IP Library Granted Patent US 12,321,908
Granted Patent B2
US 12,321,908 · App. 17/565,073 · Granted Jun 3, 2025

Systems and methods for creating dynamic sessions for mobile application integration

Inventors: Prasanna Annamalai (Chennai, IN); Harish Annam (Nanganallur, IN); Arun Arumugam (Puducherry, IN); Madar Areef Hussain Shaik (Chennai, IN)
Assignee: PAYPAL, INC.
G06Q20/108G06Q20/3223G06Q20/385G06Q20/401G06Q20/42H04L63/0807H04L67/146G06F16/2379
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,321,908
App. No.
17/565,073
Granted
Jun 3, 2025
Kind
B2
Abstract

Systems and methods for mobile application integration are described. These may include receiving a payment request a mobile application, sending a payment application detection request, receiving a detection response, and sending a customized user interface to the mobile device. The customized user interfaces are determined by whether an associated payment application is present on the mobile device and whether the mobile device is authenticated with the payment processing platform. These techniques can allow for a better user experience when interacting with the payment processing platform.

Claims (41)

1. A system comprising:

a non-transitory memory; and

one or more hardware processors coupled with the non-transitory memory and configured to execute instructions from the non-transitory memory to cause the system to perform operations comprising:

receiving, from a browser object associated with a mobile application of a computing device, a transaction request for processing a transaction during a session associated with the mobile application;

transmitting, to the mobile application, programming code that causes the computing device to retrieve authentication credentials from a web application running on the computing device, the authentication credentials for authenticating a user of the computing device with a service provider associated with the web application, the web application being different from the mobile application;

automatically authenticating the user for a session associated with the transaction request based on the authentication credentials;

processing the transaction for the user based on the authenticating the user; and

in response to authenticating the user based on the authentication credentials retrieved from the web application, causing the browser object to store an authentication session token in a data store of the browser object associated with the mobile application, the authentication session token usable for authenticating the user by the mobile application in a subsequent interaction with the user.

2. The system of claim 1 , wherein the transmitting the programming code is performed in response to determining that the authentication session token is not present in the data store.

3. The system of claim 1 , wherein the authentication credentials indicates that the user is authenticated by a hosting server of the web application.

4. The system of claim 1 , wherein the authentication credentials are retrieved from the web application using an operating system application programming interface (API).

5. The system of claim 4 , wherein the operating system API is a mobile operating system API.

6. The system of claim 4 , wherein the operating system API includes a cookie manager usable to access stored authentication session tokens.

7. The system of claim 1 , wherein the authenticating the user for the session comprises:

validating the authentication credentials with values in a hosting database; and

transmitting the authentication session token to the browser object for storage.

8. The system of claim 1 , wherein the authentication session token is associated with the mobile application.

9. A method comprising:

receiving, from a browser object associated with a mobile application of a computing device, a transaction request for processing a transaction during a session associated with the mobile application;

transmitting, to the mobile application, programming code that causes the computing device to retrieve authentication credentials from a web application running on the computing device;

authenticating a user of the computing device for the session associated with the transaction request based on the authentication credentials, wherein the transaction is processed based on the authenticating the user; and

in response to authenticating the user based on the authentication credentials retrieved from the web application, causing the browser object to store an authentication session token in a data store of the browser object associated with the mobile application, the authentication session token usable for authenticating the user by the mobile application during a subsequent session.

10. The method of claim 9 , further comprising:

providing a customized user interface to the browser object for display.

11. The method of claim 9 , wherein the authenticating the user comprises:

validating the authentication credentials using data stored on a hosting server.

12. The method of claim 9 , wherein the authenticating the user further comprises:

transmitting the authentication session token to the computing device for storage on the browser object.

13. The method of claim 9 , wherein the authentication credentials indicates that the user is authenticated by a hosting server of the web application.

