Authorization token cache system and method
US-2015350186-A1 · Dec 3, 2015 · US
US9646151B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-9646151-B2 |
| Application number | US-201514713786-A |
| Country | US |
| Kind code | B2 |
| Filing date | May 15, 2015 |
| Priority date | Jan 30, 2015 |
| Publication date | May 9, 2017 |
| Grant date | May 9, 2017 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Provided is a server including: a user authenticating unit that authenticates, using an access token, a user of a user device; a token receiving unit that receives an access token from the user device; and a determination information transmitting unit which, when the access token is received, transmits determination information that enables a determination as to whether or not a remaining time until a time of expiration of the access token is less than a predetermined threshold, to the user device, wherein the user authenticating unit issues a new access token with an updated time of expiration when an issuance request for an access token which is transmitted by the user device having received the determination information is received.
Opening claim text (preview).
What is claimed is: 1. A system comprising a server and a user device which are connected to each other via a network, the server including: a first hardware processor to authenticate, using an access token, a user of a user device connected via the network; the first hardware processor to receive an access token from the user device; and the first hardware processor to transmit, when the access token is received, determination information that enables a determination as to whether or not a remaining time until a time of expiration of the access token from a time of the determination is less than a predetermined threshold, to the user device, and the user device including: a second hardware processor to transmit an authentication request to the server; the second hardware processor to transmit the access token to the server; the second hardware processor to receive the determination information from the server; the second hardware processor to determine, when the determination information is received, whether or not a remaining time until a time of expiration of the access token is less than a predetermined threshold; the second hardware processor to transmit an issuance request for an access token when the remaining time until the time of expiration of the access token is determined to be less than the predetermined threshold; and a token managing unit to, when receiving a new access token, validate the new access token and invalidating an old access token, wherein the first hardware processor issues a new access token with an updated time of expiration when an issuance request for an access token which is transmitted by the user device having received the determination information is received, the token managing unit associates, with a plurality of access tokens retained in the user device, data which enables priorities among the access tokens to be compared, and when the new access token is received, associates the new access token with the data including a value that has a higher priority than other access tokens in order to validate the new access token and invalidate the other access tokens at the same time, and when a plurality of access tokens are retained in the user device, the second hardware processor compares the data associated with the plurality of access tokens, and transmits an access token with a highest priority to the server; wherein the first hardware processor authenticates the user by handling both the new access token and an old access token as valid access tokens during a period from issuance of the new access token to expiration of a time of expiration of the old access token. 2. The system according to claim 1 , wherein the determination information receiving unit receives, from the server, the remaining time until the time of expiration of the access token as the determination information. 3. The system according to claim 1 , the server further comprising a token generating unit to generate an access token using identification information of the user device and time of expiration related information that is related to a time of expiration of the access token, wherein the first hardware processor authenticates the user by determining whether or not the access token received from the user device is the access token that is generated using the identification information of the user device and the time of expiration related information.
using time-dependent-passwords, e.g. periodically changing passwords · CPC title
using one-time-passwords · CPC title
User authentication · CPC title
using certificates · CPC title
Structures or tools for the administration of authentication · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.