Invention Grant
- Patent Title: Secure token refresh
-
Application No.: US16818312Application Date: 2020-03-13
-
Publication No.: US11463258B2Publication Date: 2022-10-04
- Inventor: Anand Baldeodas Bahety
- Applicant: eBay Inc.
- Applicant Address: US CA San Jose
- Assignee: eBay Inc.
- Current Assignee: eBay Inc.
- Current Assignee Address: US CA San Jose
- Agency: Shook, Hardy & Bacon LLP
- Main IPC: H04L9/32
- IPC: H04L9/32 ; H04L9/30 ; H04L9/40

Abstract:
Technologies are shown for secure token refresh where a client receives a first access token from an authentication service, generates an asymmetric key pair, stores the first access token in association with a private key, and sends a public key to the authentication service. The service stores the public key in association with the first access token. The client sends a refresh token request to the service with the first access token. The service responds with a verification request with proof data. The client signs the proof data with the private key and sends the signed proof data to the service. The service verifies the signed proof data using the public key associated with the first access token, creates a second access token that is stored in association with the public key, and sends the second access token to the client, which stores it in association with the private key.
Public/Granted literature
- US20210288808A1 SECURE TOKEN REFRESH Public/Granted day:2021-09-16
Information query