IP Library › Granted Patent US 12,355,746
Granted Patent B1
US 12,355,746 · App. 16/785,307 · Granted Jul 8, 2025

Ephemeral authorization tokens from partner tokens

Inventor: Swagata Prateek (Vancouver, CA)
Assignee: Amazon Technologies, Inc.
H04L63/0807H04L9/30H04L63/0815H04L63/083
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,355,746
App. No.
16/785,307
Granted
Jul 8, 2025
Kind
B1
Abstract

In a system that controls access to resources via tokens, a system includes an application that generates ephemeral authorization tokens from partner tokens, to increase confidentiality and security, in embodiments. Responsive to a request, received by an application provider, for a protected resource, a federated ID/authorization provider is caused to receive a request for access/ID tokens that the ID/authorization provider provides (in any of various ways) to the application. The application validates and stores the tokens, nests the access/ID tokens within an ephemeral token document having a unique ID and shortened expiration, encrypts the nested ephemeral token using at least resource-specific encryption and causes the encrypted nested token to be sent to the protected resource provider that decrypts and validates the ephemeral token, causes the Access/ID token(s) within the ephemeral token to be validated, and provides the protected resource for valid tokens.

Claims (86)

1. A system, comprising:

one or more processors and corresponding memory configured to implement an application provider configured to:

receive, over a network, a request for a protected resource stored at a protected resource server of a protected resource provider;

cause a request for access and ID tokens to be sent to a federated identity/authentication service;

receive an access and ID token document having an associated expiration time,

nest the access and ID token document within a nested ephemeral token having:

a unique ID for single use of the nested ephemeraltoken, and a request-specific lifetime for the nested ephemeral token that is shorter than the associated expiration time of the access and ID token document;

encrypt the nested ephemeraltoken using resource server-specific encryption specific to the protected resource server, wherein the resource server-specific encryption is based at least in part on a key exchange with the protected resource provider; and

cause the encrypted nested ephemeral token to be sent to the protected resource server to provide the requested protected resource if the encrypted nested ephemeraltoken is found valid by the protected resource server.

2. The system of claim 1 , wherein the application provider is further configured to:

prior to said encrypt the nested ephemeral token using resource server-specific encryption, encrypt the nested ephemeral token using resource federated identity/authentication service encryption such that subsequent to said encrypt the nested ephemeral token using resource server-specific encryption, the encrypted nested ephemeral token is doubly-encrypted.

3. The system of claim 1 , wherein:

the request for the protected resource is from a browser; and

to cause a request for access and ID tokens to be sent to a federated identity/authentication service, the application provider is configured to:

generate a redirect request that comprises the request for access and ID tokens; and

send the redirect request to the browser such that the browser is caused to send the request for access and ID tokens to the federated identity/authentication service.

4. The system of claim 1 , wherein:

at least one of the access and ID tokens is associated with an expiration time; and

the application provider is further configured to:

set a lifetime of an expiration of the nested ephemeraltoken to a value less than the associated expiration time for at least one of the access and ID tokens.

5. A computer-implemented method, comprising:

receiving, by an application provider, an authorization token document that authorizes access of a protected resource stored at a protected resource server of a protected resource provider;

generating, by the application provider and based on the authorization token document having an associated expiration time, a nested ephemeral token having:

a unique ID for single use of the nested ephemeraltoken, and a request-specific lifetime for the nested ephemeral token that is shorter than the associated expiration time of the authorization token document;

encrypting the nested ephemeraltoken using resource server-specific encryption specific to the protected resource server, wherein the resource server-specific encryption is based at least in part on a key exchange with the protected resource provider; and

causing the encrypted nested ephemeral token to be sent to the protected resource server to provide the requested protected resource if the encrypted nested ephemeraltoken is found valid by the protected resource server.

6. The method of claim 5 , further comprising:

determining a value for a lifetime of an expiration of the nested ephemeral token, wherein the value is based upon one or more of: detection of a security attack, a multiple of a particular metric value determined from monitoring network characteristics, or padding to be added to a particular metric value; and

setting the request-specific lifetime of the expiration of the nested ephemeral token to the value.

7. The method of claim 5 , further comprising:

validating the authorization token document prior to said generating the nested ephemeral token.

8. The method of claim 5 , further comprising:

storing the authorization token document in durable storage;

receiving an indication that the nested ephemeral token has been determined invalid based upon expiration of the request-specific lifetime;

determining that the stored authorization token has not expired;

generating, based on the token document, another nested ephemeral token having another unique ID for single use and another request-specific lifetime;

encrypting the other nested ephemeral token using resource server-specific encryption; and

causing the encrypted other nested ephemeral token to be sent to the protected resource server.

9. The method of claim 5 , wherein said causing the request for the authorization token to be sent to the protected resource server comprises:

generating a redirect request that comprises the request for the authorization token; and

sending the redirect request to a browser such that the browser is caused to send the request for the authorization token to the protected resource server.

10. The method of claim 5 , further comprising:

causing a request for the authorization token to be sent to a federated identity/authentication service, wherein causing comprises:

receiving, from the federated identity/authentication service via URL redirection, a code; and

exchanging, with the federated identity/authentication service, the code for the authorization token.

