IP Library › Granted Patent US 9,602,484
Granted Patent B2
US 9,602,484 · App. 14/262,667 · Granted Mar 21, 2017

Online user account login method and a server system implementing the method

Inventor: Xiaolong Zhang (Shenzhen, CN)
Assignee: TENCENT TECHNOLOGY (SHENZHEN) COMPANY LIMITED
H04L63/08H04L63/083H04L63/0853H04L63/18H04W12/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,602,484
App. No.
14/262,667
Granted
Mar 21, 2017
Kind
B2
Abstract

The present application provides a webpage login method involving two client devices and a server. The server receives an information access request from a first client device. In response to the information access request, the server returns a unique identifier to the first client device. The unique identifier is to be displayed on the first client device. Next, the server receives a first message from a second client device, the first message including user account information at the server system and authentication information. The server determines whether the authentication information corresponds to the unique identifier and authenticates the information access request in accordance with a determination that the authentication information corresponds to the unique identifier such that the user can access information at the server and associated with the user account information from the first client device.

Claims (66)

1. A method for authenticating a user's request to access information managed by a server system from a first client device, the method comprising:

at the server system, the server system having one or more processors and memory for storing programs to be executed by the one or more processors:

receiving a client-visit request from the first client device;

in response to the client-visit request, returning a client-visit verification identifier to the first client device;

receiving an information access request from the first client device, wherein information access request includes the client-visit verification identifier;

in response to the information access request, returning a unique identifier to the first client device, wherein the unique identifier is to be displayed on a display of the first client device, and the unique identifier includes first authentication information generated by the server system for the information access request based on the client-visit verification identifier;

receiving a first message from a second client device, wherein the first message includes user account information at the server system and second authentication information extracted by the second client device from scanning the unique identifier on the display of the first client device;

determining whether the second authentication information is the same as the first authentication information; and

authenticating the information access request in accordance with a determination that the second authentication information is the same as the first authentication information, such that a user can access information associated with the user account information at the server system from the first client device.

2. The method of claim 1 , further comprising:

before receiving the information access request from the first client device:

receiving a login request from the second client device, wherein the login request includes a username and a password; and

generating a login record at the server system in accordance with that the username and the password match a user account at the server system, the login record including identification information associated with the user account and identification information associated with the second client device.

3. The method of claim 2 , further comprising:

after receiving the first message from the second client device:

determining whether the first message includes the identification information associated with the second client device; and

denying the information access request if the first message does not include the identification information associated with the second client device.

4. The method of claim 1 , wherein the second authentication information in the first message is generated by the second client device through performing the following operations:

receiving a second message from the first client device, the second message including the unique identifier; and

extracting the unique identifier from the second message and including the unique identifier in the first message.

5. The method of claim 1 , further comprising:

after authenticating the information access request:

generating a webpage using the information associated with the user account information; and

returning the webpage to the first client device to be displayed on the display of the first client device.

6. The method of claim 1 , further comprising:

after authenticating the information access request:

generating an alert message, the alert message indicating the first client device's access to the information associated with the user account information; and

returning the alert message to the second client device to be displayed on a display of the second client device.

7. The method of claim 1 , wherein the server system includes at least a portion of the client-visit verification identifier in the unique identifier and the step of determining whether the second authentication information is the same as the first authentication information further includes determining whether the second authentication information includes the portion of the client-visit verification identifier.

8. The method of claim 1 , wherein the unique identifier is one selected from the group consisting of 1-D bar code, 2-D bar code, and 3-D bar code.

9. A server system, comprising:

one or more processors;

memory; and

one or programs stored in the memory for authenticating a user's request to access information managed by the server system from a first client device, wherein the one or more programs, when executed by the one or more processors, causes the server system to:

receive a client-visit request from the first client device;

in response to the client-visit request, return a client-visit verification identifier to the first client device;

receive an information access request from the first client device, wherein information access request includes the client-visit verification identifier;

in response to the information access request, return a unique identifier to the first client device, wherein the unique identifier is to be displayed on a display of the first client device, and the unique identifier includes first authentication information generated by the server system for the information access request based on the client-visit verification identifier;

receive a first message from a second client device, wherein the first message includes user account information at the server system and second authentication information extracted by the second client device from scanning the unique identifier on the display of the first client device;

determine whether the second authentication information is the same as the first authentication information; and

authenticate the information access request in accordance with a determination that the second authentication information is the same as the first authentication information, such that a user can access information associated with the user account information at the server system from the first client device.

10. The server system of claim 9 , wherein the second authentication information in the first message is generated by the second client device performing the following operations:

receiving a second message from the first client device, the second message including the unique identifier; and

extracting the unique identifier from the second message and including the unique identifier in the first message.

11. The server system of claim 9 , wherein the one or more programs further include instructions for:

after authenticating the information access request:

generating a webpage using the information associated with the user account information; and

returning the webpage to the first client device to be displayed on the display of the first client device.

12. The server system of claim 9 , wherein the one or more programs further include instructions for:

after authenticating the information access request:

generating an alert message, the alert message indicating the first client device's access to the information associated with the user account information; and

returning the alert message to the second client device to be displayed on a display of the second client device.

13. A method for accessing information managed by a server system from a first client device, the method comprising:

at the first client device having one or more processors and memory for storing programs to be executed by the one or more processors:

sending a client-visit request to the server system;

receiving a response from the server system, wherein the response includes a client-visit verification identifier generated by the server system for the client-visit request;

sending an information access request to the server system without providing any user account information, wherein information access request includes the client-visit verification identifier;

receiving a response from the server system, the response including a unique identifier provided by the server system in response to the information access request, and the unique identifier includes first authentication information generated by the server system for the information access request based on the client-visit verification identifier;

providing the unique identifier to a second client device, wherein the second client device is configured to send a first message to the server system, the first message including information of a user account at the server system and second authentication information extracted by the second client device from scanning the unique identifier on the display of the first client device; and

receiving information associated with the user account from the server system after server system authenticates the information access request in accordance with a determination that the second authentication information is the same as the first authentication information.

14. The method of claim 13 , wherein the server system includes a login record associated with the user account, the login record including identification information associated with the user account and identification information associated with the second client device.

15. The method of claim 13 , wherein the second authentication information is received by the second client device through performing the following operations:

receiving a second message from the first client device, the second message including the unique identifier; and

extracting the unique identifier from the second message and including the unique identifier in the first message.

16. The method of claim 13 , wherein, before the first client device receives the information associated with the user account, the server system is configured to send an alert message to the second client device, the alert message indicating the first client device's access to the information associated with the user account information, and return the information associated with the user account to the first client device after receiving a positive response from the second client device.

17. The method of claim 13 , wherein the unique identifier is one selected from the group consisting of 1-D bar code, 2-D bar code, and 3-D bar code.

Priority Claims (1)
CN 2012 1 0264146 · Jul 27, 2012 · national
Continuity (2)
Continuation 13900468 · May 22, 2013
Related Publication 20140237563A1 · Aug 21, 2014