System and method for hardening security between web services using protected forwarded access tokens
US11121873B2 · kind B2 · utility
Assignee
Inventors
Key dates
| Filing date | Feb 8, 2019 |
| Grant date | Sep 14, 2021 |
| Priority date | — |
| Expiry date | May 18, 2039 |
Classification
- Technology area (CPC H)Electricity
- CPC primaryH04L9/3271
- WIPO fieldDigital communication
- WIPO sectorElectrical engineering
Abstract
Methods for hardening security between web services using protected forwarded access tokens are implemented via systems and devices. User applications receive user tokens with user information from an identity provider and provide the user tokens to first services with data requests. Each first service extracts and transforms a portion of a user token to validate a user token signature, and determines a target service for the data request. The first services acquire actor tokens from the identity provider that uniquely identify the first services using public keys, and then generate authentication tokens, signed with corresponding private keys, that encapsulate the actor tokens and the transformed user tokens. The signed authentication tokens are provided to target services which validate the authentication tokens as well as the encapsulated tokens and their respective signatures. Upon validation, requested data is retrieved and provided back for the user applications from the target services.
Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.