IP Library › Granted Patent US 10,754,941
Granted Patent B2
US 10,754,941 · App. 14/951,167 · Granted Aug 25, 2020

User device security manager

Inventor: Rajeev Angal (San Jose, CA)
Assignee: eBay Inc.
G06F21/44H04L63/10H04L63/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,754,941
App. No.
14/951,167
Filed
Nov 24, 2015
Granted
Aug 25, 2020
Kind
B2
Art Unit
2492
USPC
726/5
Abstract

Techniques for authentication and authorization of a user, an application, or a user device for access to web resources are described. For example, a machine identifies an access request to access a remote resource associated with a web service. The access request may be received from an application executing at a user device. The machine retrieves at least one user artifact from a security manager identifier received from the web service. The machine performs fingerprinting of the user device based on the at least one user artifact. The machine transmits the access request to the web service based on the performing of the fingerprinting of the user device. The machine, in response to the transmitting of the access request to the web service, receives a resource access authorization from the web service for the application executing at the user device.

Claims (48)

1. A system comprising:

one or more hardware processors; and

a non-transitory machine-readable medium for storing instructions that, when executed by the one or more hardware processors, cause the one or more hardware processors to perform operations comprising:

identifying an access request for an application to access a remote resource associated with a web service;

automatically retrieving at least one user artifact from a security manager identifier (SMID), the SMID including a quick response (QR) code that represents one or more artifacts previously provided by a user;

automatically performing fingerprinting of the user device based on matching the at least one user artifact and a stored artifact;

transmitting the access request based on the performing of the fingerprinting of the user device; and

in response to the transmitting of the access request, receiving a resource access authorization for the application.

2. The system of claim 1 , wherein the at least one user artifact comprises at least one of an image, color, or phrase selected by the user; and wherein the at least one user artifact is previously registered at the web service in relation with the user.

3. The system of claim 1 , wherein the QR code is generated during a registration process associated with a user device security manager.

4. The system of claim 1 , wherein the operations further comprise:

receiving the SMID using at least one of QR code submission, redirection, push notification, manual entry, or an email communication.

5. The system of claim 1 , wherein the operations further comprise:

transmitting the SMID to verify the user device in response to the identifying of the access request.

6. The system of claim 1 , wherein the operations further comprise:

signaling a display associated with the user device to present at least one portion of the at least one user artifact based on receiving an indication that the user device is verified by the web service.

7. The system of claim 1 , wherein the at least one user artifact is to be eliminated from the web service after the user device has been verified by the web service.

8. The system of claim 1 , wherein the operations further comprise:

preventing the user device from prompting the user with one or more user authentication pages based on identifying a valid user token associated with the user from the SMID.

9. A method comprising:

identifying an access request for an application to access a remote resource associated with a web service;

automatically retrieving at least one user artifact from a security manager identifier (SMID), the SMID including a quick response (QR) code that represents one or more artifacts previously provided by a user;

automatically performing fingerprinting of the user device based on matching the at east one user artifact and a stored artifact;

transmitting the access request based on the performing of the fingerprinting of the user device; and

in response to the transmitting of the access request, receiving a resource access authorization for the application.

10. The method of claim 9 , wherein the at least one user artifact comprises at least one of an image, color, or phrase selected by the user, and wherein the at least one user artifact is previously registered at the web service in relation with the user.

11. The method of claim 9 , wherein the QR code, is generated during a registration process associated with a user device security manager.

12. The method of claim 9 , further comprising:

receiving the SMID using at least one of QR code submission, redirection, push notification, manual entry or an email communication.

13. The method of claim 9 , further comprising:

transmitting the SMID to verify the user device in response to the identifying of the access request.

14. The method of claim 9 , further comprising:

signaling a display associated with the user device to present at least one portion of the at least one user artifact based on receiving an indication that the user device is verified by the web service.

15. The method of claim 9 , wherein the at least one user artifact is to be eliminated from the web service after the user device has been verified by the web service.

16. The method of claim 9 , further comprising:

preventing the user device from prompting the user with one or more user authentication pages based on identifying a valid user token associated with the user from the SMID.

17. A non-transitory machine-readable storage medium storing instructions that, when executed by one or more hardware processors, cause the one or more hardware processors to perform operations comprising:

identifying an access request for an application to access a remote resource associated with a web service;

automatically retrieving at least one user artifact from a security manager identifier (SMID), the SMID including a quick response (QR) code that represents one or more artifacts previously provided by a user;

automatically performing fingerprinting of the user device based on matching the at least one user artifact and a stored artifact;

transmitting the access request based on the performing of the fingerprinting of the user device; and

in response to the transmitting of the access request, receiving a resource access authorization for the application.

18. The non-transitory machine-readable storage medium of claim 17 , wherein the operations further comprise:

receiving the SMID using at least one of QR code submission, redirection, push notification, manual entry or an email communication.

19. The non-transitory machine-readable storage medium of claim 17 , wherein the operations further comprise:

transmitting the SMID to verify the user device in response to the identifying of the access request.

20. The non-transitory machine-readable storage medium of claim 17 , wherein the operations further comprise:

signaling a display associated with the user device to present at least one portion of the at least one user artifact based on receiving an indication that the user device is verified by the web service.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 24, 2015
From: ANGAL, RAJEEV
To: EBAY INC.
Reel/Frame 037135/0934 →
Continuity (3)
Continuation 13709705 · Dec 10, 2012
Provisional Application 61671985 · Jul 16, 2012
Related Publication 20160078214A1 · Mar 17, 2016
Cited By (2)
US 12,218,938 US 12,231,430