IP Library Granted Patent US 10,454,945
Granted Patent B1
US 10,454,945 · App. 15/495,105 · Granted Oct 22, 2019

Method, apparatus and computer program product for processing an electronic request to access a computerized resource

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,454,945
App. No.
15/495,105
Granted
Oct 22, 2019
Kind
B1
Abstract

Techniques are disclosed for use in authentication. In one embodiment, a method is disclosed. The method comprises receiving an electronic request to access a computerized resource. The electronic request comprises a user identifier identifying a user associated with the electronic request and a first access token. The method comprises retrieving, in response to receiving the electronic request, a time-varying token seed associated with the generation of access tokens during a time period. The time-varying token seed is different if retrieved after the expiration of the time period. The method comprises generating a second access token based on the time-varying token seed and the user identifier identifying the user. The method comprises comparing the first and second access tokens to determine a similarity between the respective access tokens. The method comprises determining whether to allow the user access to the computerized resource based on the similarity between the access tokens.

Claims (45)

1. A method, comprising:

receiving, by processing circuitry, an electronic request to access a computerized resource, wherein the electronic request comprises a user identifier identifying a user associated with the electronic request, a first access token, and an index value;

in response to receiving the electronic request, retrieving, by processing circuitry, a token seed associated with the index value from a data source;

generating, by processing circuitry, a second access token based on the retrieved token seed and the user identifier identifying the user;

comparing, by processing circuitry, the first and second access tokens to determine a similarity between the respective access tokens;

based on the similarity between the respective access tokens, determining, by processing circuitry, whether to allow the user access to the computerized resource;

wherein the data source comprises a plurality of entries, each entry including an index value and a token seed for use in access token generation during discrete time periods, each entry being updated upon the expiration of the discrete time period related thereto such that the token seed is replaced with a different token seed but the index value remains the same;

further wherein retrieving a token seed associated with the index value from the data source, comprises:

identifying the entry associated with the index value; and

returning the token seed in the identified entry for use in the generation of the second access token.

2. The method as claimed in claim 1 , wherein the first access token as received represents an access token previously generated for the user for enabling temporary access of the computerized resource.

3. The method as claimed in claim 1 , wherein the first access token corresponds to a hash value resulting from the hashing of the user identifier and a token seed used for access token generation during a time period and that is different after the expiration of the time period.

4. The method as claimed in claim 3 , wherein the token seed used to generate the first access token is the same as the token seed used to generate the second access token when the time period associated with the token seed used to generate the first access token has not expired at the time of retrieval of the token seed.

5. The method as claimed in claim 3 , wherein the token seed used to generate the first access token is different to the token seed used to generate the second access token when the time period associated with the token seed used to generate the first access token has expired at the time of retrieval of the token seed.

6. The method as claimed in claim 1 , wherein generating the second access token comprises hashing the user identifier and the retrieved token seed.

7. An apparatus, comprising:

memory; and

processing circuitry coupled to the memory, the memory storing instructions which, when executed by the processing circuitry, cause the processing circuitry to:

receive an electronic request to access a computerized resource, wherein the electronic request comprises a user identifier identifying a user associated with the electronic request, a first access token, and an index value;

in response to receiving the electronic request, retrieve a token seed associated with the index value from a data source;

generate a second access token based on the retrieved token seed and the user identifier identifying the user;

compare the first and second access tokens to determine a similarity between the respective access tokens;

based on the similarity between the respective access tokens, determine whether to allow the user access to the computerized resource;

wherein the data source comprises a plurality of entries, each entry including an index value and a token seed for use in access token generation during discrete time periods, each entry being updated upon the expiration of the discrete time period related thereto such that the token seed is replaced with a different token seed but the index value remains the same;

further wherein retrieving a token seed associated with the index value from the data source, comprises:

identifying the entry associated with the index value; and

returning the token seed in the identified entry for use in the generation of the second access token.

8. The apparatus as claimed in claim 7 , wherein the first access token as received represents an access token previously generated for the user for enabling temporary access of the computerized resource.

9. The apparatus as claimed in claim 7 , wherein the first access token corresponds to a hash value resulting from the hashing of the user identifier and a token seed used for access tokens generation during a time period and that is different after the expiration of the time period.

10. The apparatus as claimed in claim 9 , wherein the token seed used to generate the first access token is the same as the token seed used to generate the second access token when the time period associated with the token seed used to generate the first access token has not expired at the time of retrieval of the token seed.

11. The apparatus as claimed in claim 9 , wherein the token seed used to generate the first access token is different to the token seed used to generate the second access token when the time period associated with the token seed used to generate the first access token has expired at the time of retrieval of the token seed.

12. The apparatus as claimed in claim 7 , wherein generating the second access token comprises hashing the user identifier and the retrieved token seed.

13. A computer program product having a non-transitory computer readable medium which stores a set of instructions, the set of instructions, when carried out by processing circuitry, causing the processing circuitry to perform a method of:

receiving an electronic request to access a computerized resource, wherein the electronic request comprises a user identifier identifying a user associated with the electronic request, a first access token, and an index value;

in response to receiving the electronic request, retrieving a token seed associated with the index value from a data source;

generating a second access token based on the retrieved token seed and the user identifier identifying the user;

comparing the first and second access tokens to determine a similarity between the respective access tokens;

based on the similarity between the respective access tokens, determining whether to allow the user access to the computerized resource;

wherein the data source comprises a plurality of entries, each entry including an index value and a token seed for use in access token generation during discrete time periods, each entry being updated upon the expiration of the discrete time period related thereto such that the token seed is replaced with a different token seed but the index value remains the same;

further wherein retrieving a token seed associated with the index value from the data source, comprises:

identifying the entry associated with the index value; and

returning the token seed in the identified entry for use in the generation of the second access token.

14. The computer program product as claimed in claim 13 , wherein the first access token as received represents an access token previously generated for the user for enabling temporary access of the computerized resource.

15. The computer program product as claimed in claim 13 , wherein the first access token corresponds to a hash value resulting from the hashing of the user identifier and a token seed used for access tokens generation during a time period and that is different after the expiration of the time period.

16. The computer program product as claimed in claim 15 , wherein the token seed used to generate the first access token is the same as the token seed used to generate the second access token when the time period associated with the token seed used to generate the first access token has not expired at the time of retrieval of the token seed.

Assignments (7)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (042769/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO WYSE TECHNOLOGY L.L.C.)
Reel/Frame 059803/0802 →
RELEASE OF SECURITY INTEREST AT REEL 042768 FRAME 0585 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; MOZY, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058297/0536 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
PATENT SECURITY INTEREST (CREDIT) Recorded Jun 12, 2017
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; MOZY, INC.; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 042768/0585 →
PATENT SECURITY INTEREST (NOTES) Recorded Jun 12, 2017
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; MOZY, INC.; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 042769/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 24, 2017
From: RAMAN, HAIM; SCHOENBRUN, YIHEZKEL; ROSCHAK, JULIA; SORANI, ITZIK; VARDY, TAMAR; PERES, MIKAEL
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 042128/0353 →
Cited By (1)
US 12,437,040