IP Library Granted Patent US 12,598,191
Granted Patent B2
US 12,598,191 · App. 18/626,174 · Granted Apr 7, 2026

Secure content management through authentication

Inventors: Hyunsuk Han (San Ramon, CA); Mahesh Acharya (Castro Valley, CA)
Assignee: Lendingclub Bank, National Association
H04L63/105G06F16/9558H04L63/0876
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,598,191
App. No.
18/626,174
Granted
Apr 7, 2026
Kind
B2
Abstract

Techniques are described herein for performing authentication, and also “eager” or “lazy” fetch of data, for restricted webpages based on the restricted webpages being associated with an authentication tier in an AASD registry. Inclusion of a restricted webpage in the AASD registry enables AASD-based authentication for the webpage. According to embodiments, information for a restricted webpage included in the AASD registry includes one or more of the following for the webpage: an identifier, an authentication level, allowed fields, eager fetch fields, one or more sources for one or more fields, etc. When information for a webpage is included in the AASD registry, that information is used to perform eager fetch for one or more fields of the webpage that are not associated with authentication requirements indicated in the AASD registry information, or whose authentication requirements are already fulfilled by the requesting client.

Claims (57)

1 . A computer-executed method, comprising:

receiving a request associated with a client to access a first resource;

accessing registry information, wherein the registry information comprises, for each resource of a plurality of resources:

an identifier; and

a field-to-authentication-tier mapping that specifies an authentication tier associated with one or more data fields;

wherein the field-to-authentication-tier mapping comprises registry information that associates individual data fields with respective authentication tiers;

based at least in part on the registry information, identifying:

a first authentication tier associated with a first data field associated with the first resource; and

a second authentication tier associated with a second data field associated with the first resource;

in response to determining that the client is associated with the first authentication tier, eager-fetching the first data field by retrieving data for the first data field;

in response to determining that the client is not associated with the second authentication tier, lazy-fetching the second data field by providing a reference link for accessing the second data field;

wherein the method is performed by one or more computing devices comprising a hardware processor.

2 . The computer-executed method of claim 1 , wherein eager-fetching the first data field comprises retrieving the data associated with the first data field.

3 . The computer-executed method of claim 1 , wherein lazy-fetching the second data field comprises retrieving a reference link associated with the second data field.

4 . The computer-executed method of claim 1 , further comprising:

in response to determining that the client is not associated with the second authentication tier, causing an authentication request associated with the second authentication tier to be issued to the client.

5 . The computer-executed method of claim 4 , further comprising:

in response to determining that the client has satisfied the authentication requirements associated with the second authentication tier, retrieving the data associated with the second data field.

6 . The computer-executed method of claim 1 , wherein the registry information references a plurality of authentication tiers, wherein each authentication tier is associated with a set of authentication requirements.

7 . The computer-executed method of claim 1 , wherein the identifier associated with each resource is a URL.

8 . A system comprising:

at least one device including a hardware processor;

the system being configured to perform operations comprising:

accessing registry information, wherein the registry information comprises, for each resource of a plurality of resources:

an identifier; and

a field-to-authentication-tier mapping that specifies an authentication tier associated with one or more data fields;

wherein the field-to-authentication-tier mapping comprises registry information that associates individual data fields with respective authentication tiers;

based at least in part on the registry information, identifying:

a first authentication tier associated with a first data field associated with the first resource; and

a second authentication tier associated with a second data field associated with the first resource;

in response to determining that the client is associated with the first authentication tier, eager-fetching the first data field by retrieving data for the first data field;

in response to determining that the client is not associated with the second authentication tier, lazy-fetching the second data field by providing a reference link for accessing the second data field.

9 . The system of claim 8 , wherein eager-fetching the first data field comprises retrieving the data associated with the first data field.

10 . The system of claim 8 , wherein lazy-fetching the second data field comprises retrieving a reference link associated with the second data field.

