IP Library Granted Patent US 12,506,739
Granted Patent B2
US 12,506,739 · App. 18/610,098 · Granted Dec 23, 2025

Unified identity verification

Inventors: Rene M. Pelegero (Woodinville, WA); Girish Balasubramanian (Fremont, CA); Rohan Mahadevan (Menlo Park, CA)
Assignee: PayPal, Inc.
H04L63/102G06F21/31G06Q20/10G06Q20/385G06Q20/40H04L63/083H04L67/306
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,506,739
App. No.
18/610,098
Granted
Dec 23, 2025
Kind
B2
Abstract

Apparatus, systems, and methods are disclosed that operate to receiving an authentication request at a server associated with an authenticating entity from a requesting party responsive to a request being provided to the requesting party by a client terminal associated with an unauthenticated individual purporting to be an individual account owner previously authenticated with the authenticating entity. A token from the client terminal associated with the unauthenticated individual is received, and the token includes information associated with the unauthenticated individual and a user permission authorizing the authenticating entity to share a selected portion of the information with a plurality of selected requesting parties. The server associated with the authenticating entity authenticates the unauthenticated individual as the individual account owner based on, inter alia, matching the token to a pre-registered identity uniquely associated with the individual account owner. Additional apparatus, systems, and methods are disclosed.

Claims (32)

1 . A token-based authentication method, the method comprising:

receiving, by a server from a requesting computing system, a request for processing a certain transaction initiated by a user at a client device, the transaction between the user and the requesting computer system, the request comprising an encrypted authentication token, the request indicating that the requesting computing system received the authentication token from the client device, the encrypted authentication token associated with the user;

decrypting the encrypted authentication token;

verifying that the decrypted authentication token matches an expected token value for the user; and

responsive to the verifying of the decrypted authentication token, sending, by the server to the requesting computing system, certain user information authorized to be shared with one or more entities including the requesting computing system, the sending of the certain user information causing the requesting computing system to initiate processing of the transaction based on the certain user information, without communication of the certain user information between the client device and the requesting computing system.

2 . The method of claim 1 , wherein the authentication token indicates that the user of the client device is authenticated to initiate the transaction with the requesting computing system; and wherein the authentication token is provided to the client device prior to receiving the request from the requesting computing system.

3 . The method of claim 1 , wherein the sending of the certain user information causing the requesting computing system to initiate processing of the transaction comprises further causing the requesting computing system to perform the authentication of the user independent of communication of security credentials of the user between the computing system and the client device.

4 . The method of claim 1 , wherein the authentication token is associated with a time interval over which the authentication token is valid; and wherein the verifying of the authentication token comprises determining that the request was received during the time interval.

5 . The method of claim 1 , wherein the authentication token is associated with a number of uses for the authentication token for initiating transactions; wherein the verifying of the authentication token comprises determining that the authentication token has not been used more than the number of uses to initiate transactions.

6 . The method of claim 1 , wherein the server is configured to transfer funds, associated with the transaction, from a user account of the user in response to the authentication of the client device.

7 . The method of claim 1 , further comprising:

verifying information in the request to determine that the requesting computing system is authorized to receive the authentication token.

8 . The method of claim 1 , further comprising: updating, by the computing system based on communication with the client device, user information to specify additional information that the computing system is authorized to share.

9 . A server configured to perform token-based authentication, the server comprising:

a non-transitory memory storing instructions; and

a processor configured to execute the instructions to cause the server to:

receive, from a requesting computing system, a request for processing a certain transaction initiated by a user of a client device, the transaction between the user and the requesting computing system, the request comprising an encrypted authentication token associated with the user, the request indicating that the requesting computing system received the authentication token from the client device;

decrypting the encrypted authentication token;

determine, based at least on a verification that the decrypted authentication token matches an expected token value for the user, that the user is authenticated to initiate transactions with a user account of the user; and

in response to the determination that the user of the client device is authenticated to initiate transactions, communicate to the requesting computing system certain user information authorized to be shared with one or more entities including the requesting computing system, the communicating of the certain user information causing the requesting computing system initiate the transaction with the server, independent of communication of any user information between the client device and the requesting computing system.

