Access token management

US9646151B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9646151-B2
Application numberUS-201514713786-A
CountryUS
Kind codeB2
Filing dateMay 15, 2015
Priority dateJan 30, 2015
Publication dateMay 9, 2017
Grant dateMay 9, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Provided is a server including: a user authenticating unit that authenticates, using an access token, a user of a user device; a token receiving unit that receives an access token from the user device; and a determination information transmitting unit which, when the access token is received, transmits determination information that enables a determination as to whether or not a remaining time until a time of expiration of the access token is less than a predetermined threshold, to the user device, wherein the user authenticating unit issues a new access token with an updated time of expiration when an issuance request for an access token which is transmitted by the user device having received the determination information is received.

First claim

Opening claim text (preview).

What is claimed is: 1. A system comprising a server and a user device which are connected to each other via a network, the server including: a first hardware processor to authenticate, using an access token, a user of a user device connected via the network; the first hardware processor to receive an access token from the user device; and the first hardware processor to transmit, when the access token is received, determination information that enables a determination as to whether or not a remaining time until a time of expiration of the access token from a time of the determination is less than a predetermined threshold, to the user device, and the user device including: a second hardware processor to transmit an authentication request to the server; the second hardware processor to transmit the access token to the server; the second hardware processor to receive the determination information from the server; the second hardware processor to determine, when the determination information is received, whether or not a remaining time until a time of expiration of the access token is less than a predetermined threshold; the second hardware processor to transmit an issuance request for an access token when the remaining time until the time of expiration of the access token is determined to be less than the predetermined threshold; and a token managing unit to, when receiving a new access token, validate the new access token and invalidating an old access token, wherein the first hardware processor issues a new access token with an updated time of expiration when an issuance request for an access token which is transmitted by the user device having received the determination information is received, the token managing unit associates, with a plurality of access tokens retained in the user device, data which enables priorities among the access tokens to be compared, and when the new access token is received, associates the new access token with the data including a value that has a higher priority than other access tokens in order to validate the new access token and invalidate the other access tokens at the same time, and when a plurality of access tokens are retained in the user device, the second hardware processor compares the data associated with the plurality of access tokens, and transmits an access token with a highest priority to the server; wherein the first hardware processor authenticates the user by handling both the new access token and an old access token as valid access tokens during a period from issuance of the new access token to expiration of a time of expiration of the old access token. 2. The system according to claim 1 , wherein the determination information receiving unit receives, from the server, the remaining time until the time of expiration of the access token as the determination information. 3. The system according to claim 1 , the server further comprising a token generating unit to generate an access token using identification information of the user device and time of expiration related information that is related to a time of expiration of the access token, wherein the first hardware processor authenticates the user by determining whether or not the access token received from the user device is the access token that is generated using the identification information of the user device and the time of expiration related information.

Assignees

Inventors

Classifications

  • using time-dependent-passwords, e.g. periodically changing passwords · CPC title

  • using one-time-passwords · CPC title

  • User authentication · CPC title

  • using certificates · CPC title

  • G06F21/45Primary

    Structures or tools for the administration of authentication · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9646151B2 cover?
Provided is a server including: a user authenticating unit that authenticates, using an access token, a user of a user device; a token receiving unit that receives an access token from the user device; and a determination information transmitting unit which, when the access token is received, transmits determination information that enables a determination as to whether or not a remaining time …
Who is the assignee on this patent?
Pfu Ltd
What technology area does this patent fall under?
Primary CPC classification H04L63/0838. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue May 09 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 3 related publications on this page (citations in our corpus or others sharing the same primary CPC).