11 . The system of claim 8 , further comprising:

in response to determining that the client is not associated with the second authentication tier, causing an authentication request associated with the second authentication tier to be issued to the client.

12 . The system of claim 11 , further comprising:

in response to determining that the client has satisfied the authentication requirements associated with the second authentication tier, retrieving the data associated with the second data field.

13 . The system of claim 11 , wherein the registry information references a plurality of authentication tiers, wherein each authentication tier is associated with a set of authentication requirements.

14 . The system of claim 11 , wherein the identifier associated with each resource is a URL.

15 . One or more non-transitory computer readable media comprising instructions which, when executed by one or more hardware processors, cause performance of operations comprising:

accessing registry information, wherein the registry information comprises, for each resource of a plurality of resources:

an identifier; and

a field-to-authentication-tier mapping that specifies an authentication tier associated with one or more data fields;

wherein the field-to-authentication-tier mapping comprises registry information that associates individual data fields with respective authentication tiers;

based at least in part on the registry information, identifying:

a first authentication tier associated with a first data field associated with the first resource; and

a second authentication tier associated with a second data field associated with the first resource;

in response to determining that the client is associated with the first authentication tier, eager-fetching the first data field by retrieving data for the first data field;

in response to determining that the client is not associated with the second authentication tier, lazy-fetching the second data field by providing a reference link for accessing the second data field.

16 . The non-transitory media of claim 15 , wherein eager-fetching the first data field comprises retrieving the data associated with the first data field.

17 . The non-transitory media of claim 15 , wherein lazy-fetching the second data field comprises retrieving a reference link associated with the second data field.

18 . The non-transitory media of claim 15 , further comprising:

in response to determining that the client is not associated with the second authentication tier, causing an authentication request associated with the second authentication tier to be issued to the client.

19 . The non-transitory media of claim 18 , further comprising:

in response to determining that the client has satisfied the authentication requirements associated with the second authentication tier, retrieving the data associated with the second data field.

20 . The non-transitory media of claim 15 , wherein the registry information references a plurality of authentication tiers, wherein each authentication tier is associated with a set of authentication requirements.

