examiner]
RU 2308755C2 · 2007 [cited by applicant]
RU 2693330C2 · 2019 [cited by applicant]
RU 2740308C1 · 2021 [cited by applicant]
Russian Search Report dated Jul. 27, 2023 issued in respect of the counterpart Russian Patent Application No. RU 2022106749. [cited by applicant]
Web Article, “Client IDs in AMP pages” retrieved on Feb. 9, 2023, https://developers.google.com/analytics/devguides/collection/amp-analytics/client-id#client_id_considerations. [cited by applicant]
Web Article, “Microsoft Account”, retrieved on Dec. 10, 2021 from Wikipedia, https://en.wikipedia.org/wiki/Microsoft_account. [cited by applicant]
Web article “OAuth 2.0 Protocol” retrieved on Feb. 9, 2023 with the English translation obtained on Google Translate. [cited by applicant]
D. Hardt, Ed., “The OAuth 2.0 Authorization Framework”, published in Oct. 2012, retrieved on Dec. 10, 2021, https://datatracker.ietf.org/doc/html/rfc6749. [cited by applicant]
Micah Silverman, “Implement the OAuth 2.0 Authorization Code with PKCE Flow”, published on Aug. 22, 2019, retrieved on Dec. 10, 2021, https://developer.okta.com/blog/2019/08/22/okta-authjs-pkce. [cited by applicant]