IP Library Granted Patent US 11,606,349
Granted Patent B2
US 11,606,349 · App. 16/890,531 · Granted Mar 14, 2023

Authentication token refresh

Inventor: David Brainer (Salida, CO)
Assignee: salesforce.com, inc.
H04L63/083
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,606,349
App. No.
16/890,531
Granted
Mar 14, 2023
Kind
B2
Abstract

Techniques are disclosed relating to authentication token refresh. In various embodiments, a first of a plurality of instances of an application executing on the server system receives a request to provide content to a browser of a client device. The first application instance determines that an authentication token useable to provide the content has expired. The authentication token is maintained in a storage accessible to the plurality of application instances. The first application instance sends a refresh request for the authentication token to an authentication service. In response to the authentication service denying the refresh request, the first application instance waits for a particular period of time before checking the storage to determine whether another instance of the plurality of instances of the application has refreshed the authentication token.

Claims (81)

1. A non-transitory computer readable medium having program instructions stored thereon that are capable of causing a server system to perform operations comprising:

receiving, by a first application instance of a plurality of instances of an application executing on the server system, a request to provide content to a browser of a client device;

determining, by the first application instance, that an authentication token useable to provide the content has expired, wherein the authentication token is maintained in a storage accessible to the plurality of application instances;

sending, by the first application instance, a refresh request for the authentication token to an authentication service;

in response to the authentication service denying the refresh request, waiting, by the first application instance, for a particular period of time before checking the storage to determine whether another instance of the plurality of instances of the application has refreshed the authentication token;

sending, by the first application instance after waiting the particular period of time, a second refresh request to the authentication service;

comparing, by the first application instance, a refresh expiration timestamp of a refreshed authentication token received from the authentication service in response to the second refresh request with a stored expiration timestamp of a refreshed authentication token stored by a second application instance in the storage accessible to the plurality of application instances; and

in response to the refreshed expiration timestamp being earlier in time than the stored expiration timestamp, discarding, by the first application instance, the refreshed authentication token received from the authentication service based on the second refresh request.

2. The non-transitory computer readable medium of claim 1 , wherein the operations further comprise:

in response to determining that the authentication token has been refreshed by another instance of the plurality of instances of the application:

retrieving, by the first application instance, the refreshed authentication token from the storage;

sending, by the first application instance, the retrieved authentication token with a request for the content to a backend server; and

providing, by the first application instance, the content from the backend server to the browser of the client device.

3. The non-transitory computer readable medium of claim 1 , wherein the operations further comprise:

prior to the first application instance receiving the request, receiving the request at a load balancer of the server system; and

determining, by the load balancer, to distribute the request to the first application instance for processing.

4. The non-transitory computer readable medium of claim 1 , wherein the operations further comprise:

prior to the first application instance receiving the request for content:

receiving, by the second application instance, user credentials from the browser of the client device;

presenting, by the second application instance, the user credentials to the authentication service;

in response to a successful verification of the user credentials, receiving, by the second application instance from the authentication service, the authentication token and a refresh token, wherein the refresh token is useable to refresh the authentication token in response to an expiration of the authentication token; and

storing, by the second application instance, the authentication token and the refresh token in the storage accessible to the plurality of application instances.

5. The non-transitory computer readable medium of claim 4 , wherein sending the refresh request includes:

presenting, to the authentication service, the refresh token maintained in the storage accessible to the plurality of application instances.

6. The non-transitory computer readable medium of claim 1 , wherein the operations further comprise:

refreshing, by the second application instance, the authentication token from the authentication service;

saving, by the second application instance, the refreshed authentication token to a memory external to the storage accessible to the plurality of application instances; and

replacing, by the second application instance, the authentication token in the storage with the authentication token in the memory external to the storage.

7. The non-transitory computer readable medium of claim 1 , further comprising:

in response to determining that the authentication token has not been refreshed, performing, by the first application instance, one or more retries to check the storage to determine whether the authentication token has been refreshed, wherein the performing includes scheduling the one or more retries based on a variable waiting period between the retries.

8. The non-transitory computer readable medium of claim 7 , further comprising:

in response to determining that the authentication token has not been refreshed after performing the one or more retries, returning, by the first application instance, a failure to the browser of the client device for the request to provide content.

9. The non-transitory computer readable medium of claim 1 , further comprising:

in response to determining that the authentication token in the storage is not expired, sending, by a third application instance of the plurality of application instances, the authentication token in the storage with a request for content from the browser of the client device to a backend server; and

providing, by the third application instance, the requested content from the backend server to the browser of the client device.

