IP Library Granted Patent US 11,431,493
Granted Patent B1
US 11,431,493 · App. 16/245,078 · Granted Aug 30, 2022

Systems and methods for secure authentication

Inventors: Kevin Lewi (Mountain View, CA); Yue Ting Lee (Menlo Park, CA); Haozhi Xiong (Fremont, CA); Benjamin B. Yang (Menlo Park, CA)
Assignee: Meta Platforms, Inc.
H04L9/0866H04L9/0869H04L9/3242H04L9/3263H04L63/0884
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,431,493
App. No.
16/245,078
Granted
Aug 30, 2022
Kind
B1
Abstract

Systems, methods, and non-transitory computer-readable media can be configured to generate a first key for a first entity. A second key for a second entity can be generated wherein the first entity can authenticate the second entity based on an authentication token generated based on the second key. In some instances, the first entity can be a server and the second entity can be a client.

Claims (26)

1. A computer-implemented method comprising:

generating, by a computing system, a first key for a first server entity associated with a first backend service of a social networking system; and

generating, by the computing system, a second key for a second entity, wherein the second entity is a client and the first backend service can authenticate the second entity and a request by the second entity based on an authentication token generated based on the second key, wherein the request by the second entity is provided to the backend service through an intermediary, and wherein the intermediary and the first backend service are controlled by a common entity.

2. The computer-implemented method of claim 1 , wherein the first key is generated based in part on an identity associated with the first server entity.

3. The computer-implemented method of claim 2 , wherein the second key is generated based in part on an identity associated with the second entity and the identity associated with the first server entity.

4. The computer-implemented method of claim 1 , wherein a derived second key, symmetric to the second key, can be generated based on the first key and an identity associated with the second entity.

5. The computer-implemented method of claim 1 , wherein the first key is generated based on applying a pseudorandom function to a root key and an identity associated with the first server entity.

6. The computer-implemented method of claim 1 , wherein the second key is generated based on applying a pseudorandom function to the first key and an identity associated with the second entity.

7. The computer-implemented method of claim 1 , wherein the authentication token comprises a message associated with the request and a message authentication code.

8. The computer-implemented method of claim 7 , wherein the message authentication code is generated based on the second key and the message.

9. The computer-implemented method of claim 7 , wherein the message authentication code is authenticated.

10. The computer-implemented method of claim 9 , wherein the message authentication code is authenticated based on a derived second key symmetric to the second key.

11. The computer-implemented method of claim 1 , wherein the intermediary includes a proxy or a frontend service associated with a social networking system.

12. A system comprising:

at least one processor; and

a memory storing instructions that, when executed by the at least one processor, cause the system to perform:

generating a first key for a first server entity associated with a first backend service of a social networking system; and

generating a second key for a second entity, wherein the second entity is a client and the first backend service can authenticate the second entity and a request by the second entity based on an authentication token generated based on the second key, wherein the request by the second entity is provided to the backend service through an intermediary, and wherein the intermediary and the first backend service are controlled by a common entity.

13. The system of claim 12 , wherein the first key is generated based in part on an identity associated with the first server entity.

14. The system of claim 13 , wherein the second key is generated based in part on an identity associated with the second entity and the identity associated with the first server entity.

15. The system of claim 12 , wherein a derived second key, symmetric to the second key, can be generated based on the first key and an identity associated with the second entity.

16. A non-transitory computer-readable storage medium including instructions that, when executed by at least one processor of a computing system, cause the computing system to perform a method comprising:

generating a first key for a first server entity associated with a first backend service of a social networking system; and

generating a second key for a second entity, wherein the second entity is a client and the first backend service can authenticate the second entity and a request by the second entity based on an authentication token generated based on the second key, wherein the request by the second entity is provided to the backend service through an intermediary, and wherein the intermediary and the first backend service are controlled by a common entity.

17. The non-transitory computer-readable storage medium of claim 16 , wherein the first key is generated based in part on an identity associated with the first server entity.

18. The non-transitory computer-readable storage medium of claim 17 , wherein the second key is generated based in part on an identity associated with the second entity and the identity associated with the first server entity.

Assignments (2)
CHANGE OF NAME Recorded Nov 23, 2021
From: FACEBOOK, INC.
To: META PLATFORMS, INC.
Reel/Frame 058235/0904 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 14, 2019
From: LEWI, KEVIN; LEE, YUE TING; XIONG, HAOZHI; YANG, BENJAMIN B.
To: FACEBOOK, INC.
Reel/Frame 047991/0970 →
Cited By (1)
US 12,705,336