IP Library Granted Patent US 11,228,579
Granted Patent B2
US 11,228,579 · App. 16/487,783 · Granted Jan 18, 2022

Passing authentication information via parameters

Inventors: Justin Lewis (Marina Del Rey, CA); Abhiram Kasina (San Bruno, CA)
Assignee: GOOGLE LLC
H04L63/0815H04L63/062H04L63/083H04L67/125H04L67/2842H04L67/42H04W12/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,228,579
App. No.
16/487,783
Granted
Jan 18, 2022
Kind
B2
Abstract

Systems and methods for passing account authentication information via parameters. A server can provide, to a client device, an account parameter derived from an account credential used to authenticate a first application to insert into a link. The link can include an address referencing a second application. The account parameter can be passed from the first application to the second application responsive to an interaction on the link. The server can receive from the second application of the client device, subsequent to passing the account parameter from the first application to the second application, a request to authenticate the second application including the account parameter. The server can authenticate the client device for the second application using the account parameter. The server can transmit, responsive to authenticating the client device for the second application, an authentication indication to the second application of the client device.

Claims (41)

1. A method of passing account authentication information via parameters, comprising:

providing, by an authentication server having one or more processors, to a client device, an account parameter to insert into a link, the account parameter derived from an account credential used to authenticate a first application executing on the client device, the link including an address referencing a second application executable on the client device, the account parameter passed from the first application to the second application responsive to an interaction on the link;

receiving, by the authentication server, from the second application of the client device, subsequent to passing the account parameter from the first application to the second application, a request to authenticate the second application, the request including the account parameter;

authenticating, by the authentication server, the client device for the second application using the account parameter provided to the first application and passed via the link to the second application; and

transmitting, by the authentication server, based on authenticating the client device for the second application, an authentication indication identifying one of success or failure of authentication of the client device for the second application.

2. The method of claim 1 , wherein in the event that the authentication indication identifies success of authentication, the method further comprises performing a full or partial login to an account on the second application using the account parameter.

3. The method of claim 2 , wherein in the event that authentication indication identifies failure of authentication, the second application is executed without using the account parameter to perform a full or partial login to an account of the second application.

4. The method of claim 1 , wherein providing the account parameter further comprises providing the account parameter derived from the account credential using a two-way encryption algorithm; and

wherein authenticating the client device for the second application further comprises recovering the account credentials by applying the two-way encryption algorithm to the account parameter included in the request to authenticate.

5. The method of claim 1 , wherein providing the account parameter further comprises providing the account parameter derived from the account credential using a one-way encryption algorithm; and

wherein authenticating the client device for the second application further comprises determining that a second account parameter separately derived from the account credential using the one-way encryption algorithm matches the account parameter included in the request to authenticate.

6. The method of claim 1 , wherein authenticating the client device for the second application further comprises determining that the account parameter included in the request to authenticate matches the account parameter stored in a cache.

7. The method of claim 1 , wherein providing the account parameter further comprises providing the account parameter passed from the first application to the second application responsive to the interaction on the link via at least one of a link parameter of the link and of a function call by a platform application running on the client device.

8. The method of claim 1 , wherein receiving the request to authenticate further comprises receiving the request to authenticate from the second application of the client device via an application server associated with the second application; and

wherein transmitting authentication indication further comprises transmitting authentication indication to the second application of the client device via the application server associated with the second application.

9. The method of claim 1 , wherein providing the account parameter further comprises providing the account parameter included in the link, the link including the address referencing the second application, the interaction on the link causing the client device to install the second application and to pass the account parameter to the second application subsequent to installation of the second application.

10. The method of claim 1 , further comprising generating, by the authentication server, the account parameter based on the account credential used to authenticate the first application executing on the client device; and

wherein providing the account parameter further comprises providing the link including the account parameter and the address referencing the second application, responsive to generating the account parameter.

11. The method of claim 1 , wherein transmitting authentication indication further comprises transmitting the authentication indication including account settings for the second application corresponding to the authentication credentials, receipt of the account settings causing the client device to apply the account settings for the second application.

12. A system for passing account authentication information via parameters, comprising:

an authenticator executed on an authentication server having one or more processors, configured to:

provide, to a client device, an account parameter to insert into a link, the account parameter derived from an account credential used to authenticate a first application executing on the client device, the link including an address referencing a second application executable on the client device, the account parameter passed from the first application to the second application responsive to an interaction on the link;

receive, from the second application of the client device, subsequent to passing the account parameter from the first application to the second application, a request to authenticate the second application, the request including the account parameter;

authenticate the client device for the second application using the account parameter provided to the first application and passed via the link to the second application; and

transmit, based on the authentication of the client device for the second application, an authentication indication identifying one of success or failure of the authentication of the client device for the second application.

13. The system of claim 12 , wherein the authenticator is further configured to:

provide the account parameter derived from the account credential using a two-way encryption algorithm; and

authenticate the client device for the second application by recovering the account credentials by applying the two-way encryption algorithm to the account parameter included in the request to authenticate.

14. The system of claim 12 , wherein the authenticator is further configured to:

provide the account parameter derived from the account credential using a one-way encryption algorithm; and

authenticate the client device for the second application by determining that a second account parameter separately derived from the account credential using the one-way encryption algorithm matches the account parameter included in the request to authenticate.

15. The system of claim 12 , wherein the authenticator is further configured to authenticate the client device for the second application by determining that the account parameter included in the request to authenticate matches the account parameter stored in a cache.

16. The system of claim 12 , wherein the authenticator is further configured to provide the account parameter passed from the first application to the second application responsive to the interaction on the link via at least one of a link parameter of the link and of a function call by a platform application running on the client device.

17. The system of claim 12 , wherein the authenticator is further configured to:

receive the request to authenticate from the second application of the client device via an application server associated with the second application; and

transmit the authentication indication to the second application of the client device via the application server associated with the second application.

18. The system of claim 12 , wherein the authenticator is further configured to provide the account parameter included in the link, the link including the address referencing the second application, the interaction on the link causing the client device to install the second application and to pass the account parameter to the second application subsequent to installation of the second application.

19. The system of claim 12 , wherein the authenticator is further configured to:

generate the account parameter based on the account credential used to authenticate the first application executing on the client device; and

provide the link including the account parameter and the address referencing the second application, responsive to the generation of the account parameter.

20. The system of claim 12 , wherein the authenticator is further configured to transmit the authentication indication including account settings for the second application corresponding to the authentication credentials, receipt of the account settings causing the client device to apply the account settings for the second application.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 13, 2021
From: KASINA, ABHIRAM; LEWIS, JUSTIN
To: GOOGLE INC.
Reel/Frame 058374/0008 →
CHANGE OF NAME Recorded Dec 13, 2021
From: GOOGLE INC.
To: GOOGLE LLC
Reel/Frame 058495/0468 →
Continuity (2)
Provisional Application 62486852 · Apr 18, 2017
Related Publication 20200244644A1 · Jul 30, 2020
Cited By (1)
US 12,348,504