Invention Grant
- Patent Title: Refresh token for credential renewal
-
Application No.: US16704985Application Date: 2019-12-05
-
Publication No.: US10951618B2Publication Date: 2021-03-16
- Inventor: Graeme David Baer , Dmitry Frenkel , Marc R. Barbour
- Applicant: Amazon Technologies, Inc.
- Applicant Address: US NV Reno
- Assignee: Amazon Technologies, Inc.
- Current Assignee: Amazon Technologies, Inc.
- Current Assignee Address: US NV Reno
- Agency: Hogan Lovells US LLP
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
Security credentials issued by an entity, such as an identity broker, can have a limited lifetime. Access to resources or content under those credentials then can only be obtained for a limited period of time, limiting the ability of an unauthorized entity obtaining the credentials to utilize those credentials for access. Along with the credentials, a refresh token can be issued to a requesting client that can enable the limited lifetime of the credentials to be renewed up to a maximum lifetime of the credentials and/or the token. A service providing access can determine that the client has a valid copy of the refresh token when the credentials are about to expire, and if so can cause the lifetime of the credentials to be extended another credential lifetime. This renewal can be done transparent to a user and without again contacting the identity broker.
Public/Granted literature
- US20200153831A1 REFRESH TOKEN FOR CREDENTIAL RENEWAL Public/Granted day:2020-05-14
Information query