IP Library Granted Patent US 10,158,626
Granted Patent B1
US 10,158,626 · App. 15/624,731 · Granted Dec 18, 2018

Token-based access control

Inventors: Zi Lian Ji (Shanghai, CN); Ping Li (Shanghai, CN); Yong Chao Li (Shanghai, CN); Xian Dong Meng (Shanghai, CN); Zhao Li Wang (Shanghai, CN)
Assignee: International Business Machines Corporation
H04L63/083G06F3/065G06F3/0619G06F3/0685H04B10/116H04L9/3213H04L9/3297
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,158,626
App. No.
15/624,731
Granted
Dec 18, 2018
Kind
B1
Abstract

Implementations of the present disclosure relate to methods, systems and products for access control. In one implementation, a computer-implemented method is proposed. According to the method, a token for accessing an object is received from a terminal device via a communication channel, where the communication channel is built based on a Light Fidelity connection which is deployed within a restrictive area. A validity of the received token is determined. An access to the object is controlled based on the validity of the received token.

Claims (62)

1. A computer-implemented method, comprising:

receiving an access request, from a control application on a terminal device, for accessing an object via a Light Fidelity (LiFi) connection which is deployed within a first restrictive area;

loading a token on the terminal device for accessing the object, via a communication channel, if the access request is accepted, wherein the token comprises one or more user privileges based on a unique username and password associated with the received request;

determining the one or more user privileges based on a unique identification associated with a received access request from a control application on the terminal device;

generating the token based on the one or more user privileges;

sending the generated token to the terminal device;

determining a validity of the received token from the terminal device;

controlling an access to the object based on the validity of the received token;

requiring a user to enter a valid password on the terminal device, in response to receiving a further accessing request;

updating the one or more user privileges;

updating the token based on the updated one or more user privileges;

sending the updated token to the terminal device; and

building a further communication channel, based on a second LiFi connection, which is deployed within a second restrictive area, pursuant to the updated one or more user privileges.

2. The method of claim 1 , further comprising:

saving a copy of the generated token.

3. The method of claim 2 , wherein determining the validity of the received token further comprises:

in response to the received token matching the saved copy, identifying the validity as valid; and

in response to a timestamp of the received token being expired, identifying the validity as invalid.

4. The method of claim 2 , further comprising:

in response to the communication channel being disconnected, identifying the validity of the saved copy as invalid.

5. A computer-implemented system for controlling access to an object comprising:

one or more computer devices each having one or more processors and one or more tangible devices; and

a program embodied on at least one of one or more storage devices, the program having a plurality of program instructions for execution by the one or more processors, the program instructions comprising instructions for:

receiving, by the computer, an access request, from a control application on a terminal device, for accessing an object via a Light Fidelity (LiFi) connection which is deployed within a first restrictive area;

loading, by the computer, a token on the terminal device for accessing the object, via a communication channel, if the access request is accepted, wherein the token comprises one or more user privileges based on a unique username and password associated with the received request;

determining, by the computer, the one or more user privileges based on a unique identification associated with a received access request from a control application on the terminal device;

generating, by the computer, the token based on the one or more user privileges;

sending, by the computer, the generated token to the terminal device;

determining, by the computer, a validity of the received token from the terminal device;

controlling, by the computer, an access to the object based on the validity of the received token;

requiring, by the computer, a user to enter a valid password on the terminal device, in response to receiving a further accessing request;

updating, by the computer, the one or more user privileges;

updating, by the computer, the token based on the updated one or more user privileges;

sending, by the computer, the updated token to the terminal device; and

building, by the computer, a further communication channel, based on a second LiFi connection, which is deployed within a second restrictive area, pursuant to the updated one or more user privileges.

6. The computer-implemented system of claim 5 , wherein the program instructions further comprise instructions for:

saving, by the computer, a copy of the generated token.

7. The computer-implemented system of claim 6 , wherein determining a validity of the received token further comprises:

in response to the received token matching the saved copy, identifying, by the computer, the validity as valid; and

in response to a timestamp of the received token being expired, identifying, by the computer, the validity as invalid.

8. The computer-implemented system of claim 6 , wherein the program instructions further comprise instructions for:

in response to the communication channel being disconnected, identifying, by the computer, a validity of the saved copy as invalid.

9. A computer program product for controlling access to an object, comprising a non-transitory tangible storage device having program code embodied therewith, the program code executable by a processor of an electronic device to perform a method, the method comprising:

receiving, by the processor, an access request, from a control application on a terminal device, for accessing an object via a Light Fidelity (LiFi) connection which is deployed within a first restrictive area;

loading, by the processor, a token on the terminal device for accessing the object, via a communication channel, if the access request is accepted, wherein the token comprises one or more user privileges based on a unique username and password associated with the received request;

determining, by the processor, the one or more user privileges based on a unique identification associated with a received access request from a control application on the terminal device;

generating, by the processor, the token based on the one or more user privileges;

sending, by the processor, the generated token to the terminal device;

determining, by the processor, a validity of the received token from the terminal device;

controlling, by the processor, an access to the object based on the validity of the received token;

requiring, by the processor, a user to enter a valid password on the terminal device, in response to receiving a further accessing request;

updating, by the processor, the one or more user privileges;

updating, by the processor, the token based on the updated one or more user privileges;

sending, by the processor, the updated token to the terminal device; and

building, by the processor, a further communication channel, based on a second LiFi connection, which is deployed within a second restrictive area, pursuant to the updated one or more user privileges.

10. The computer program product of claim 9 , wherein the method further comprises:

saving, by the processor, a copy of the generated token.

11. The computer program product of claim 10 , wherein the method further comprises:

in response to the received token matching the saved copy, identifying, by the processor, the validity as valid; and

in response to a timestamp of the received token being expired, identifying, by the processor, the validity as invalid.

12. The computer program product of claim 10 , wherein the method further comprises:

in response to the communication channel being disconnected, identifying, by the processor, a validity of the saved copy as invalid.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2017
From: JI, ZI LIAN; LI, PING; LI, YONG CHAO; MENG, XIAN DONG; WANG, ZHAO LI
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 042728/0817 →
Cited By (1)
US 12,191,909