10 . The server of claim 9 , wherein the authentication token is provided to the client device prior to receiving the request from the requesting computing system.

11 . The server of claim 9 , wherein the communicating of the certain user information causing the requesting computing system to initiate the transaction comprises further causing the requesting computing system to perform the authentication of the user independent of communication of security credentials of the user account between the computing system and the client device.

12 . The server of claim 9 , wherein the authentication token is associated with a time interval over which the authentication token is valid; and wherein the verification of the authentication token comprises determining that the request was received during the time interval.

13 . The server of claim 9 , wherein executing the instructions further causes the server to update, based on at least on communication with the client device, user information to specify additional information that the server is authorized to share.

14 . A non-transitory machine-readable medium having instructions stored thereon, the instructions executable to cause performance of operations comprising:

accessing a request for initiating a transaction from a user at a client device, the request comprising an encrypted authentication token, the request indicating that a requesting computing system received the authentication token from the client device;

decrypting the encrypted authentication token;

determining, based at least on a verification that the decrypted authentication token matches an expected token value for the user, that the user is authenticated for initiating transaction involving a user account of a user; and

in response to the determination that the user of the client device is authenticated to initiate transactions, communicating to the requesting computing system certain user information authorized to be shared with one or more entities including the requesting computing system, the communicating of the certain user information causing the requesting computing system to initiate the transaction, without the requesting computing system receiving the certain user information.

15 . The non-transitory machine-readable medium of claim 14 , wherein the authentication token is provided to the client device prior to receiving the request from the requesting computing system.

16 . The non-transitory machine-readable medium of claim 14 , wherein the communicating of the certain user permission information causing the requesting computing system to initiate the transaction comprises further causing the requesting computing system to perform the authentication of the user independent of communication of security credentials of the user account between the computing system and the client device.

