IP Library Granted Patent US 12,488,082
Granted Patent B1
US 12,488,082 · App. 18/193,256 · Granted Dec 2, 2025

Online authentication and security management using device-based identification

Inventor: Peter Manwiller (Chicago, IL)
Assignee: WALGREEN CO.
G06F21/34G06F21/316H04L63/0876H04L63/10H04L63/126H04L63/1408H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,488,082
App. No.
18/193,256
Granted
Dec 2, 2025
Kind
B1
Abstract

Techniques are disclosed to provide enhanced online security. When user authenticating information is provided to access secure content, a network server identifies the user via a website identifier. Some of the disclosed techniques leverage third party “cookie stitchers” to associate user data, which may include a website identifier, to the user's computing devices. If the cookie stitcher cannot identify a current computing device, or if a current website identifier does not match one stored in the user data, then 2-factor authentication (2FA) may be triggered. Other disclosed techniques leverage stored device management data (DMD), which uniquely identifies each computing device that is associated with a website identifier. These techniques allow the network server to block access to explicitly-identified computing devices, and to trigger 2FA unless specific computing device metrics, which are associated with a computing device, are matched to computing device metrics contained in the DMD.

Claims (31)

1 . A system for providing access to secure content, comprising:

a network server having a memory storing a set of instructions and one or more processors interfaced with the memory and configured to receive user authenticating information that is provided via a computing device attempting to access secure content that is hosted by the network server; and

a cookie-stitching server configured to:

access a storage device containing sets of user data that are correlated to respective sets of computing devices, wherein each set of user data is stored with an associated agency identification that uniquely identifies a user,

receive from the network server user and device identifying data,

in response to identifying, based at least in part on the user and device identifying data, an agency identification, send a set of user data associated with the agency identification to the network server, and

in response to not identifying an agency identification, send a notification to the network server,

wherein the network server is further configured to:

in response to receiving the set of user data from the cookie-stitching server, grant the computing device access to secure content that is provided by the network server upon verification that (i) user authenticating information received via the computing device is correct, and (ii) a website identifier generated by the network server from the user authenticating information, wherein the website identifier enables one or more back-end computing devices to provide access to the secure content during a browsing session, matches a website identifier associated with the set of user data received from the cookie-stitching server, and

in response to receiving the notification from the cookie-stitching server, trigger execution of a two-factor authentication (2FA), and grant the computing device access to the secure content upon satisfaction of one or more conditions associated with the 2FA.

2 . The system of claim 1 , wherein the cookie-stitching server is further configured to identify the user data using one or more of (i) cookie data, (ii) unique device identifiers, and (iii) browser information.

3 . The system of claim 1 , wherein the cookie-stitching server is further configured to access the set of user data, and to send the user data or the notification to the network server in real time.

4 . The system of claim 1 , wherein the secure content includes one or more of payment information, prescription information, and health-related information.

5 . The system of claim 1 , wherein the one or more conditions associated with the 2FA include sending an alphanumeric code to a computing device associated with the user data, requesting the alphanumeric code be entered via the computing device from which the user authenticating information was received, and verifying that an alphanumeric code received in response to the request matches the alphanumeric code sent in a text message.

6 . The system of claim 1 , wherein the one or more conditions associated with the 2FA include requesting that biometric information be entered via the computing device from which the user authenticating information was received, and verifying the biometric information received in response to the request.

7 . A method for providing access to secure content, comprising:

receiving, by a network server, user authenticating information that is provided via a computing device attempting to access secure content that is hosted by the network server,

accessing, by a cookie-stitching server, a storage device containing sets of user data that are correlated to respective sets of computing devices, wherein each set of user data is stored with an associated agency identification that uniquely identifies a user,

receiving from the network server user and device identifying data,

in response to identifying, based at least in part on the user and device identifying data, an agency identification, sending, by the cookie-stitching server, a set of user data associated with the agency identification to the network server, and

in response to not identifying an agency identification, sending, by the cookie-stitching server, a notification to the network server,

in response to receiving the set of user data from the cookie-stitching server, granting, by the network server, the computing device access to secure content that is provided by the network server upon verification that (i) user authenticating information received via the computing device is correct, and (ii) a website identifier generated by the network server from the user authenticating information, wherein the website identifier enables one or more back-end computing devices to provide access to the secure content during a browsing session, matches a website identifier associated with the set of user data received from the cookie-stitching server, and

in response to receiving the notification from the cookie-stitching server, triggering, by the network server, execution of a two-factor authentication (2FA), and granting, by the network server, the computing device access to the secure content upon satisfaction of one or more conditions associated with the 2FA.

