IP Library Granted Patent US 11,477,190
Granted Patent B2
US 11,477,190 · App. 16/400,192 · Granted Oct 18, 2022

Dynamic user ID

Inventors: Vinay Kumar Tiruvaipeta (Hyderabad, IN); Chandra Sekhar Varanasi (Hyderabad, IN)
Assignee: Salesforce, Inc.
H04L63/0853H04L63/0876
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,477,190
App. No.
16/400,192
Granted
Oct 18, 2022
Kind
B2
Abstract

The disclosed subject matter provides authentication between a client device and a server. The server allocates a dynamic user ID contained within an authentication token that is provided to the client device. In response to each successful authentication with the server, a new dynamic user ID is generated and provided to the client device for use in a subsequent authentication session. In generating the new dynamic user ID for the client device, the server invalidates any previously-provided dynamic user IDs for the client device.

Claims (58)

1. A method of authenticating a client device with a server, the method comprising:

receiving a first authentication request from a first client device;

generating, in response to receiving the first authentication request, a first authentication token, the first authentication token including a first dynamic user ID and a first session ID;

transmitting, to the first client device, the first authentication token being encrypted using a public key associated with the first client device;

storing, based on transmitting the first authentication token to the first client device, the first dynamic user ID and the first session ID designated as a temporary session type;

receiving, based on transmitting the encrypted first authentication token to the first client device, a digital signature based on a user entered PIN at the first client device and a second authentication token from the first client device, the second authentication token including the first dynamic user ID and the first session ID;

verifying, using the public key associated with the first client device transmitted to the first client device, the digital signature based on the contents of the second authentication token;

generating, based on verifying the digital signature, a third authentication token including a second dynamic user ID and a second session ID, the third authentication token being encrypted using the public key associated with the first client device;

transmitting, to the first client device, the third authentication token;

overwriting, based on transmitting the third authentication token to the first client device, the stored first dynamic user ID with the second dynamic user ID, and the stored first session ID with the second session ID designated as a permanent session type;

receiving the second dynamic user ID and the third authentication token from the first client device in a second authentication request occurring after the first authentication request; and

authenticating the first client device using the third authentication token upon entry of the user entered PIN at the first client device.

2. The method of claim 1 , wherein the first authentication request includes a fourth authentication token, the method further comprising:

extracting a second session ID from the fourth authentication token; and

determining whether a valid session for the first client device exists based on the second session ID.

3. The method of claim 2 , wherein the fourth authentication token contains a third dynamic user ID having a null or empty value.

4. The method of claim 1 , wherein the first and second dynamic user ID, when generated, are uniquely assigned to a static user ID wherein no other static user ID may be assigned to the same dynamic user ID.

5. The method of claim 1 , further comprising:

generating a third session ID that is assigned to the second dynamic user ID.

6. The method of claim 1 , wherein the second dynamic user ID is transmitted within the third authentication token.

7. The method of claim 3 , wherein the third dynamic user ID is transmitted separately from the third authentication token.

8. The method of claim 2 , further comprising:

determining that a valid session for the first client device does not exist;

generating a challenge;

generating a third session ID; and

transmitting the challenge to the client device.

9. The method of claim 1 , further comprising:

after generating the second dynamic user ID, rejecting authentication of a second client device in response to receiving an authentication token containing the first dynamic user ID.

10. The method of claim 9 , wherein the second client device is the first client device.

11. A non-transitory computer-readable medium storing a plurality of instructions which, when executed by a processor, perform a method comprising:

receiving a first authentication request from a first client device;

generating, in response to receiving the first authentication request, a first authentication token, the first authentication token including a first dynamic user ID and a first session ID;

transmitting, to the first client device, the first authentication token being encrypted using a public key associated with the first client device;

storing, based on transmitting the first authentication token to the first client device, the first dynamic user ID and the first session ID designated as a temporary session type;

receiving, based on transmitting the encrypted first authentication token to the first client device, a digital signature based on a user entered PIN at the first client device and a second authentication token from the first client device, the second authentication token including the first dynamic user ID and the first session ID;

verifying, using the public key associated with the first client device transmitted to the first client device, the digital signature based on the contents of the second authentication token;

generating, based on verifying the digital signature, a third authentication token including a second dynamic user ID and a second session ID, the third authentication token being encrypted using the public key associated with the first client device;

transmitting, to the first client device, the third authentication token;

overwriting, based on transmitting the third authentication token to the first client device, the stored first dynamic user ID with the second dynamic user ID, and the stored first session ID with the second session ID designated as a permanent session type;

receiving the second dynamic user ID and the third authentication token from the first client device in a second authentication request occurring after the first authentication request; and

authenticating the first client device using the third authentication token upon correct entry of the user entered PIN at the first client device.

12. The medium of claim 11 , wherein the first authentication request includes a fourth authentication token, the method further comprising:

extracting a second session ID from the fourth authentication token; and

determining whether a valid session for the first client device exists based on the second session ID.

13. The medium of claim 12 , wherein the fourth authentication token contains a third dynamic user ID having a null or empty value.

14. The method of claim 11 , wherein the first and second dynamic user ID, when generated, are uniquely assigned to a static user ID wherein no other static user ID may be assigned to the same dynamic user ID.

15. The method of claim 11 , further comprising:

generating a third session ID that is assigned to the second dynamic user ID.

16. The method of claim 11 , wherein the second dynamic user ID is transmitted within the third authentication token.

17. The method of claim 13 , wherein the third dynamic user ID is transmitted separately from the third authentication token.

18. The method of claim 12 , further comprising:

determining that a valid session for the first client device does not exist;

generating a challenge;

generating a third session ID; and

transmitting the challenge to the client device.

19. The method of claim 11 , further comprising:

after generating the second dynamic user ID, rejecting authentication of a second client device in response to receiving an authentication token containing the first dynamic user ID.

20. The method of claim 19 , wherein the second client device is the first client device.

Assignments (2)
CHANGE OF NAME Recorded Dec 18, 2024
From: SALESFORCE.COM, INC.
To: SALESFORCE, INC.
Reel/Frame 069717/0416 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 1, 2019
From: TIRUVAIPETA, VINAVINAY KUMAR; VARANASI, CHANDRA SEKHAR
To: SALESFORCE.COM, INC.
Reel/Frame 049048/0308 →
Continuity (1)
Related Publication 20200351263A1 · Nov 5, 2020