Patent No. US7222363 (titled "Device independent authentication system and method") on Dec 9, 2002. The application was issued on May 22, 2007.
’363 is related to the field of wireless internet communications and secure session management. Specifically, it addresses the technical challenge of maintaining persistent, authenticated user sessions on mobile devices that lack the memory or software support for traditional browser cookies. The context involves the transition from standard PC-based web browsing to early mobile web environments where hardware constraints often broke the standard mechanisms used for security and session tracking.
The underlying idea behind ’363 is to bypass the need for cookie files by embedding session-specific security data directly into the markup of the web page itself. Instead of relying on the browser to manage a separate text file, the system utilizes HTML-INPUT tags—specifically hidden fields—to carry an encrypted security token. This approach effectively turns the stateless HTTP protocol into a stateful session by forcing the communication device to reflect the token back to the server within the body of subsequent requests, ensuring the server can verify the user's identity without local file storage.
The claims of ’363 focus on a multi-stage authentication method that validates both the user and the specific hardware being used. The process begins by inspecting an incoming HTTP request for client agent data and device model information to determine if the hardware is authorized to access the service. If the device is permitted but lacks a valid session, the server issues a security token encapsulated within an HTML tag after a successful login, which the communication device then stores in its temporary memory for the duration of the session.
In practice, the invention functions as a gatekeeper that first filters traffic based on the device's identity—such as the service provider or the specific phone model—before even attempting user-level authentication. Once a device is cleared, the server dynamically generates a hidden input field containing a 128-bit encrypted token. Because this token is part of the HTML form data or request body, it bypasses the memory limitations that typically cause wireless devices to reject or truncate large cookie files, allowing for secure 'clickthrough' navigation across multiple pages.
This solution differentiates itself from prior approaches like URL rewriting or proxy-based mapping by avoiding the character limits and security risks associated with long, visible query strings. Unlike URL rewriting, which can exceed the 100-character capacity of early mobile browsers, the use of hidden HTML tags keeps the session data internal to the request processing. Furthermore, by performing a hardware-level check against a database of authorized models and agents, the system adds a layer of device-specific validation that prevents unauthorized hardware from even reaching the login interface.
In the early 2000s when ’363 was filed, web-based session management and authentication were typically implemented using browser cookies to store state information and security tokens on client hardware. At a time when mobile internet access was increasingly facilitated by handheld wireless devices, systems commonly relied on these text-based files to maintain persistent connections over the stateless HTTP protocol. However, hardware and software constraints of the era, specifically limited onboard memory and restricted URL character limits on mobile handsets, made the use of standard cookie-based authentication non-trivial. Many wireless devices lacked the capacity to store large cookie files or process complex URL rewriting, while alternative gateway-based mapping often resulted in device-specific compatibility issues or security vulnerabilities related to data artifacts left on intermediate servers.
The disclosed invention represents a technical advancement in secure session management by enabling authentication on devices that lack cookie support without exceeding URL length constraints. The architectural solution involves an authentication flow where, upon valid credential entry, a host server issues and embeds a security token directly within HTML input tags rather than relying on the browser's cookie management layer. This integration allows the security token to be stored in an encrypted form on the communication device and transmitted back to the server during subsequent HTTP requests. The technical effect achieved is the establishment of a secure, trackable session that is independent of cookie-handling capabilities, overcoming the memory and protocol limitations of early wireless browsing environments while maintaining session integrity through the validation of device-specific identifying information.
The patent contains a total of 9 claims, with claims 1, 8, and 9 serving as the independent claims. These independent claims focus on a method and system for facilitating authentication between a communication device and a host web server by analyzing HTTP request files for client agent and device model data and subsequently issuing a security token within an HTML tag. The dependent claims serve to further specify the authentication process by detailing the use of login pages, defining the types of communication devices and browser information involved, and describing the management of secure web sessions through token tracking.
Definitions of key terms used in the patent claims.
US Latest litigation cases involving this patent.

The dossier documents provide a comprehensive record of the patent's prosecution history - including filings, correspondence, and decisions made by patent offices - and are crucial for understanding the patent's legal journey and any challenges it may have faced during examination.
Get instant alerts for new documents