8 . The method of claim 7 , further comprising:

identifying, by the cookie-stitching server, the user data using one or more of (i) cookie data, (ii) unique device identifiers, and (iii) browser information.

9 . The method of claim 7 , further comprising:

accessing, by the cookie-stitching server, the set of user data, and

sending, by the cookie-stitching server, the user data or the notification to the network server in real time.

10 . The method of claim 7 , wherein the secure content includes one or more of payment information, prescription information, and health-related information.

11 . The method of claim 7 , wherein the one or more conditions associated with the 2FA include sending an alphanumeric code to a computing device associated with the user data, requesting the alphanumeric code be entered via the computing device from which the user authenticating information was received, and verifying that an alphanumeric code received in response to the request matches the alphanumeric code sent in a text message.

12 . The method of claim 7 , wherein the one or more conditions associated with the 2FA include requesting that biometric information be entered via the computing device from which the user authenticating information was received, and verifying the biometric information received in response to the request.

Assignments (3)
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 28, 2025
From: WALGREEN CO.
To: SIXTH STREET LENDING PARTNERS, AS COLLATERAL AGENT
Reel/Frame 072606/0878 →
SECURITY INTEREST Recorded Aug 28, 2025
From: WALGREEN CO.; DUANE READE; WALGREENS SPECIALTY PHARMACY LLC; WALGREENS BOOTS ALLIANCE, INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 072679/0926 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 18, 2024
From: MANWILLER, PETER
To: WALGREEN CO.
Reel/Frame 066160/0173 →
Continuity (2)
Division 17035960 · Sep 29, 2020
Division 15679776 · Aug 17, 2017
References Cited (93)
US 5684945A · Chen · 1997 [cited by examiner]
US 6006260A · Barrick, Jr. · 1999 [cited by examiner]
US 6449739B1 · Landan · 2002 [cited by examiner]
US 6922776B2 · Cook · 2005 [cited by examiner]
US 7100049B2 · Gasparini · 2006 [cited by examiner]
US 7178025B2 · Scheidt · 2007 [cited by examiner]
US 7346775B2 · Gasparinl · 2008 [cited by examiner]
US 7526485B2 · Hagan · 2009 [cited by examiner]
US 7739512B2 · Hawkes · 2010 [cited by examiner]
US 8131799B2 · Landsman · 2012 [cited by examiner]
US 8321913B2 · Turnbull · 2012 [cited by examiner]
US 8356333B2 · Kramer · 2013 [cited by examiner]
US 8615809B2 · Bajaj · 2013 [cited by examiner]
US 8640216B2 · Anderson · 2014 [cited by examiner]
US 8856869B1 · Brinskelle · 2014 [cited by examiner]
US 8893255B1 · Martini · 2014 [cited by examiner]
US 8898450B2 · Harjanto · 2014 [cited by examiner]
US 9002018B2 · Wilkins · 2015 [cited by examiner]
US 9319419B2 · Sprague · 2016 [cited by examiner]
US 9361481B2 · LaFever · 2016 [cited by examiner]
US 9660974B2 · Grajek · 2017 [cited by examiner]
US 9781097B2 · Grajek · 2017 [cited by examiner]
US 9819684B2 · Cernoch · 2017 [cited by examiner]
US 9959694B2 · Lindsay · 2018 [cited by examiner]
US 10158489B2 · Shastri · 2018 [cited by examiner]
US 10171439B2 · Camenisch · 2019 [cited by examiner]
US 10387980B1 · Shahidzadeh · 2019 [cited by examiner]
US 10404678B2 · Grajek · 2019 [cited by examiner]
US 10419418B2 · Grajek · 2019 [cited by examiner]
US 11805300B2 · Shkedi · 2023 [cited by examiner]
US 20010044820A1 · Scott · 2001 [cited by examiner]
