US 12,457,105 B2
Using co-located secondary devices to protect against cookie theft
Adrian Isles, Oakland, CA (US); Philipp Pfeiffenberger, San Francisco, CA (US); and David Turner, Newark, CA (US)
Assigned to Google LLC, Mountain View, CA (US)
Filed by Google LLC, Mountain View, CA (US)
Filed on Oct. 28, 2021, as Appl. No. 17/513,564.
Prior Publication US 2023/0137767 A1, May 4, 2023
Int. Cl. H04L 9/32 (2006.01)
CPC H04L 9/3213 (2013.01) 21 Claims
OG exemplary drawing
 
1. A method, comprising:
receiving, by a server, a service request from a first client device, and a first instance of an authentication token associated with the service request and generated by the first client device, and first location data associated with the first instance of the authentication token and reflecting a physical location of the first client device;
receiving, by the server, from a second client device, a second instance of the authentication token associated with the service request and generated by the first client device, and second location data associated with the second instance of the authentication token and reflecting a physical location of the second client device, wherein the second client device received the second instance of the authentication token from the first client device, wherein the second instance of the authentication token is a duplicate of the first instance of the authentication token;
determining, by the server, that the first instance of the authentication token matches the second instance of the authentication token and that the first location data matches the second location data; and
responsive to determining that the first instance of the authentication token matches the second instance of the authentication token and that the first location data matches the second location data, processing, by the server, the service request.