IP Library Granted Patent US 11,017,063
Granted Patent B2
US 11,017,063 · App. 16/240,604 · Granted May 25, 2021

Authority revoking method and device

Inventor: Dong Chen (Hangzhou, CN)
Assignee: Advanced New Technologies Co., Ltd.
G06F21/31G06F16/00G06F21/30G06F21/6218H04L9/08H04L63/068H04L63/0807H04L9/0891
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,017,063
App. No.
16/240,604
Granted
May 25, 2021
Kind
B2
Abstract

An authorizing party determines an authorization record set that needs to be revoked, where an authorization record included in the authorization record set corresponds to a token that is issued to an authorized party after the authorizing party grants access to the authorized party, and where each authorization record includes an authorization validation moment for a corresponding token. A time validity attribute of the authorization record set is configured. For a specific point-in-time, a value associated with the time validity attribute is set. A determination is performed as to whether the authorization record is revoked based on the authorization validation moment and the value associated with the time validity attribute.

Claims (65)

1. A computer-implemented method, comprising:

receiving, by an authorizing party and from an application, a plurality of first access requests to a service provided by the authorizing party;

determining, by the authorizing party, that the application is granted access to the service;

issuing, by the authorizing party and to the application, a plurality of tokens;

determining, by the authorizing party, an authorization record set that needs to be revoked, wherein the authorization record set includes a plurality of authorization records, wherein each authorization record included in the authorization record set corresponds to the corresponding token that is issued to an authorized party after the authorizing party grants access to the authorized party, and wherein each authorization record includes an authorization validation moment for the corresponding token;

configuring a time validity attribute of the authorization record set;

setting, to a specific point-in-time, a value of the time validity attribute of the authorization record set, comprising:

determining a next earliest authorization validation moment associated with the authorization records in the authorization record set that need to be revoked; and

setting the value of the time validity attribute to a future moment, wherein the future moment is earlier than the next earliest authorization validation moment, and wherein the future moment is set to a range between a latest authorization validation moment and the next earliest authorization validation moment;

revoking in batches all the authorization records in the authorization record set whenever the authorization validation moment of each authorization record is earlier than the value of the time validity attribute of the authorization record set;

receiving, by the authorizing party, a second access request from the application for accessing the service, wherein the second access request comprises a particular token comprised in the plurality of tokens issued to the application;

obtaining, by the authorizing party, the authorization validation moment of the authorization record corresponding to the particular token;

obtaining, by the authorizing party, the value of the time validity attribute of the authorization record set;

determining, by the authorizing party, that the authorization validation moment of the authorization record is earlier than the value of the time validity attribute of the authorization record set; and

in response, rejecting the second access request from the application for accessing the service.

2. The computer-implemented method of claim 1 , further comprising, prior to revoking in batches all the authorization records:

determining whether a validity attribute value associated with the authorization record is valid.

3. The computer-implemented method of claim 1 , further comprising revoking in batches all the authorization records in the authorization record set by setting the value of the time validity attribute to a current moment.

4. The computer-implemented method of claim 1 , wherein the authorization record set is configured with another time validity attribute, and wherein the time validity attribute is set to a first value and the other time validity attribute is set to a second value, so that the authorization record is revoked:

if an authorization validation time is earlier than the first value; or

if the authorization validation time is later than the second value.

5. A non-transitory, computer-readable medium storing one or more instructions executable by a computer system to perform operations comprising:

receiving, by an authorizing party and from an application, a plurality of first access requests to a service provided by the authorizing party;

determining, by the authorizing party, that the application is granted access to the service;

issuing, by the authorizing party and to the application, a plurality of tokens;

determining, by the authorizing party, an authorization record set that needs to be revoked, wherein the authorization record set includes a plurality of authorization records, wherein each authorization record included in the authorization record set corresponds to the corresponding token that is issued to an authorized party after the authorizing party grants access to the authorized party, and wherein each authorization record includes an authorization validation moment for the corresponding token;

configuring a time validity attribute of the authorization record set;

setting, to a specific point-in-time, a value of the time validity attribute of the authorization record set, comprising:

determining a next earliest authorization validation moment associated with the authorization records in the authorization record set that need to be revoked; and

setting the value of the time validity attribute to a future moment, wherein the future moment is earlier than the next earliest authorization validation moment, and wherein the future moment is set to a range between a latest authorization validation moment and the next earliest authorization validation moment;

revoking in batches all the authorization records in the authorization record set whenever the authorization validation moment of each authorization record is earlier than the value of the time validity attribute of the authorization record set;

receiving, by the authorizing party, a second access request from the application for accessing the service, wherein the second access request comprises a particular token comprised in the plurality of tokens issued to the application;

obtaining, by the authorizing party, the authorization validation moment of the authorization record corresponding to the particular token;

obtaining, by the authorizing party, the value of the time validity attribute of the authorization record set;

determining, by the authorizing party, that the authorization validation moment of the authorization record is earlier than the value of the time validity attribute of the authorization record set; and

in response, rejecting the second access request from the application for accessing the service.