14. The method of claim 9 , wherein the authentication session token is associated with the mobile application.

15. A non-transitory machine-readable medium having stored thereon machine-readable instructions executable to cause a machine to perform operations comprising:

transmitting, to a mobile application of a computing device, programming code that causes the computing device to retrieve authentication credentials from a web application running on the computing device, the authentication credentials being retrieved for a transaction request received by the mobile application during a session between a user of the computing device and the mobile application;

authenticating the user of the computing device for the session associated with the transaction request based on the authentication credentials; and

in response to authenticating the user based on the authentication credentials retrieved from the web application, (i) processing the transaction and (ii) causing the browser object to store an authentication session token in a data store of the browser object associated with the mobile application, the authentication session token usable for authenticating the user by the mobile application in a subsequent interaction with the user.

16. The non-transitory machine-readable medium of claim 15 , wherein the transmitting the programming code is performed in response to determining that the authentication session token is not present in the data store.

17. The non-transitory machine-readable medium of claim 15 , wherein the authentication credentials indicates that the user is authenticated by a hosting server of the web application.

18. The non-transitory machine-readable medium of claim 15 , wherein the authentication credentials are retrieved from the web application using a mobile operating system application programming interface (API).

19. The non-transitory machine-readable medium of claim 15 , wherein the authenticating the user for the session comprises:

validating the authentication credentials with values in a hosting database; and

transmitting the authentication session token to the browser object for storage.

20. The non-transitory machine-readable medium of claim 15 , wherein the authentication session token is associated with the mobile application.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 29, 2021
From: ANNAMALAI, PRASANNA; ANNAM, HARISH; SHAIK, MADAR AREEF HUSSAIN; A, ARUN
To: PAYPAL, INC.
Reel/Frame 058502/0973 →
Continuity (2)
Continuation 16731535 · Dec 31, 2019
Related Publication 20220122049A1 · Apr 21, 2022
References Cited (24)
US 8874899B1 · Persson et al. · 2014 [cited by applicant]
US 8943150B2 · Massey et al. · 2015 [cited by applicant]
US 10430796B2 · Shah · 2019 [cited by examiner]
US 10467615B1 · Omojola · 2019 [cited by examiner]
US 10885541B1 · Ho · 2021 [cited by applicant]
US 20120324556A1 · Yefimov · 2012 [cited by examiner]
US 20150178726A1 · Wen · 2015 [cited by examiner]
US 20160314460A1 · Subramanian · 2016 [cited by examiner]
US 20170316400A1 · Venkatakrishnan · 2017 [cited by examiner]
US 20180137505A1 · Soppitt · 2018 [cited by examiner]
US 20180314513A1 · DiTullio et al. · 2018 [cited by applicant]
US 20200028753A1 · Powar · 2020 [cited by examiner]
US 20200082459A1 · Varma · 2020 [cited by examiner]
EP 3198397B1 · 2021 [cited by examiner]
WO WO2010033967A1 · 2010 [cited by examiner]
WO 2016015096A1 · 2016 [cited by applicant]
WO WO2016175896A1 · 2016 [cited by examiner]
WO WO2017189917A1 · 2017 [cited by examiner]
Dacosta et al.: One-Time Cookie: Preventing Session Hijacking Attacks with Stateless Authentication Tokens, Jun. 2012, ACM Transactions on Internet Technology, vol. 12, No. 1, Article 1, pp. 1.1-1.24 (Year: 2012). [cited by examiner]
Popa, Raluca, Ada: Web Security: Session Management and CSRF, Feb. 10, 2017, CS 161: Computer Security, pp. 1-52 (Year: 2017). [cited by examiner]
Polat et al.: Token-based authentication for M2M Platforms, 2016, Turkish Journal of Electrical Engineering and Computer Science, pp. 1-12 (Year: 2016). [cited by examiner]
Klm, Albert: Understanding User Authentication in Your Web App and How to Implement it Part 1 (the High Level Overview), Apr. 26, 2019, Medium, pp. 1-40 (Year: 2019). [cited by examiner]
Cipriani J., “How to Check Your Android Phone Malicious Apps,” May 14, 2019, 4 pages. [cited by applicant]
Polat H., et al., “Token-Based Authentication for M2M Platforms,” Turkish Journal of Electrical Engineering and Computer Sciences, vol. 25, Jul. 30, 2017, 12 pages. [cited by applicant]
Cited By (2)
US 12,388,826 US 12,596,682