10. A non-transitory computer readable medium having program instructions stored thereon that are capable of causing a first application instance of a plurality of application instances instantiated by a server system to perform operations comprising:

determining whether an authentication token usable by the plurality of application instances to obtain content from a database has expired, wherein the authentication token is maintained in a storage accessible to the plurality of application instances;

in response to determining that the authentication token has expired, sending a refresh request for the authentication token to an authentication service;

in response to determining that the authentication token has not been refreshed by the authentication service, checking the storage to determine whether another instance of the plurality of application instances has stored a refreshed authentication token in the storage;

sending, based on determining that the authentication token has not yet been refreshed by the authentication service, a second refresh request to the authentication service;

comparing a refresh expiration timestamp of a refreshed authentication token received from the authentication service in response to the second refresh request with a stored expiration timestamp of a refreshed authentication token stored by a second application instance in the storage accessible to the plurality of application instances; and

in response to the stored expiration timestamp being later in time than the refreshed expiration timestamp, discarding the refreshed authentication token received from the authentication service based on the second refresh request.

11. The non-transitory computer readable medium of claim 10 , wherein the operations further comprise:

in response to determining that no response to the refresh request has been received from the authentication service, sending, by the first application instance, one or more additional refresh requests for the authentication token to the authentication service.

12. The non-transitory computer readable medium of claim 10 , wherein sending the refresh request for the authentication token further comprises:

presenting a refresh token, to the authentication service, wherein the refresh token is maintained in the storage accessible to the plurality of application instances.

13. The non-transitory computer readable medium of claim 10 , wherein the operations further comprise:

in response to a successful refresh of the authentication token by the authentication service, receiving, by the first application instance, a refreshed authentication token;

saving, by the first application instance, the refreshed authentication token to a memory external to the storage; and

in response to determining that the authentication token in the memory has an expiration time later than the authentication token in the storage, replacing the authentication token in the storage with the authentication token in the memory.

14. The non-transitory computer readable medium of claim 10 , wherein the operations further comprise:

in response to a successful refresh of the authentication token by the authentication service, receiving, by the first application instance, a refreshed authentication token;

saving, by the first application instance, the refreshed authentication token to a memory external to the storage; and

in response to determining that the authentication token in the memory has an expiration time earlier than the authentication token in the storage, discarding the authentication token in the memory without replacing the authentication token in the storage.

15. A method comprising:

receiving, by a first application instance of a plurality of instances of an application executing on a server system, a request to perform a service from a browser of a client device;

determining, by the first application instance, that an authentication token useable to provide the service has expired, wherein the authentication token is maintained in a storage accessible to the plurality of application instances;

sending, by the first application instance, a refresh request for the authentication token to an authentication service;

in response to the authentication service denying the refresh request, determining, by the first application instance, whether another instance of the plurality of instances of the application has refreshed the authentication token by checking the storage;

sending, by the first application instance based on determining that the authentication token has not yet been refreshed by the authentication service, a second refresh request to the authentication service;

comparing, by the first application instance, a refresh expiration timestamp of a refreshed authentication token received from the authentication service in response to the second refresh request with a stored expiration timestamp of a refreshed authentication token stored by a second application instance in the storage accessible to the plurality of application instances; and

in response to the refreshed expiration timestamp being earlier in time than the stored expiration timestamp, discarding, by the first application instance, the refreshed authentication token received from the authentication service based on the second refresh request.

16. The method of claim 15 , further comprising:

refreshing, by the second application instance of the plurality of application instances, the authentication token with the authentication service;

copying, by the second application instance, the refreshed authentication token into a memory associated with the second application instance and external to the storage accessible to the plurality of application instances; and

replacing, by the second application instance, the authentication token maintained in the storage by the refreshed authentication token.

17. The method of claim 15 , further comprising:

in response to determining that the authentication token has been refreshed by another instance of the plurality of instances of the application:

retrieving, by the first application instance, the authentication token from the storage into a memory external to the storage;

sending, by the first application instance, the authentication token in the memory external to the storage to a backend server along with a request to perform the service; and

forwarding, by the first application instance, a result of the performed service received from the backend server to the browser of the client device.

18. The method of claim 15 , further comprising:

prior to the first application instance receiving the request for service, receiving the request at a load balancer of the server system; and

determining, by the load balancer, to distribute the request to the first application instance for processing based on a comparison of a workload of the first application instance with workloads of other application instances.

19. The method of claim 15 , further comprising:

in response to determining that the authentication token has not been refreshed, performing, by the first application instance, one or more retries to check the storage to determine whether the authentication token has been refreshed, wherein the performing includes varying a particular waiting period between the retries.

20. The method of claim 19 , further comprising:

after performing the one or more retries and in response to determining that the authentication token has been refreshed:

retrieving, by the first application instance, the authentication token from the storage;

sending, by the first application instance, the retrieved authentication token to a backend server along with a request to perform the service; and

forwarding, by the first application instance, a result of the performed service received from the backend server to the browser of the client device.

Assignments (2)
CHANGE OF NAME Recorded Dec 18, 2024
From: SALESFORCE.COM, INC.
To: SALESFORCE, INC.
Reel/Frame 069717/0499 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 2, 2020
From: BRAINER, DAVID
To: SALESFORCE.COM, INC.
Reel/Frame 052813/0680 →
Continuity (1)
Related Publication 20210377248A1 · Dec 2, 2021