Authorization token cache system and method
US-2015350186-A1 · Dec 3, 2015 · US
US2016224782A1 · US · A1
| Field | Value |
|---|---|
| Publication number | US-2016224782-A1 |
| Application number | US-201514713786-A |
| Country | US |
| Kind code | A1 |
| Filing date | May 15, 2015 |
| Priority date | Jan 30, 2015 |
| Publication date | Aug 4, 2016 |
| Grant date | — |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Provided is a server including: a user authenticating unit that authenticates, using an access token, a user of a user device; a token receiving unit that receives an access token from the user device; and a determination information transmitting unit which, when the access token is received, transmits determination information that enables a determination as to whether or not a remaining time until a time of expiration of the access token is less than a predetermined threshold, to the user device, wherein the user authenticating unit issues a new access token with an updated time of expiration when an issuance request for an access token which is transmitted by the user device having received the determination information is received.
Opening claim text (preview).
What is claimed is: 1 . A server comprising: a user authenticating unit to authenticate, using an access token, a user of a user device connected via a network; a token receiving unit to receive an access token from the user device; and a determination information transmitting unit to transmit, when the access token is received, determination information that enables a determination as to whether or not a remaining time until a time of expiration of the access token is less than a predetermined threshold, to the user device, wherein the user authenticating unit issues a new access token with an updated time of expiration when an issuance request for an access token which is transmitted by the user device having received the determination information is received. 2 . The server according to claim 1 , further comprising a token generating unit to generate an access token using identification information of the user device and time of expiration related information that is related to a time of expiration of the access token, wherein the user authenticating unit authenticates the user by determining whether or not the access token received from the user device is the access token that is generated using the identification information of the user device and the time of expiration related information. 3 . The server according to claim 1 , wherein the user authenticating unit authenticates the user by handling both the new access token and an old access token as valid access tokens during a period from issuance of the new access token to expiration of a time of expiration of the old access token. 4 . The server according to claim 1 , further comprising: an invalidation request receiving unit to receive an invalidation request of an old access token from the user device having received a new access token; and a token invalidating unit to invalidate the old access token when the invalidation request is received. 5 . The server according to claim 4 , wherein the user authenticating unit authenticates the user by handling both the new access token and an old access token as valid access tokens during a period from issuance of the new access token to invalidation of the old access token at the server. 6 . The server according to claim 4 , wherein the invalidation request receiving unit receives a request to invalidate an old access token, from the user device having received a new access token and having validated the new access token. 7 . The server according to claim 4 , further comprising an invalidation notifying unit to notify, when the old access token is invalidated at the server, the user device of the invalidation. 8 . A system comprising a server and a user device which are connected to each other via a network, the server including: a user authenticating unit to authenticate, using an access token, a user of a user device connected via the network; a token receiving unit to receive an access token from the user device; and a determination information transmitting unit to transmit, when the access token is received, determination information that enables a determination as to whether or not a remaining time until a time of expiration of the access token is less than a predetermined threshold, to the user device, and the user device including: an authentication request transmitting unit to transmit an authentication request to the server; a token transmitting unit to transmit the access token to the server; a determination information receiving unit to receive the determination information from the server; a remaining time confirming unit to determine, when the determination information is received, whether or not a remaining time until a time of expiration of the access token is less than a predetermined threshold; and an issuance request transmitting unit to transmit an issuance request for an access token when the remaining time until the time of expiration of the access token is determined to be less than the predetermined threshold, wherein the user authenticating unit issues a new access token with an updated time of expiration when an issuance request for an access token which is transmitted by the user device having received the determination information is received. 9 . The system according to claim 8 , wherein the determination information receiving unit receives, from the server, the remaining time until the time of expiration of the access token as the determination information. 10 . The system according to claim 8 , wherein the user device further includes a token managing unit to, when receiving a new access token, validate the new access token and invalidating an old access token. 11 . The system according to claim 10 , wherein the token managing unit associates, with a plurality of access tokens retained in the user device, data which enables priorities among the access tokens to be compared, and when the new access token is received, associates the new access token with the data including a value that has a higher priority than other access tokens in order to validate the new access token and invalidate the other access tokens at the same time, and when a plurality of access tokens are retained in the user device, the token transmitting unit compares the data associated with the plurality of access tokens, and transmits an access token with a highest priority to the server. 12 . The system according to claim 10 , wherein when both the new access token and the old access token are valid, the token transmitting unit preferentially transmits the new access token to the server. 13 . The system according to claim 10 , further comprising an invalidation request transmitting unit to transmit an invalidation request of the old access token to the server when validation of the new access token at the user device is completed. 14 . The system according to claim 10 , wherein the token managing unit invalidates the old access token when notification of invalidation of the old access token at the server is sent from the server. 15 . An access token management method causing a computer to execute: authenticating, using an access token, a user of a user device connected via a network; receiving an access token from the user device; and transmitting, when the access token is received, determination information that enables a determination as to whether or not a remaining time until a time of expiration of the access token is less than a predetermined threshold, to the user device, wherein when authenticating the user, a new access token with an updated time of expiration is issued when an issuance request for an access token which is transmitted by the user device having received the determination information is received.
using passwords (cryptographic mechanisms or cryptographic arrangements for entity authentication using a predetermined code H04L9/3226) · CPC title
User authentication · CPC title
Structures or tools for the administration of authentication · CPC title
using one-time-passwords · CPC title
using certificates · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.