US2021390548A1PendingUtilityA1

Passwordless authentication through use of device tokens or web browser cookies

Assignee: PAYPAL INCPriority: Jun 10, 2016Filed: Aug 30, 2021Published: Dec 16, 2021
Est. expiryJun 10, 2036(~9.9 yrs left)· nominal 20-yr term from priority
H04L 63/0807G06Q 20/4014G06Q 20/12
47
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

There is provided systems and methods for passwordless authentication through use of device tokens or web browser cookies. A user may enter into a checkout process with a merchant for a transaction requiring electronic transaction processing with a service provider. The checkout process may be performed prior to or without the user having previously established an account with the service provider for electronic transaction processing. The user may therefore provide user information, such as a name and financial information, and an account for the user may be established. To establish the account, the user is not required to enter a password, and the password is automatically set by the service provider. The service provider may then establish a token on the user's device during transaction processing that later authenticates the device for use of the account during future transaction processing when the token is received.

Claims

exact text as granted — not AI-modified
1 . (canceled) 
     
     
         2 . A method, comprising:
 receiving, at a computer system, an indication that a web browsing software executing on a user device is currently viewing a web page configured to execute an electronic transaction process corresponding to an electronic transaction, and that the web browsing software has not yet completed the electronic transaction, wherein the web page corresponds to a particular web site;   receiving, at the computer system from the user device while the user device is still in the electronic transaction process, identifying information corresponding to a user of the user device;   based on the identifying information, the computer system determining that the user of the user device is not associated with any particular user account for an electronic transaction service corresponding to the electronic transaction process;   in response to determining that the user of the user device is not associated with any particular user account, the computer system causing display of a plurality of graphical elements on the web page, wherein the plurality of graphical elements are configured to, in response to user input for the plurality of graphical elements, cause creation of a passwordless checkout user account for the electronic transaction service;   based on receiving the user input for the plurality of graphical elements on the web page, the computer system creating the passwordless checkout user account;   using identifying device information for the user device and without using a password, the computer system authenticating the user of the user device prior to completion of the electronic transaction; and   based on authenticating the user of the user device, authorizing completion of the electronic transaction via the web page.   
     
     
         3 . The method of  claim 2 , further comprising:
 collecting the identifying device information for the user device via web code executable on the web browsing software.   
     
     
         4 . The method of  claim 2 , wherein the identifying device information comprises a secure token corresponding to a data element of the user device, and wherein authenticating the user of the user device comprises receiving the secure token corresponding to the data element of the user device from the user device prior to completion of the electronic transaction. 
     
     
         5 . The method of  claim 2 , wherein the identifying device information comprises a cookie configured to be stored by the web browsing software executing on the user device, wherein the method further comprises:
 creating the cookie by the computer system, and wherein authenticating the user of the user device comprises receiving the cookie from the user device and verifying contents of the cookie by the computer system.   
     
     
         6 . The method of  claim 2 , wherein determining that the user of the user device is not associated with any particular user account comprises the computer system searching one or more data sources for entries for causing at least a portion of the identifying information corresponding to the user of the user device, and finding no entries for the user information for the user. 
     
     
         7 . The method of  claim 2 , wherein receiving the identifying information corresponding to the user of the user device comprises receiving the identifying information via a graphical user interface element of one or more particular web pages of the particular web site. 
     
     
         8 . The method of  claim 2 , wherein the electronic transaction is an electronic purchase transaction. 
     
     
         9 . A system, comprising:
 a processor;   a network interface device; and   a non-transitory computer-readable medium having stored thereon instructions executable to cause the system to perform operations comprising:   receiving an indication that a web browsing software executing on a user device is currently viewing a web page configured to execute an electronic transaction process corresponding to an electronic transaction, and that the web browsing software has not yet completed the electronic transaction, wherein the web page corresponds to a particular web site;   receiving, from the user device, identifying information corresponding to a user of the user device;   based on the identifying information, determining that the user of the user device is not associated with any particular user account for an electronic transaction service corresponding to the electronic transaction process;   in response to determining that the user of the user device is not associated with any particular user account, causing display of a plurality of graphical elements on the web page, wherein the plurality of graphical elements are configured to, in response to user input for the plurality of graphical elements, cause creation of a passwordless checkout user account for the electronic transaction service;   based on receiving the user input for the plurality of graphical elements on the web page, creating the passwordless checkout user account;   using identifying device information for the user device and without using a password, authenticating the user of the user device prior to completion of the electronic transaction; and   based on authenticating the user of the user device, authorizing completion of the electronic transaction via the web page.   
     
