IP Library Granted Patent US 10,356,071
Granted Patent B2
US 10,356,071 · App. 15/126,226 · Granted Jul 16, 2019

Automatic log-in and log-out of a session with session sharing

Inventors: Gregory Whiteside (Montreal, CA); Richard Bruno (St Albans, VT); Richard Reiner (Mississauga, CA)
Assignee: McAfee, LLC
H04L63/08G06F21/335H04L63/0272H04L67/02H04L67/14H04L67/42H04L9/0863H04L9/3226H04L67/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,356,071
App. No.
15/126,226
Granted
Jul 16, 2019
Kind
B2
Abstract

A technique allows for transparently managing, suspending, restoring, sharing, limiting and migrating user sessions on a device without having access to user credentials. A user may automatically log in and out of each or all their online accounts instantaneously and, in doing so, the user may share sessions without sharing passwords across client devices as well as with other authenticated and authorized users. Sharing may be done in a secure manner with the initiating-user being able to restrict shared session rights, as well as being able to remove access to each of the shared sessions.

Claims (44)

1. A machine readable medium comprising instructions that when executed cause at least one machine to at least:

transmit user information to create a first active session on a web browser of a first device for a web page associated with a web domain, wherein the user information includes user credentials;

obtain shared session information from a second device, the shared session information encrypted using a public key to create, from the first active session, a locked shared session with the second device;

transmit logout information to terminate the locked shared session to create a terminated session, an indication of the terminated session to persist after termination;

transmit a request to retrieve the terminated session using the public key without the user credentials; and

obtain session information to inject the terminated session in the web browser to create a second active session.

2. The machine readable medium of claim 1 , wherein the instructions cause the at least one machine to:

store session data related to the locked shared session responsive to transmitting the logout information; and

delete session cookies related to the locked shared session from the web browser.

3. The machine readable medium of claim 1 , wherein the first device includes a mobile device.

4. The machine readable medium of claim 1 , wherein the instructions cause the at least one machine to transmit restrictions for the shared session to the second device.

5. The machine readable medium of claim 1 , wherein the instructions cause the at least one machine to prevent the user credentials from being transmitted after the request to retrieve the terminated session has been transmitted, wherein the user credentials includes at least one of a username and a password of a user.

6. The machine readable medium of claim 1 , wherein the instructions cause the at least one machine to transmit a request to the web domain to at least one of: (i) keep the locked shared session alive or (ii) modify the session information to keep the locked shared session alive, the request being a non-session modifying request.

7. The machine readable medium of claim 1 , wherein the instructions cause the at least one machine to determine if a previous session exists for the web page associated with the web domain.

8. The machine readable medium of claim 1 , wherein the instructions cause the at least one machine to terminate the locked shared session on the first device and retrieve the terminated session on the second device, the first and second devices being associated with a user.

9. A method for restoring and sharing a session, comprising:

transmitting user information to create a first active session on a web browser of a first device for a web page associated with a web domain, wherein the user information includes user credentials;

accessing shared session information from a second device, the shared session information encrypted using a public key to create, from the first active session, a locked shared session with the second device;

transmitting logout information to transform the locked shared session into a terminated session;

transmitting a request to retrieve the terminated session using the public key without the user credentials; and

accessing session information to inject the terminated session in the web browser to create a second active session.

10. The method of claim 9 , further including:

storing session data related to the locked shared session responsive to transmitting the logout information; and

deleting session cookies related to the locked shared session from the web browser.

11. The method of claim 9 , wherein the first device includes a mobile device.

12. The method of claim 9 , further including transmitting restrictions for the shared session to the second user.

13. The method of claim 9 , further including preventing the user credentials from being transmitted after transmitting the request to retrieve the terminated session, wherein the user credentials includes at least one of a username and a password of a user.

14. The method of claim 9 , further including transmitting a request to the web domain to keep the locked shared session alive, the request being a non-session modifying request.

15. The method of claim 9 , further including determining whether a previous session exists for the web page associated with the web domain.

16. The method of claim 9 , further including terminating the locked shared session on a first device and retrieving the terminated session on a second device, the first and second devices being associated with the user.

17. A first device comprising:

one or more processors; and

a memory including instructions that, when executed, cause the one or more of processors to:

access user information to create a first active session on a web browser of the first device for a web page associated with a web domain, wherein the user information includes user credentials;

access shared session information from a second device, the shared session information encrypted using a public key to create, from the first active session, a locked shared session with the second device;

transmit logout information to transform the locked shared session into a terminated session;

transmit a request to retrieve the terminated session using the public key without the user credentials; and

access session information to inject the terminated session in the web browser to create a second active session.

18. The first device of claim 17 , wherein the one or more processors are to:

store session data related to the locked shared session responsive to transmitting the logout information; and

delete session cookies related to the locked shared session from the web browser.

19. The first device of claim 17 , wherein the one or more processors are to transmit restrictions for the shared session related to the second device.

20. The first device of claim 17 , wherein the one or more processors are to prevent the user credentials from being transmitted responsive to transmitting the request to retrieve the terminated session, wherein the user credentials includes at least one of a username and a password of a user.

21. The first device of claim 17 , wherein the one or more processors are to transmit a request to the web domain to keep the locked shared session alive, the request being a non-session modifying request.

Assignments (12)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 6, 2019
From: REINER, RICHARD; WHITESIDE, GREGORY; BRUNO, RICHARD
To: PASSWORDBOX INC.
Reel/Frame 049397/0525 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 6, 2019
From: PASSWORDBOX, INC.
To: MCAFEE, INC.
Reel/Frame 049397/0600 →
CHANGE OF NAME Recorded Jun 6, 2019
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 049587/0459 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
Continuity (2)
Provisional Application 61979289 · Apr 14, 2014
Related Publication 20170093835A1 · Mar 30, 2017