Invention Grant
- Patent Title: Securing authorization tokens using client instance specific secrets
-
Application No.: US15622834Application Date: 2017-06-14
-
Publication No.: US10972273B2Publication Date: 2021-04-06
- Inventor: Anand Baldeodas Bahety , Nebojsa Pesic , Mallikarjuna Potta
- Applicant: eBay Inc.
- Applicant Address: US CA San Jose
- Assignee: eBay Inc.
- Current Assignee: eBay Inc.
- Current Assignee Address: US CA San Jose
- Agency: Shook, Hardy & Bacon LLP
- Main IPC: H04L9/32
- IPC: H04L9/32 ; G06Q20/40 ; H04L29/06 ; G06Q20/38 ; G06Q30/06 ; H04L9/08

Abstract:
A system, method, and computer program product are provided for securing authorization tokens using client instance specific secrets. Tokens are valid for service requests only if time constraints and additional security constraints are met by additional information stored in the token in hashed form. A required comparison of a timestamp in a client service request header to the current server time limits the useful token life, e.g., to a few minutes. The service request header also includes data generated based on a secret previously assigned to a specific client instance. The secret may be generated by the server according to a public/private key scheme and sent to a particular client instance only once, e.g., during initial device registration. The secret may be omitted from service requests for public information. Service request headers may include device identifiers, so that service requests from known rogue clients may be ignored.
Public/Granted literature
- US20180367306A1 SECURING AUTHORIZATION TOKENS USING CLIENT INSTANCE SPECIFIC SECRETS Public/Granted day:2018-12-20
Information query