Delegating authorizations

US9648003B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9648003-B2
Application numberUS-201514604509-A
CountryUS
Kind codeB2
Filing dateJan 23, 2015
Priority dateNov 5, 2013
Publication dateMay 9, 2017
Grant dateMay 9, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Delegating authorizations sufficient to access services is contemplate. The authorization may be delegated in the form of a token or other transmissible construct relied upon to authenticate access to services, such as but not necessarily limited to conferring a user identity established via authenticated device for the purposes of enabling an unauthenticated or unsecured device to access a service associated with the user identity.

First claim

Opening claim text (preview).

What is claimed is: 1. A method for delegating access tokens relied upon to authenticate access to services, the method comprising: receiving a plurality of access tokens from a plurality of service providers after the plurality of service providers associates each of the plurality of access tokens with at least one of a plurality of users; receiving a first credential from a control device generated in response to the control device interacting with an sink device while the sink device is being engaged to access a first services associated with a first service provider of the plurality of service providers at a first instance in time; identifying a first access token of the plurality of access tokens associated with a first user of the plurality of users as a function of information included within the first credential; and transmitting the first access token to the first service provider at a second instance in time occurring after the first instance in time, the first service provider granting the sink device access to the first service at the second instance in time according to entitlements of the first user if the first access token is valid when received, thereby enabling the sink device to access the first service without providing the first access token to the service provider. 2. The method of claim 1 further comprising determining an address to be used in transmitting the first access token to the first service provider as a function of information included within the first credential. 3. The method of claim 2 further comprising determining at least a portion of the information included in the first credential as a result of the sink device determining an indicator displayed on the control device having an indicia sufficient for identifying the first service provider. 4. The method of claim 3 further comprising instructing an identifier application on the control device to determine the indicia by processing an image of the indicator captured with a camera of the control device. 5. The method of claim 4 further comprising instructing the first user to capture the image by positioning the camera to take a picture of a webpage associated with the first service provider, the webpage displaying the indicator proximate to input fields operable to receive a username and a password sufficient to enable the first user to access the first service without use of the first access token. 6. The method of claim 5 further comprising transmitting a redirect message to a browser operating on the sink device to display the webpage sufficient to automatically direct the browser to a service page used to engage the first service without having to input the username and the password. 7. The method of claim 1 further comprising: updating the first access token after being determined as invalid with a second access token received from the first service provider at a third instance in time occurring after the second instance in time; receiving a second credential from the control device generated in response to the control device interacting with the sink device while the sink device is being engaged to access the first service at a fourth instance in time occurring after the third instance in time; and transmitting the second access token to the first service provider at a fifth instance in time occurring after the fourth instance in time as a function of information included within the second credential, the first service provider granting the sink device access to the first service at the fifth instance in time if the second access token is valid when received, thereby enabling the sink device to access the first service without providing the second access token to the service provider. 8. The method of claim 1 further comprising: receiving a second credential from the control device generated in response to the control device interacting with the sink device while the sink device is being engaged to access the first service at a third instance in time occurring after the second instance in time; determining the second credential to be one of authenticated and unauthenticated at a fourth instance in time occurring after the third instance in time, including determining the second credential to be authenticated if the control device successful completed an authentication process at a fifth instance in time occurring prior to the third instance in time and to be unauthenticated if the control device unsuccessfully completed the authentication process at the fifth instance in time; transmitting the first access token to the first service provider at a sixth instance in time occurring after to the fourth instance in time if the second credential is determined to be authenticated, the first service provider granting the sink device access to the first service at the sixth instance in time if the first access token is valid when received; and instructing the control device to display a login message to the first user in the event the second credential is determined to be unauthenticated, the login message instructing the first user to input a username and a password or other sufficient authentication to a webpage displayed on the sink device to facilitate access to the first service at the sixth instance in time. 9. A non-transitory computer-readable medium having a plurality of non-transitory instructions operable with a processor associated with a service provider to facilitate access to services, the non-transitory instructions being sufficient for: associating a plurality of users with one or more of a plurality of access tokens, each access token authenticating the corresponding user for access to at least one of a plurality of services offered by the service provider; associating at least one of a plurality of indicators with each of the plurality of services, each indicator being sufficient to uniquely identify the service associated therewith; associating a first indicator of the plurality of indicators with a sink device attempting to access the first service, the first indicator uniquely identifying a first service of the plurality of services; and enabling the sink device access to the first service according to a first user of the plurality of users associated with a first access token of the plurality of access tokens, including determining the first access token in response to a control device generating a credential having information sufficient to identify the first user and the first service, the control device identifying the first service after interacting with the first indicator associated with the sink device. 10. The non-transitory computer-readable medium of claim 9 further comprising non-transitory instructions sufficient for transmitting the plurality of access tokens to a server in communication with the control device. 11. The non-transitory computer-readable medium of claim 10 further comprising non-transitory instructions sufficient for enabling the sink device access to the first service following receipt of an access message from the server, the access message being generated according to information included in the credential transmitted from the control device to include the first access token and an address of the sink device. 12. The non-transitory computer-readable medium of claim 11 further comprising non-transitory instructions sufficient for transmitting access instructions to the sink device to access the first service therethrough, including identifying the sink device to receive the access instructions as a function of the address included with the access message. 13. The non-transitory computer readable medium of cla

Assignees

Inventors

Classifications

  • using tickets or tokens, e.g. Kerberos (network architectures or network communication protocols for entities authentication using tickets in a packet data network H04L63/0807) · CPC title

  • using passwords (cryptographic mechanisms or cryptographic arrangements for entity authentication using a predetermined code H04L9/3226) · CPC title

  • based on web technology, e.g. hypertext transfer protocol [HTTP] · CPC title

  • providing single-sign-on or federations · CPC title

  • H04L63/10Primary

    for controlling access to devices or network resources · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9648003B2 cover?
Delegating authorizations sufficient to access services is contemplate. The authorization may be delegated in the form of a token or other transmissible construct relied upon to authenticate access to services, such as but not necessarily limited to conferring a user identity established via authenticated device for the purposes of enabling an unauthenticated or unsecured device to access a ser…
Who is the assignee on this patent?
Cable Television Laboratories Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/10. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue May 09 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).