17 . The non-transitory machine-readable medium of claim 14 , wherein the authentication token is associated with a time interval over which the authentication token is valid; and wherein the verification of the authentication token comprises determining that the request was received during the time interval.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2024
From: PELEGERO, RENE M.; BALASUBRAMANIAN, GIRISH; MAHADEVAN, ROHAN
To: EBAY INC.
Reel/Frame 067555/0232 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2024
From: EBAY INC.
To: PAYPAL, INC.
Reel/Frame 067555/0286 →
Continuity (8)
Continuation 17827901 · May 30, 2022
Continuation 16877140 · May 18, 2020
Continuation 14941810 · Nov 16, 2015
Continuation 13910872 · Jun 5, 2013
Continuation 13453492 · Apr 23, 2012
Continuation 11962757 · Dec 21, 2007
Provisional Application 60981408 · Oct 19, 2007
Related Publication 20240380756A1 · Nov 14, 2024
References Cited (104)
US 5661803A · Cordery et al. · 1997 [cited by applicant]
US 5812666A · Baker et al. · 1998 [cited by applicant]
US 5943423A · Muftic · 1999 [cited by applicant]
US 6385596B1 · Wiser et al. · 2002 [cited by applicant]
US 6659259B2 · Knox et al. · 2003 [cited by applicant]
US 6868403B1 · Wiser et al. · 2005 [cited by applicant]
US 6970853B2 · Schutzer · 2005 [cited by applicant]
US 7017188B1 · Schmeidler et al. · 2006 [cited by applicant]
US 7369999B2 · Dubois et al. · 2008 [cited by applicant]
US 8214291B2 · Pelegero et al. · 2012 [cited by applicant]
US 8498940B2 · Pelegero et al. · 2013 [cited by applicant]
US 8838503B2 · Pelegero · 2014 [cited by applicant]
US 20030061170A1 · Uzo · 2003 [cited by applicant]
US 20030061203A1 · Hayduk · 2003 [cited by applicant]
US 20030187787A1 · Freund · 2003 [cited by applicant]
US 20040139028A1 · Fishman et al. · 2004 [cited by applicant]
US 20050065881A1 · Li et al. · 2005 [cited by applicant]
US 20050119978A1 · Ates · 2005 [cited by applicant]
US 20050131752A1 · Gracie et al. · 2005 [cited by applicant]
US 20060015463A1 · Gupta et al. · 2006 [cited by applicant]
US 20060020542A1 · Litle et al. · 2006 [cited by applicant]
US 20060074765A1 · Crawford et al. · 2006 [cited by applicant]
US 20060204051A1 · Holland, IV · 2006 [cited by applicant]
US 20070215689A1 · Algiene · 2007 [cited by applicant]
US 20080072293A1 · D'Urso · 2008 [cited by applicant]
US 20080162295A1 · Bedier · 2008 [cited by applicant]
US 20080189214A1 · Mueller et al. · 2008 [cited by applicant]
US 20080228653A1 · Holdsworth · 2008 [cited by applicant]
US 20090048953A1 · Hazel et al. · 2009 [cited by applicant]
US 20090106150A1 · Pelegero et al. · 2009 [cited by applicant]
US 20100145860A1 · Pelegero · 2010 [cited by applicant]
US 20120209733A1 · Pelegero et al. · 2012 [cited by applicant]
US 20130269004A1 · Pelegero et al. · 2013 [cited by applicant]
US 20140365373A1 · Pelegero · 2014 [cited by applicant]
WO 2010078522A1 · 2010 [cited by applicant]
U.S. Appl. No. 12/347,907, Notice of Allowance mailed May 15, 2014, 11 pages. [cited by applicant]
U.S. Appl. No. 12/347,907, Response filed Apr. 28, 2014 to Non-Final Office Action mailed Feb. 7, 2014, 7 pages. [cited by applicant]
U.S. Appl. No. 12/347,907, Response filed Dec. 13, 2010 to Non-Final Office Action mailed Jul. 13, 2010, 10 pages. [cited by applicant]
U.S. Appl. No. 12/347,907, Response filed Jan. 28, 2010 to Non-Final Office Action mailed Oct. 28, 2009, 13 pages. [cited by applicant]
U.S. Appl. No. 12/347,907, Response Filed Mar. 31, 2011 to Final Office Action Received Jan. 26, 2011, 10 pages. [cited by applicant]
U.S. Appl. No. 13/453,492, Notice of Allowance mailed Mar. 27, 2013, 9 pages. [cited by applicant]