Continuity (4)
Continuation 17988508 · Nov 16, 2022
Continuation 17139793 · Dec 31, 2020
Provisional Application 63003207 · Mar 31, 2020
Related Publication 20240250954A1 · Jul 25, 2024
References Cited (53)
US 8006289B2 · Hinton et al. · 2011 [cited by applicant]
US 9300645B1 · Rao et al. · 2016 [cited by applicant]
US 9800614B2 · Hinton et al. · 2017 [cited by applicant]
US 10860703B1 · Manwiller · 2020 [cited by examiner]
US 11165581B2 · Hunt · 2021 [cited by applicant]
US 11288346B1 · Zubovsky · 2022 [cited by examiner]
US 11411944B2 · Abdul et al. · 2022 [cited by applicant]
US 11438764B2 · Avetisov et al. · 2022 [cited by applicant]
US 11843611B2 · Pattar · 2023 [cited by examiner]
US 20020087894A1 · Foley · 2002 [cited by examiner]
US 20060294370A1 · Greenspan · 2006 [cited by applicant]
US 20080134305A1 · Hinton et al. · 2008 [cited by applicant]
US 20080313728A1 · Pandrangi et al. · 2008 [cited by applicant]
US 20090106433A1 · Knouse et al. · 2009 [cited by applicant]
US 20090292927A1 · Wenzel · 2009 [cited by examiner]
US 20100107214A1 · Ganz · 2010 [cited by examiner]
US 20120023558A1 · Rafiq · 2012 [cited by applicant]
US 20130160144A1 · Mok · 2013 [cited by examiner]
US 20130298047A1 · Buehler et al. · 2013 [cited by applicant]
US 20140033327A1 · Conte · 2014 [cited by examiner]
US 20140109196A1 · Jagannatharao et al. · 2014 [cited by applicant]
US 20140366128A1 · Venkateswaran · 2014 [cited by examiner]
US 20150227725A1 · Grigg · 2015 [cited by examiner]
US 20150242605A1 · Du et al. · 2015 [cited by applicant]
US 20160119354A1 · Logue et al. · 2016 [cited by applicant]
US 20170118223A1 · Mathew · 2017 [cited by examiner]
US 20170374056A1 · Scavo et al. · 2017 [cited by applicant]
US 20180183789A1 · Tischart et al. · 2018 [cited by applicant]
US 20190230088A1 · Rice · 2019 [cited by examiner]
US 20190334921A1 · Pattar · 2019 [cited by examiner]
US 20200311135A1 · Kligman · 2020 [cited by examiner]
US 20200320218A1 · Buehler · 2020 [cited by examiner]
US 20210234850A1 · Vogt · 2021 [cited by examiner]
US 20210306334A1 · Han et al. · 2021 [cited by applicant]
US 20210306344A1 · Han et al. · 2021 [cited by applicant]
US 20210306346A1 · Han et al. · 2021 [cited by applicant]
US 20210350388A1 · Brannon · 2021 [cited by examiner]
US 20230038476A1 · Han et al. · 2023 [cited by applicant]
“Patent Electronic System Access Document”, dated Oct. 2018, 9 pages. [cited by applicant]
A Customizable Client Authentication Framework (CCAF) Based on Multi-Factor for Cloud Computing Application. Kaleem. IJCST. (Year: 2017). [cited by applicant]
Chan et al., “On Applying SIP Security to Networked Appliances”, Proceedings 2002 IEEE 4th International Workshop on Networked Appliances, Jan. 2002, 10 pages. [cited by applicant]
Coinbase.com, “Coinbase User Agreement”, https://www.coinbase.com/legal/user_agreement dated as early as Jan. 2020, 23 pages. [cited by applicant]
Han, U.S. Appl. No. 16/836,813, filed Mar. 31, 2020, Non-Final Rejection, dated Jan. 21, 2022. [cited by applicant]
Han, U.S. Appl. No. 16/836,813, filed Mar. 31, 2020, Notice of Allowance and Fees Due Jul. 14, 2022. [cited by applicant]
Han, U.S. Appl. No. 16/836,814, filed Mar. 31, 2020, Non-Final Rejection, dated Feb. 7, 2022. [cited by applicant]
Han, U.S. Appl. No. 16/836,814, filed Mar. 31, 2020, Notice of Allowance and Fees Due Jun. 2, 2022. [cited by applicant]
Han, U.S. Appl. No. 17/972,516, filed Oct. 24, 2022, Notice of Allowance and Fees Due, dated May 1, 2023. [cited by applicant]
Kaleem et al., “A Customizable Client Authentication Framework (CCAF) Based on Multi-Factor for Cloud Computing Application”, IJCST, vol. 8, Issue 3, May 2017, 8 pages. [cited by applicant]
Nordicapis.com, “GraphQL or Bust”, Nordic APIs, dated Jul. 11, 2018, 125 pages. [cited by applicant]
Shweta et al., “Three Tier Web Application and Internal Database Protection by Double Guard”, IJSTE, vol. 2, Issue 10, Apr. 2016, 11 pages. [cited by applicant]
Three Tier Web Application and Internal Database Protection by Double Guard. Gade. IJSTE. (Year: 2016). [cited by applicant]
United States Patent and Trademark Office, “Authentication Change for EFS-Web and PA”, https://www.uspto.gov/patent/authentication-changes-efs-web-and-pair, dated Nov. 20, 2018, 2 pages. [cited by applicant]
USPTO.Gov, “Patent Electronic System Access Document”, www.uspto.gov/sites/default/files/documents/Patent%20Electronic%20System%20Access%20Document, dated Oct. 2018, 9 pages. [cited by applicant]