IP Library Granted Patent US 12,621,285
Granted Patent B2
US 12,621,285 · App. 18/645,063 · Granted May 5, 2026

Systems and methods for using partial cookies for electronic authentication and authorization

Inventors: Jiwon Kim (South San Francisco, CA); Jose Carlos Matias (South San Francisco, CA); Ernesto Carvajal Lastres (South San Francisco, CA); Suhas Hoskote Muralidhar (South San Francisco, CA)
Assignee: STRIPE, LLC
H04L63/0815H04L63/102H04L63/108
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,621,285
App. No.
18/645,063
Granted
May 5, 2026
Kind
B2
Abstract

The methods and systems disclosed herein allow for faster and more efficient authentication using a partial cookie instead of a full cookie (or other data structure). In one example, a server receives, during the first browser session at the first time, a first request for authorization from an electronic device along with authentication information. Responsive to generating a profile using the authentication information, the server transmits to the electronic device a first data source configured to grant access to the profile to the electronic device, via a first authentication protocol; and receives, at a second browser session at a second time, from the electronic device, a second request for authorization to access the profile; responsive to a determination that the electronic device includes the first data source, the server executes a secondary authentication protocol.

Claims (44)

1 . A system, comprising:

one or more processors coupled to non-transitory memory, the one or more processors configured to:

receive, during a first browser session at a first time, a first request for authorization from an electronic device;

receive authentication information associated with an end-user of the electronic device;

responsive to generating a profile for the end-user using the authentication information, during the first browser session and prior to receiving the authentication information again, transmit, to the electronic device, a first data source configured to grant a first level of access to the profile via a first authentication protocol, wherein the first level of access grants partial access to the profile;

receive, at a second browser session at a second time, from the electronic device, a second request for authorization to access the profile;

identify a first attribute associated with the second request;

responsive to a determination that the electronic device includes the first data source, transmit a first notification to an authorized device associated with the profile;

upon receiving a response to the first notification that the electronic device has been successfully authenticated, transmit, to the electronic device, a second data source configured to grant a second level of access to the profile via a second authentication protocol having fewer authentication prompts than the first authentication protocol, wherein the second level of access grants full access to the profile;

receive, at a third browser session at a third time, from the electronic device, a third request for authorization to access the profile;

identify a second attribute associated with the third request;

when the first attribute does not match the second attribute, transmit a second notification to the electronic device indicating suspicious activity associated with the profile; and

upon determining that the electronic device includes the second data source and receiving a response to the second notification, grant full access to the profile via the second authentication protocol.

2 . The system of claim 1 , wherein the one or more processors are further configured to:

generate the profile to store the authentication information associated with the end-user of the electronic device; and

generate the first data source to grant partial access to the profile during the first browser session via the first authentication protocol.

3 . The system of claim 1 , wherein the first data source or the second data source is configured to grant partial or full access to the profile for a defined period of time.

4 . The system of claim 1 , wherein the one or more processors are further configured to embed a code within the first notification, the code including a plurality of alphanumeric values.

5 . The system of claim 1 , wherein the authentication information comprises at least one of an electronic mail address, credit card information, debit card information, a cardholder name, a phone number, or a region.

6 . The system of claim 1 , wherein the one or more processors are further configured to:

when the first attribute does not match the second attribute, revoke the second data source.

7 . The system of claim 1 , wherein the first attribute or the second attribute is one of at least a geographical location, an internet protocol address of the electronic device, or an operating system of the electronic device.

8 . The system of claim 1 , wherein the one or more processors are further configured to determine that the electronic device includes the first data source by retrieving the first data source from memory of the electronic device.

9 . A method, comprising:

receiving, by one or more processors during a first browser session at a first time, a first request for authorization from an electronic device;

receiving, by the one or more processors, authentication information associated with an end-user of the electronic device;

responsive to generating a profile for the end-user using the authentication information, during the first browser session and prior to receiving the authentication information again, transmitting, by the one or more processors, to the electronic device a first data source configured to grant a first level of access to the profile via a first authentication protocol, wherein the first level of access grants partial access to the profile;

receiving, by the one or more processors, at a second browser session at a second time, from the electronic device, a second request for authorization to access the profile;

identifying, by the one or more processors, a first attribute associated with the second request;

responsive to a determination that the electronic device includes the first data source, transmitting, by the one or more processors, a first notification to an authorized device associated with the profile;

upon receiving a response to the first notification that the electronic device has been successfully authenticated, transmitting, by the one or more processors, to the electronic device a second data source configured to grant a second level of access to the profile via a second authentication protocol having fewer authentication prompts than the first authentication protocol, wherein the second level of access grants full access to the profile;

receiving, by the one or more processors at a third browser session at a third time, from the electronic device, a third request for authorization to access the profile;

identifying, by the one or more processors, a second attribute associated with the third request; when the first attribute does not match the second attribute, transmitting, by the one or more processors, a second notification to the electronic device indicating suspicious activity associated with the profile; and

upon determining that the electronic device includes the second data source and receiving a response to the second notification, granting, by the one or more processors, full access to the profile via the second authentication protocol.

10 . The method of claim 9 , further comprising:

generating, by the one or more processors, the profile to store the authentication information associated with the end-user of the electronic device; and

generating, by the one or more processors, the first data source to grant partial access to the profile during the first browser session, via the first authentication protocol.

11 . The method of claim 9 , wherein the first data source or the second data source is configured to grant partial or full access to the profile for a defined period of time.

12 . The method of claim 9 , wherein transmitting the first notification to the authorized device further comprises embedding, by the one or more processors, a code within the first notification, the code including a plurality of alphanumeric values.

13 . The method of claim 9 , wherein the authentication information comprises at least one of an electronic mail address, credit card information, debit card information, a cardholder name, a phone number, and a region.

14 . The method of claim 9 , further comprising:

when the first attribute does not match the second attribute, revoking, by the one or more processors, the second data source.

15 . The method of claim 9 , wherein the first attribute or the second attribute is one of at least a geographical location, internet protocol address of the electronic device, or an operating system of the electronic device.

16 . The method of claim 9 , further comprising determining, by the one or more processors, that the electronic device includes the first data source.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 6, 2026
From: KIM, JIWON; MATIAS, JOSE CARLOS; LASTRES, ERNESTO CARVAJAL; MURALIDHAR, SUHAS HOSKOTE
To: STRIPE, INC.
Reel/Frame 074283/0251 →
CHANGE OF NAME Recorded Jan 7, 2026
From: STRIPE, INC.
To: STRIPE, LLC
Reel/Frame 074264/0807 →
Continuity (1)
Related Publication 20250337724A1 · Oct 30, 2025
References Cited (9)
US 9208298B2 · McCoy · 2015 [cited by examiner]
US 12231417B2 · Thubert · 2025 [cited by examiner]
US 20040080529A1 · Wojcik · 2004 [cited by examiner]
US 20220114245A1 · Krishan · 2022 [cited by examiner]
US 20240283657A1 · Jose · 2024 [cited by examiner]
US 20240348695A1 · Kannembath · 2024 [cited by examiner]
US 20250080570A1 · Ramsue · 2025 [cited by examiner]
Victoria Beltran, “Characterization of Web Single Sign-on protocols,” 2016, pp. 24-30 (Year: 2013). [cited by examiner]
Feng Yang, “A Security analysis of the OAuth protocol,” 2013, pp. 1-6. (Year: 2013). [cited by examiner]