U.S. Appl. No. 13/453,492, Response filed Mar. 12, 2013 to Restriction Requirement mailed Mar. 7, 2013, 6 pages. [cited by applicant]
U.S. Appl. No. 13/453,492, Restriction Requirement mailed Mar. 7, 2013, 6 pages. [cited by applicant]
U.S. Appl. No. 13/910,872, Advisory Action mailed Sep. 24, 2015, 3 pages. [cited by applicant]
U.S. Appl. No. 13/910,872, Final Office Action mailed Jul. 16, 2015, 9 pages. [cited by applicant]
U.S. Appl. No. 13/910,872, Non-Final Office Action mailed Mar. 2, 2015, 5 pages. [cited by applicant]
U.S. Appl. No. 13/910,872, Preliminary Amendment filed Aug. 15, 2013, 9 pages. [cited by applicant]
U.S. Appl. No. 13/910,872, Response filed Jan. 14, 2015 to Restriction Requirement mailed Nov. 14, 2014, 5 pages. [cited by applicant]
U.S. Appl. No. 13/910,872, Response filed Jul. 2, 2015 to Non-Final Office Action mailed Mar. 2, 2015, 24 pages. [cited by applicant]
U.S. Appl. No. 13/910,872, Response filed Sep. 15, 2015 to Final Office Action mailed Jul. 16, 2015, 18 pages. [cited by applicant]
U.S. Appl. No. 13/910,872, Restriction Requirement mailed Nov. 14, 2014, 6 pages. [cited by applicant]
U.S. Appl. No. 14/465,732, Preliminary Amendment filed Sep. 18, 2014, 6 pages. [cited by applicant]
Wikipedia., “Security Assertion Markup Language,” Retrieved from Internet URL: https://en.wikipedia.org/wiki/Security_Assertion_Markup_Language, Oct. 20, 2008, 8 pages. [cited by applicant]
Wikipedia., “Security Engineering,” Retrieved from Internet URL: https://en.wikipedia.org/w/index.phptitle=Security_engineering&oldid=1017168910, last edited on Apr. 11, 2021, 5 pages. [cited by applicant]
Australian Appl. No. 2009334494, Examiner Report mailed Jun. 19, 2012, 3 pages. [cited by applicant]
Australian Appl. No. 2009334494, Notice of Acceptance mailed Jan. 9, 2013, 2 pages. [cited by applicant]
Australian Appl. No. 2009334494, Response filed Dec. 18, 2012 to Examiner Report mailed Jun. 19, 2012, 18 pages. [cited by applicant]
Australian Appl. No. 2013205575, Response filed Jul. 16, 2015 to Subsequent Examiners Report mailed Jan. 12, 2015, 15 pages. [cited by applicant]
Australian Appl. No. 2013205575, Response filed Oct. 19, 2015, 17 pages. [cited by applicant]
Australian Appl. No. 2013205575, Subsequent Examiners Report mailed Aug. 11, 2015, 3 pages. [cited by applicant]
Australian Appl. No. 2013205575, Subsequent Examiners Report mailed Jan. 12, 2015, 4 pages. [cited by applicant]
Australian Appl. No. 2013205575, Voluntary Amendment filed May 30, 2013, 9 pages. [cited by applicant]
Canadain Appl. No. 2,747,831, Office Action mailed Nov. 10, 2015, 4 pages. [cited by applicant]
Canadian Appl. No. 2,747,831, Office Action mailed Dec. 16, 2014, 3 pages. [cited by applicant]
Canadian Appl. No. 2,747,831, Office Action mailed Nov. 15, 2013, 2 pages. [cited by applicant]
Canadian Appl. No. 2,747,831, Response filed Jun. 16, 2015 to Office Action mailed Dec. 16, 2014, 10 pages. [cited by applicant]
Canadian Appl. No. 2,747,831, Response filed May 1, 2014 to Office Action mailed Nov. 15, 2013, 5 pages. [cited by applicant]
Digitaltransactions., “Why NYCE Plans To Test Two Online PIN Debit Systems in Parallel,” Retrieved from Internet URL: http://www.digitaltransactions.net/newsstory.cfm?newsid=1995, Retrieved on Dec. 8, 2008, 3 pages. [cited by applicant]
European Appl. No. 09837215.4, Extended European Search Report mailed May 2, 2012, 6 pages. [cited by applicant]
European Appl. No. 09837215.4, Office Action mailed Jun. 16, 2011, 2 pages. [cited by applicant]
European Appl. No. 09837215.4, Office Action mailed May 6, 2013, 5 pages. [cited by applicant]
European Appl. No. 09837215.4, Office Action mailed Sep. 25, 2015, 39 pages. [cited by applicant]