US 20010054155A1 · Hagan · 2001 [cited by examiner]
US 20040030784A1 · Abdulhayoglu · 2004 [cited by examiner]
US 20040039846A1 · Goss · 2004 [cited by examiner]
US 20040215959A1 · Cook · 2004 [cited by examiner]
US 20040243802A1 · Jorba · 2004 [cited by examiner]
US 20040250075A1 · Anthe, II · 2004 [cited by examiner]
US 20050044213A1 · Kobayashi · 2005 [cited by examiner]
US 20050166053A1 · Cui · 2005 [cited by examiner]
US 20050177750A1 · Gasparini · 2005 [cited by examiner]
US 20050235148A1 · Scheidt · 2005 [cited by examiner]
US 20060004772A1 · Hagan · 2006 [cited by examiner]
US 20060282660A1 · Varghese · 2006 [cited by examiner]
US 20060288213A1 · Gasparini · 2006 [cited by examiner]
US 20070198435A1 · Siegal · 2007 [cited by examiner]
US 20070203850A1 · Singh · 2007 [cited by examiner]
US 20070244904A1 · Durski · 2007 [cited by examiner]
US 20080028444A1 · Loesch · 2008 [cited by examiner]
US 20080028475A1 · Kalman · 2008 [cited by examiner]
US 20080072053A1 · Halim · 2008 [cited by examiner]
US 20080091618A1 · Obrea · 2008 [cited by examiner]
US 20080120711A1 · Dispensa · 2008 [cited by examiner]
US 20080196084A1 · Hawkes · 2008 [cited by examiner]
US 20080229109A1 · Gantman · 2008 [cited by examiner]
US 20090132813A1 · Schibuk · 2009 [cited by examiner]
US 20090259588A1 · Lindsay · 2009 [cited by examiner]
US 20100031022A1 · Kramer · 2010 [cited by examiner]
US 20100057843A1 · Landsman · 2010 [cited by examiner]
US 20100325040A1 · Etchegoyen · 2010 [cited by examiner]
US 20110154473A1 · Anderson · 2011 [cited by examiner]
US 20110179477A1 · Starnes · 2011 [cited by examiner]
US 20120159177A1 · Bajaj · 2012 [cited by examiner]
US 20120204032A1 · Wilkins · 2012 [cited by examiner]
US 20120210119A1 · Baxter · 2012 [cited by examiner]
US 20120215896A1 · Johannsen · 2012 [cited by examiner]
US 20120233665A1 · Ranganathan · 2012 [cited by examiner]
US 20120317622A1 · Harjanto · 2012 [cited by examiner]
US 20130061055A1 · Schibuk · 2013 [cited by examiner]
US 20130167196A1 · Spencer · 2013 [cited by examiner]
US 20130212654A1 · Dorfman · 2013 [cited by examiner]
US 20140304786A1 · Pei · 2014 [cited by examiner]
US 20150046192A1 · Raduchel · 2015 [cited by examiner]
US 20150089568A1 · Sprague · 2015 [cited by examiner]
US 20150237038A1 · Grajek · 2015 [cited by examiner]
US 20150244706A1 · Grajek · 2015 [cited by examiner]
US 20150294313A1 · Kamal · 2015 [cited by examiner]
US 20160105424A1 · Logue · 2016 [cited by examiner]
US 20160234729A1 · Achtari · 2016 [cited by examiner]
US 20170093821A1 · Camenisch · 2017 [cited by examiner]
US 20170118025A1 · Shastri · 2017 [cited by examiner]
US 20170163647A1 · Cernoch · 2017 [cited by examiner]
US 20170180347A1 · Koved · 2017 [cited by examiner]
US 20170187525A1 · Rosenquist · 2017 [cited by examiner]
US 20180124039A1 · Grajek · 2018 [cited by examiner]
US 20180255057A1 · Hein · 2018 [cited by examiner]
US 20190052466A1 · Bettger · 2019 [cited by examiner]
US 20190052467A1 · Bettger · 2019 [cited by examiner]
U.S. Appl. No. 15/652,889, filed Jul. 18, 2017. [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 15/679,776 dated Oct. 2, 2019. [cited by applicant]
Final Office Action for U.S. Appl. No. 15/679,776 dated Apr. 9, 2020. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 15/679,776 dated Aug. 10, 2020. [cited by applicant]
Search Query Report from IP.com (performed Apr. 5, 2020). [cited by applicant]
Search Query Report from IP.com (performed Jul. 29, 2020) (Year: 2020). [cited by applicant]