US 11,943,356 B2
Persistent login
Shaoyen Chang, Stamford, CT (US); William Mahoney, Stamford, CT (US); Chidhambaram Mathevan Pillai, Stamford, CT (US); Seulkee Park, Stamford, CT (US); Jeremy T. Mack, Brighton, MI (US); Shahul Shaik, Hyderabad (IN); Sathyanarayana Mahendran, Hyderabad (IN); and Marina Loginova, Stamford, CT (US)
Assigned to SYNCHRONY BANK, Stamford, CT (US)
Filed by Synchrony Bank, Stamford, CT (US)
Filed on May 5, 2023, as Appl. No. 18/312,615.
Application 18/312,615 is a continuation of application No. 17/728,416, filed on Apr. 25, 2022, granted, now 11,689,368.
Application 17/728,416 is a continuation of application No. 17/083,692, filed on Oct. 29, 2020, granted, now 11,349,662, issued on May 31, 2022.
Claims priority of provisional application 62/927,552, filed on Oct. 29, 2019.
Prior Publication US 2023/0362008 A1, Nov. 9, 2023
This patent is subject to a terminal disclaimer.
Int. Cl. H04L 9/32 (2006.01); H04L 9/08 (2006.01); H04L 9/40 (2022.01); H04L 29/06 (2006.01); H04L 67/306 (2022.01)
CPC H04L 9/3213 (2013.01) [H04L 9/088 (2013.01); H04L 9/3226 (2013.01); H04L 63/105 (2013.01); H04L 63/1433 (2013.01); H04L 67/306 (2013.01)] 18 Claims
OG exemplary drawing
 
1. A computer-implemented method comprising:
transmitting an access token, wherein the access token is associated with a security profile, and wherein when the access token is received at a first service, the first service generates an access request that includes the access token;
receiving the access request regarding access to account data associated with a second service, wherein the security profile indicates permission to access the account data;
permitting access to the account data based on validation of the access token, wherein when the access is permitted to the account data, a display of a web application associated with the first service is populated with the account data;
receiving a follow-up request to perform one or more additional actions associated with the account data, wherein the follow-up request includes the access token, and wherein the security profile indicates that the one or more additional actions require additional authentication data associated with a user device;
receiving the additional authentication data;
transmitting a new access token after validation of the additional authentication data, wherein the new access token is associated with an updated security profile that indicates permission to perform the one or more additional actions; and
permitting the one or more additional actions to be performed based on the new access token, wherein when the one or more additional actions are permitted, the display of the web application is dynamically modified to include one or more interface elements corresponding to the one or more additional actions.