- 专利标题: Secure token refresh
-
申请号: US17895305申请日: 2022-08-25
-
公开(公告)号: US11824992B2公开(公告)日: 2023-11-21
- 发明人: Anand Baldeodas Bahety
- 申请人: eBay Inc.
- 申请人地址: US CA San Jose
- 专利权人: eBay Inc.
- 当前专利权人: eBay Inc.
- 当前专利权人地址: US CA San Jose
- 代理机构: SHOOK, HARDY & BACON L.L.P.
- 主分类号: H04L9/32
- IPC分类号: H04L9/32 ; H04L9/30 ; H04L9/40
摘要:
Technologies are shown for secure token refresh where a client receives a first access token from an authentication service, generates an asymmetric key pair, stores the first access token in association with a private key, and sends a public key to the authentication service. The service stores the public key in association with the first access token. The client sends a refresh token request to the service with the first access token. The service responds with a verification request with proof data. The client signs the proof data with the private key and sends the signed proof data to the service. The service verifies the signed proof data using the public key associated with the first access token, creates a second access token that is stored in association with the public key, and sends the second access token to the client, which stores it in association with the private key.
公开/授权文献
- US20220407713A1 SECURE TOKEN REFRESH 公开/授权日:2022-12-22
信息查询