Access token management

US2016224782A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2016224782-A1
Application numberUS-201514713786-A
CountryUS
Kind codeA1
Filing dateMay 15, 2015
Priority dateJan 30, 2015
Publication dateAug 4, 2016
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Provided is a server including: a user authenticating unit that authenticates, using an access token, a user of a user device; a token receiving unit that receives an access token from the user device; and a determination information transmitting unit which, when the access token is received, transmits determination information that enables a determination as to whether or not a remaining time until a time of expiration of the access token is less than a predetermined threshold, to the user device, wherein the user authenticating unit issues a new access token with an updated time of expiration when an issuance request for an access token which is transmitted by the user device having received the determination information is received.

First claim

Opening claim text (preview).

What is claimed is: 1 . A server comprising: a user authenticating unit to authenticate, using an access token, a user of a user device connected via a network; a token receiving unit to receive an access token from the user device; and a determination information transmitting unit to transmit, when the access token is received, determination information that enables a determination as to whether or not a remaining time until a time of expiration of the access token is less than a predetermined threshold, to the user device, wherein the user authenticating unit issues a new access token with an updated time of expiration when an issuance request for an access token which is transmitted by the user device having received the determination information is received. 2 . The server according to claim 1 , further comprising a token generating unit to generate an access token using identification information of the user device and time of expiration related information that is related to a time of expiration of the access token, wherein the user authenticating unit authenticates the user by determining whether or not the access token received from the user device is the access token that is generated using the identification information of the user device and the time of expiration related information. 3 . The server according to claim 1 , wherein the user authenticating unit authenticates the user by handling both the new access token and an old access token as valid access tokens during a period from issuance of the new access token to expiration of a time of expiration of the old access token. 4 . The server according to claim 1 , further comprising: an invalidation request receiving unit to receive an invalidation request of an old access token from the user device having received a new access token; and a token invalidating unit to invalidate the old access token when the invalidation request is received. 5 . The server according to claim 4 , wherein the user authenticating unit authenticates the user by handling both the new access token and an old access token as valid access tokens during a period from issuance of the new access token to invalidation of the old access token at the server. 6 . The server according to claim 4 , wherein the invalidation request receiving unit receives a request to invalidate an old access token, from the user device having received a new access token and having validated the new access token. 7 . The server according to claim 4 , further comprising an invalidation notifying unit to notify, when the old access token is invalidated at the server, the user device of the invalidation. 8 . A system comprising a server and a user device which are connected to each other via a network, the server including: a user authenticating unit to authenticate, using an access token, a user of a user device connected via the network; a token receiving unit to receive an access token from the user device; and a determination information transmitting unit to transmit, when the access token is received, determination information that enables a determination as to whether or not a remaining time until a time of expiration of the access token is less than a predetermined threshold, to the user device, and the user device including: an authentication request transmitting unit to transmit an authentication request to the server; a token transmitting unit to transmit the access token to the server; a determination information receiving unit to receive the determination information from the server; a remaining time confirming unit to determine, when the determination information is received, whether or not a remaining time until a time of expiration of the access token is less than a predetermined threshold; and an issuance request transmitting unit to transmit an issuance request for an access token when the remaining time until the time of expiration of the access token is determined to be less than the predetermined threshold, wherein the user authenticating unit issues a new access token with an updated time of expiration when an issuance request for an access token which is transmitted by the user device having received the determination information is received. 9 . The system according to claim 8 , wherein the determination information receiving unit receives, from the server, the remaining time until the time of expiration of the access token as the determination information. 10 . The system according to claim 8 , wherein the user device further includes a token managing unit to, when receiving a new access token, validate the new access token and invalidating an old access token. 11 . The system according to claim 10 , wherein the token managing unit associates, with a plurality of access tokens retained in the user device, data which enables priorities among the access tokens to be compared, and when the new access token is received, associates the new access token with the data including a value that has a higher priority than other access tokens in order to validate the new access token and invalidate the other access tokens at the same time, and when a plurality of access tokens are retained in the user device, the token transmitting unit compares the data associated with the plurality of access tokens, and transmits an access token with a highest priority to the server. 12 . The system according to claim 10 , wherein when both the new access token and the old access token are valid, the token transmitting unit preferentially transmits the new access token to the server. 13 . The system according to claim 10 , further comprising an invalidation request transmitting unit to transmit an invalidation request of the old access token to the server when validation of the new access token at the user device is completed. 14 . The system according to claim 10 , wherein the token managing unit invalidates the old access token when notification of invalidation of the old access token at the server is sent from the server. 15 . An access token management method causing a computer to execute: authenticating, using an access token, a user of a user device connected via a network; receiving an access token from the user device; and transmitting, when the access token is received, determination information that enables a determination as to whether or not a remaining time until a time of expiration of the access token is less than a predetermined threshold, to the user device, wherein when authenticating the user, a new access token with an updated time of expiration is issued when an issuance request for an access token which is transmitted by the user device having received the determination information is received.

Assignees

Inventors

Classifications

  • using passwords (cryptographic mechanisms or cryptographic arrangements for entity authentication using a predetermined code H04L9/3226) · CPC title

  • User authentication · CPC title

  • G06F21/45Primary

    Structures or tools for the administration of authentication · CPC title

  • using one-time-passwords · CPC title

  • using certificates · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2016224782A1 cover?
Provided is a server including: a user authenticating unit that authenticates, using an access token, a user of a user device; a token receiving unit that receives an access token from the user device; and a determination information transmitting unit which, when the access token is received, transmits determination information that enables a determination as to whether or not a remaining time …
Who is the assignee on this patent?
Pfu Ltd
What technology area does this patent fall under?
Primary CPC classification G06F21/45. Mapped technology areas include Physics.
When was this patent published?
Publication date Thu Aug 04 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 3 related publications on this page (citations in our corpus or others sharing the same primary CPC).