Device independent authentication system and method

Patent No. US7222363 (titled "Device independent authentication system and method") on Dec 9, 2002. The application was issued on May 22, 2007.

What is this patent about?

’363 is related to the field of wireless internet communications and secure session management. Specifically, it addresses the technical challenge of maintaining persistent, authenticated user sessions on mobile devices that lack the memory or software support for traditional browser cookies. The context involves the transition from standard PC-based web browsing to early mobile web environments where hardware constraints often broke the standard mechanisms used for security and session tracking.

The underlying idea behind ’363 is to bypass the need for cookie files by embedding session-specific security data directly into the markup of the web page itself. Instead of relying on the browser to manage a separate text file, the system utilizes HTML-INPUT tags—specifically hidden fields—to carry an encrypted security token. This approach effectively turns the stateless HTTP protocol into a stateful session by forcing the communication device to reflect the token back to the server within the body of subsequent requests, ensuring the server can verify the user's identity without local file storage.

The claims of ’363 focus on a multi-stage authentication method that validates both the user and the specific hardware being used. The process begins by inspecting an incoming HTTP request for client agent data and device model information to determine if the hardware is authorized to access the service. If the device is permitted but lacks a valid session, the server issues a security token encapsulated within an HTML tag after a successful login, which the communication device then stores in its temporary memory for the duration of the session.

In practice, the invention functions as a gatekeeper that first filters traffic based on the device's identity—such as the service provider or the specific phone model—before even attempting user-level authentication. Once a device is cleared, the server dynamically generates a hidden input field containing a 128-bit encrypted token. Because this token is part of the HTML form data or request body, it bypasses the memory limitations that typically cause wireless devices to reject or truncate large cookie files, allowing for secure 'clickthrough' navigation across multiple pages.

This solution differentiates itself from prior approaches like URL rewriting or proxy-based mapping by avoiding the character limits and security risks associated with long, visible query strings. Unlike URL rewriting, which can exceed the 100-character capacity of early mobile browsers, the use of hidden HTML tags keeps the session data internal to the request processing. Furthermore, by performing a hardware-level check against a database of authorized models and agents, the system adds a layer of device-specific validation that prevents unauthorized hardware from even reaching the login interface.

How does this patent fit in bigger picture?

Technical Landscape

In the early 2000s when ’363 was filed, web-based session management and authentication were typically implemented using browser cookies to store state information and security tokens on client hardware. At a time when mobile internet access was increasingly facilitated by handheld wireless devices, systems commonly relied on these text-based files to maintain persistent connections over the stateless HTTP protocol. However, hardware and software constraints of the era, specifically limited onboard memory and restricted URL character limits on mobile handsets, made the use of standard cookie-based authentication non-trivial. Many wireless devices lacked the capacity to store large cookie files or process complex URL rewriting, while alternative gateway-based mapping often resulted in device-specific compatibility issues or security vulnerabilities related to data artifacts left on intermediate servers.

Prosecution Position

The disclosed invention represents a technical advancement in secure session management by enabling authentication on devices that lack cookie support without exceeding URL length constraints. The architectural solution involves an authentication flow where, upon valid credential entry, a host server issues and embeds a security token directly within HTML input tags rather than relying on the browser's cookie management layer. This integration allows the security token to be stored in an encrypted form on the communication device and transmitted back to the server during subsequent HTTP requests. The technical effect achieved is the establishment of a secure, trackable session that is independent of cookie-handling capabilities, overcoming the memory and protocol limitations of early wireless browsing environments while maintaining session integrity through the validation of device-specific identifying information.

Claims

The patent contains a total of 9 claims, with claims 1, 8, and 9 serving as the independent claims. These independent claims focus on a method and system for facilitating authentication between a communication device and a host web server by analyzing HTTP request files for client agent and device model data and subsequently issuing a security token within an HTML tag. The dependent claims serve to further specify the authentication process by detailing the use of login pages, defining the types of communication devices and browser information involved, and describing the management of secure web sessions through token tracking.

Key Claim Terms New

Definitions of key terms used in the patent claims.

Term (Source)Support for SpecificationInterpretation
Client agent data
(Claim 1, Claim 8, Claim 9)
In additional embodiments, additional validation processes are provided, such as analyzing device identifying information, including URL information, client browser information, and client agent identification information associated with the HTTP requests.Information identifying the specific software or browser application used by the communication device to access the web server, used for validation and access control.
Communication device model data
(Claim 1, Claim 8, Claim 9)
One method requests device-specific information associated with a wireless or handheld device and maps this device information onto a proxy database associated with a server for that device. A host web server analyzes an HTTP request file received from a communication device... [and compares] communication device model data to authorized communication device models.Hardware-specific identification information regarding the type or model of the wireless device, used by the server to determine if the device is authorized or how to configure the session.
HTML tag
(Claim 1, Claim 8, Claim 9)
In accordance with an exemplary embodiment, a host web server issues a security token using standard HTML-INPUT tags. The security token obtained from the web server may be stored on a communication device, in encrypted form, utilizing standard HTML-INPUT tags. The HTML-INPUT tags may also initiate a secure session with a web server application.A standard markup language element, specifically HTML-INPUT tags, used to transmit, store, and return security token data between a server and a wireless device to circumvent the lack of cookie support.
HTTP request file
(Claim 1, Claim 8, Claim 9)
A host web server analyzes an HTTP request file received from a communication device for the presence of security token data. Thereafter, the host web server determines if each additional HTTP request file received from the client includes a security token before responding to the request. Unique identification data or session data may be added in a header of an HTTP request.A data transmission from a client device to a server using the Hypertext Transfer Protocol that contains headers and metadata, such as device identification and security tokens, to facilitate session tracking.
Security token
(Claim 1, Claim 8)
In a secure session transaction, a client visiting a secure web site for the first time is typically queried for client ID and password information. Upon valid authentication, a security token is then typically issued to the client. The host web server determines if each additional HTTP request file received from the client includes a security token before responding to the request.A piece of authentication data or a security identifier issued by a host web server to a client device after valid authentication, used to initiate or maintain a secure session in place of a cookie file.

Litigation Cases New

US Latest litigation cases involving this patent.

Case NumberFiling DateTitle
2:25-cv-00772Aug 8, 2025Disintermediation Services, Inc. V. The Goodyear Tire & Rubber Company
2:25-cv-00771Aug 8, 2025Disintermediation Services, Inc. V. Carvana, Llc
2:25-cv-00773Aug 8, 2025DISINTERMEDIATION SERVICES, INC. v. HILTON WORLDWIDE HOLDINGS INC. et al

Patent Family

Patent Family

File Wrapper

The dossier documents provide a comprehensive record of the patent's prosecution history - including filings, correspondence, and decisions made by patent offices - and are crucial for understanding the patent's legal journey and any challenges it may have faced during examination.

  • Get instant alerts for new documents

US7222363

Application Number
US10314736A
Filing Date
Dec 9, 2002
Publication Date
May 22, 2007
External Links
Slate, USPTO , Google Patents