European Appl. No. 09837215.4, Response filed Aug. 27, 2013, 14 pages. [cited by applicant]
European Appl. No. 09837215.4, Response filed Nov. 15, 2012 to Extended Search Report mailed May 2, 2012, 17 pages. [cited by applicant]
European Appl. No. 09837215.4, Response filed Nov. 25, 2014, 10 pages. [cited by applicant]
European Appl. No. 09837215.4, Response filed Sep. 19, 2011 to Office Action mailed Jun. 16, 2011, 11 pages. [cited by applicant]
European Appl. No. 09837215.4, Summons to Attend Oral Proceedings mailed Jul. 16, 2014, 7 pages. [cited by applicant]
International Appl. No. PCT/US2009/069963, International Preliminary Report on Patentability mailed Jul. 14, 2011, 6 pages. [cited by applicant]
International Appl. No. PCT/US2009/069963, International Search Report mailed Mar. 4, 2010, 4 pages. [cited by applicant]
International Appl. No. PCT/US2009/069963, Written Opinion mailed Mar. 4, 2010, 4 pages. [cited by applicant]
Onlineresources., “CARD HQ, Online Resources,” Retrieved from Internet URL: http://www.orcc.com/products/ebanking/banking/cardhq.asp, Retrieved on Sep. 30, 2008, 2 pages. [cited by applicant]
O'Reilly., “Chapter 1: What Is Security Engineering,” Retrieved from Internet URL: https://www.oreilly.com/library/view/security-engineering-a/9780470068526/ch01.html, Apr. 14, 2008, 14 pages. [cited by applicant]
U.S. Appl. No. 11/962,757, 312 Amendment filed Apr. 11, 2012, 11 pages. [cited by applicant]
U.S. Appl. No. 11/962,757, Advisory Action mailed Jun. 4, 2010, 3 pages. [cited by applicant]
U.S. Appl. No. 11/962,757, Examiner Interview Summary mailed Aug. 17, 2010, 3 pages. [cited by applicant]
U.S. Appl. No. 11/962,757, Examiner Interview Summary mailed Jan. 12, 2012, 1 pg. [cited by applicant]
U.S. Appl. No. 11/962,757, Final Office Action mailed Mar. 25, 2010, 15 pages. [cited by applicant]
U.S. Appl. No. 11/962,757, Final Office Action mailed Nov. 30, 2011, 5 pages. [cited by applicant]
U.S. Appl. No. 11/962,757, Issue Notification mailed Jun. 15, 2012, 1 pg. [cited by applicant]
U.S. Appl. No. 11/962,757, Non-Final Office Action mailed Sep. 2, 2009, 16 pages. [cited by applicant]
U.S. Appl. No. 11/962,757, Non-Final Office Action mailed Sep. 6, 2011, 17 pages. [cited by applicant]
U.S. Appl. No. 11/962,757, Notice of Allowance mailed Jan. 12, 2012, 8 pages. [cited by applicant]
U.S. Appl. No. 11/962,757, Response filed Dec. 2, 2009 to Non-Final Office Action mailed Sep. 2, 2009, 11 pages. [cited by applicant]
U.S. Appl. No. 11/962,757, Response filed Dec. 21, 2011 to Final Office Action mailed Nov. 30, 2011, 13 pages. [cited by applicant]
U.S. Appl. No. 11/962,757, Response filed Jun. 25, 2010 to Advisory Action mailed Jun. 4, 2010, 7 pages. [cited by applicant]
U.S. Appl. No. 11/962,757, Response filed May 25, 2010 to Final Office Action mailed Mar. 25, 2010, 10 pages. [cited by applicant]
U.S. Appl. No. 11/962,757, Response filed Nov. 4, 2011 to Non-Final Office Action mailed Sep. 6, 2011, 17 pages. [cited by applicant]
U.S. Appl. No. 11/962,757, Response to Rule 312 Amendment mailed May 4, 2012, 2 pages. [cited by applicant]
U.S. Appl. No. 11/962,757, Response to Rule 312 Communication mailed Apr. 19, 2012, 2 pages. [cited by applicant]
U.S. Appl. No. 12/347,907, Examiner Interview Summary mailed May 1, 2014, 3 pages. [cited by applicant]
U.S. Appl. No. 12/347,907, Final Office Action mailed Jan. 26, 2011, 10 pages. [cited by applicant]
U.S. Appl. No. 12/347,907, Non-Final Office Action mailed Feb. 7, 2014, 12 pages. [cited by applicant]
U.S. Appl. No. 12/347,907, Non-Final Office Action mailed Jul. 13, 2010, 10 pages. [cited by applicant]
U.S. Appl. No. 12/347,907, Non-Final Office Action mailed Oct. 28, 2009, 10 pages. [cited by applicant]