6. The non-transitory, computer-readable medium of claim 5 , wherein the operations further comprise, prior to revoking in batches all the authorization records:

determining whether a validity attribute value associated with the authorization record is valid.

7. The non-transitory, computer-readable medium of claim 5 , wherein the operations further comprise revoking in batches all the authorization records in the authorization record set by setting the value of the time validity attribute to a current moment.

8. The non-transitory, computer-readable medium of claim 5 , wherein the authorization record set is configured with another time validity attribute, and wherein the time validity attribute is set to a first value and the other time validity attribute is set to a second value, so that the authorization record is revoked:

if an authorization validation time is earlier than the first value; or

if the authorization validation time is later than the second value.

9. A computer-implemented system, comprising:

one or more computers; and

one or more computer memory devices interoperably coupled with the one or more computers and having tangible, non-transitory, machine-readable media storing one or more instructions that, when executed by the one or more computers, perform one or more operations comprising:

receiving, by an authorizing party and from an application, a plurality of first access requests to a service provided by the authorizing party;

determining, by the authorizing party, that the application is granted access to the service;

issuing, by the authorizing party and to the application, a plurality of tokens;

determining, by the authorizing party, an authorization record set that needs to be revoked, wherein the authorization record set includes a plurality of authorization records, wherein each authorization record included in the authorization record set corresponds to the corresponding token that is issued to an authorized party after the authorizing party grants access to the authorized party, and wherein each authorization record includes an authorization validation moment for the corresponding token;

configuring a time validity attribute of the authorization record set;

setting, to a specific point-in-time, a value of the time validity attribute of the authorization record set, comprising:

determining a next earliest authorization validation moment associated with the authorization records in the authorization record set that need to be revoked; and

setting the value of the time validity attribute to a future moment, wherein the future moment is earlier than the next earliest authorization validation moment, and wherein the future moment is set to a range between a latest authorization validation moment and the next earliest authorization validation moment;

revoking in batches all the authorization records in the authorization record set whenever the authorization validation moment of each authorization record is earlier than the value of the time validity attribute of the authorization record set;

receiving, by the authorizing party, a second access request from the application for accessing the service, wherein the second access request comprises a particular token comprised in the plurality of tokens issued to the application;

obtaining, by the authorizing party, the authorization validation moment of the authorization record corresponding to the particular token;

obtaining, by the authorizing party, the value of the time validity attribute of the authorization record set;

determining, by the authorizing party, that the authorization validation moment of the authorization record is earlier than the value of the time validity attribute of the authorization record set; and

in response, rejecting the second access request from the application for accessing the service.

10. The computer-implemented system of claim 9 , wherein the operations further comprise, prior to revoking in batches all the authorization records:

determining whether a validity attribute value associated with the authorization record is valid.

11. The computer-implemented system of claim 9 , wherein the operations further comprise revoking in batches all the authorization records in the authorization record set by setting the value of the time validity attribute to a current moment.

12. The computer-implemented system of claim 9 , wherein the authorization record set is configured with another time validity attribute, and wherein the time validity attribute is set to a first value and the other time validity attribute is set to a second value, so that the authorization record is revoked:

if an authorization validation time is earlier than the first value; or

if the authorization validation time is later than the second value.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 21, 2024
From: ADVANCED NEW TECHNOLOGIES CO., LTD.
To: ADVANCED NOVA TECHNOLOGIES (SINGAPORE) HOLDING PTE. LTD.
Reel/Frame 066862/0668 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 10, 2020
From: ADVANTAGEOUS NEW TECHNOLOGIES CO., LTD.
To: ADVANCED NEW TECHNOLOGIES CO., LTD.
Reel/Frame 053754/0625 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 31, 2020
From: ALIBABA GROUP HOLDING LIMITED
To: ADVANTAGEOUS NEW TECHNOLOGIES CO., LTD.
Reel/Frame 053743/0464 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 10, 2019
From: CHEN, DONG
To: ALIBABA GROUP HOLDING LIMITED
Reel/Frame 049145/0682 →