11. The method of claim 5 , further comprising:

causing a request for the authorization token to be sent to a federated identity/authentication service, wherein causing comprises:

generating a redirect request that comprises the encrypted nested ephemeral token; and

sending the redirect request to a browser such that the browser is caused to send the encrypted nested ephemeral token to the protected resource server.

12. The method of claim 5 , further comprising

encrypting the nested ephemeral nested token using both resource server-specific encryption and federated identity/authentication service-specific encryption to generate a doubly-encrypted nested ephemeral token.

13. A system, comprising:

one or more processors and corresponding memory configured to implement a protected resource provider configured to:

receive a request for a protected resource, the request including an encrypted nested ephemeral token comprising an authorization token having an associated expiration time, the encrypted nested ephemeral token having a request-specific lifetime that is shorter than the associated expiration time of the authorization token;

decrypt the encrypted nested ephemeral token into a nested ephemeral token using a resource provider private key;

for a valid nested ephemeral token with a request-specific lifetime, for the nested ephemeral token, that is not expired, validate the authorization token; and

for a valid authorization token, return the requested protected resource; and

for an invalid nested ephemeraltoken or invalid authorization token, decline the request for the protected resource.

14. The system of claim 13 , wherein to decrypt the encrypted nested ephemeral token, the protected resource provider is further configured to:

decrypt, using a private key of a federated identity/authentication service, the results of said decryption of the nested ephemeral token using the resource provider private key.

15. The system of claim 14 , wherein the protected resource provider is further configured to:

prior to said decrypt the encrypted nested ephemeral token using the using a private key of the federated identity/authentication service,

generate a pair of keys; and

perform a key exchange of a public key of the keys with the federated identity/authentication service;

wherein the private key is one of the pair of keys.

16. The system of claim 13 , wherein the protected resource provider is further configured to:

compare a nonce of the nested ephemeral token to a list of nonce values received with prior requests; and

for the nonce that is a match with a nonce on the list, decline the request for the protected resource.

17. The system of claim 13 , wherein the protected resource provider is further configured to:

receive another request for the protected resource, the request including another encrypted nested ephemeral token comprising the same authorization token as in the request for the protected resource;

decrypt the other encrypted nested ephemeral token into another nested ephemeral token using the resource provider private key;

validate the other nested ephemeral token, wherein validate comprises:

determine whether a request-specific lifetime for the other encrypted nested ephemeral token is expired;

for a valid nested ephemeral token with the request-specific lifetime that is not expired,

validate the authorization token; and

for a valid authorization token,

return the requested protected resource.

18. The system of claim 13 , wherein to return the requested protected resource, the protected resource provider is further configured to:

generate a redirect request that comprises the protected resource; and

send the redirect request to a browser.

19. The system of claim 13 , wherein the protected resource provider is further configured to:

prior to said decrypt the encrypted nested ephemeral token using the resource provider private key,

generate a pair of keys; and

perform a key exchange of a public key of the keys with an application provider, wherein the resource provider private key is one of the pair of keys.

20. The system of claim 13 , wherein to validate the nested ephemeral token, the protected resource provider is further configured to:

determine whether a unique ID for the encrypted nested ephemeral token is a repeat.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 10, 2020
From: PRATEEK, SWAGATA
To: AMAZON TECHNOLOGIES, INC.
Reel/Frame 051767/0841 →
References Cited (23)
US 10616193B2 · Hawkins · 2020 [cited by examiner]
US 10860724B2 · Pearson · 2020 [cited by examiner]
US 11212101B2 · Kanukollu · 2021 [cited by examiner]
US 11411735B2 · Mars · 2022 [cited by examiner]
US 20040002878A1 · Maria Hinton · 2004 [cited by examiner]
US 20120260322A1 · Logan · 2012 [cited by examiner]
US 20130174244A1 · Taveau · 2013 [cited by examiner]
US 20140040993A1 · Lorenzo · 2014 [cited by examiner]
US 20140189799A1 · Lu · 2014 [cited by examiner]
US 20150206139A1 · Lea · 2015 [cited by examiner]
US 20160065563A1 · Broadbent · 2016 [cited by examiner]
US 20180183802A1 · Choyi · 2018 [cited by examiner]
US 20180255036A1 · Fiedler · 2018 [cited by examiner]
US 20180351958A1 · Sakurai · 2018 [cited by examiner]
US 20180375791A1 · Kaladgi · 2018 [cited by examiner]
US 20190312733A1 · Engan · 2019 [cited by examiner]
US 20190319967A1 · Holt · 2019 [cited by examiner]
US 20190372958A1 · Dunjic · 2019 [cited by examiner]
US 20200329041A1 · Mandadi · 2020 [cited by examiner]
US 20210226794A1 · Axdorff · 2021 [cited by examiner]
WO WO2015081899A1 · 2015 [cited by examiner]
Unknown, “OpenID Connect—OpenID”, Retrieved from https://openid.net/connect/ on Jan. 16, 2020, pp. 1-4. [cited by applicant]
Unknown, “OpenID Connect”, Retrieved from https://auth0.com/docs/protocols/oidc on Jan. 16, 2020, pp. 1-4. [cited by applicant]