A computer-readable device is provided to a user. The device has unique
and unalterable identification data set by its manufacturer, and
application data stored therein by a party other than the manufacturer.
The identification data and the application data from the device are
collected based on an attempt by the user to access a first Web resource.
The device is authorized or unauthorized based on the identification data
and the application data. If the device is unauthorized, access to the
first Web resource is denied and the user is forwarded to a second Web
resource. If the device is authorized, access is authorized or
unauthorized based on a rule record associated with the device. If access
is authorized, the user is enabled access to the first Web resource. If
access is unauthorized, access to the first Web resource is denied and
the user is forwarded to a third Web resource.