     
         10 . The system of  claim 9 , wherein the identifying device information comprises a secure token corresponding to a data element of the user device, and wherein authenticating the user of the user device comprises receiving the secure token corresponding to the data element of the user device from the user device prior to completion of the electronic transaction. 
     
     
         11 . The system of  claim 9 , wherein the identifying device information comprises a cookie configured to be stored by the web browsing software executing on the user device, wherein the operations further comprise:
 creating the cookie by the system, and wherein authenticating the user of the user device comprises receiving the cookie from the user device and verifying contents of the cookie by the system.   
     
     
         12 . The system of  claim 9 , wherein determining that the user of the user device is not associated with any particular user account comprises the system searching one or more data sources for entries for causing at least a portion of the identifying information corresponding to the user of the user device, and finding no entries for the user information for the user. 
     
     
         13 . The system of  claim 9 , wherein receiving the identifying information corresponding to the user of the user device comprises receiving the identifying information via a graphical user interface element of one or more particular web pages of the particular web site. 
     
     
         14 . The system of  claim 9 , wherein the electronic transaction is an electronic purchase transaction. 
     
     
         15 . The system of  claim 9 , wherein the operations further comprise:
 collecting the identifying device information for the user device prior to initiation of the electronic transaction.   
     
     
         16 . A non-transitory computer-readable medium having stored thereon instructions executable by a computer system to cause the computer system to perform operations comprising:
 receiving an indication that a web browsing software executing on a user device is currently viewing a web page configured to execute an electronic transaction process corresponding to an electronic transaction, and that the web browsing software has not yet completed the electronic transaction, wherein the web page corresponds to a particular web site;   receiving, from the user device, identifying information corresponding to a user of the user device;   based on the identifying information, determining that the user of the user device is not associated with any particular user account for an electronic transaction service corresponding to the electronic transaction process;   in response to determining that the user of the user device is not associated with any particular user account, causing display of a plurality of graphical elements on the web page, wherein the plurality of graphical elements are configured to, in response to user input for the plurality of graphical elements, cause creation of a passwordless checkout user account for the electronic transaction service;   based on receiving the user input for the plurality of graphical elements on the web page, creating the passwordless checkout user account;   using identifying device information for the user device and without using a password, authenticating the user of the user device prior to completion of the electronic transaction; and   based on authenticating the user of the user device, authorizing completion of the electronic transaction via the web page.   
     
     
         17 . The non-transitory computer-readable medium of  claim 16 , wherein the identifying device information comprises a secure token corresponding to a data element of the user device, and wherein authenticating the user of the user device comprises receiving the secure token corresponding to the data element of the user device from the user device prior to completion of the electronic transaction. 
     
     
         18 . The non-transitory computer-readable medium of  claim 16 , wherein the identifying device information comprises a cookie configured to be stored by the web browsing software executing on the user device, wherein the operations further comprise:
 creating the cookie by the computer system, and wherein authenticating the user of the user device comprises receiving the cookie from the user device and verifying contents of the cookie by the computer system.   
     
     
         19 . The non-transitory computer-readable medium of  claim 16 , wherein determining that the user of the user device is not associated with any particular user account comprises the computer system searching one or more data sources for entries for causing at least a portion of the identifying information corresponding to the user of the user device, and finding no entries for the user information for the user. 
     
     
         20 . The non-transitory computer-readable medium of  claim 16 , wherein receiving the identifying information corresponding to the user of the user device comprises receiving the identifying information via a graphical user interface element of one or more particular web pages of the particular web site. 
     
     
         21 . The non-transitory computer-readable medium of  claim 16 , wherein the operations further comprise:
 collecting the identifying device information for the user device via the web browsing software prior to initiation of the electronic transaction.

Join the waitlist — get patent alerts

Track US2021390548A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.