IP Library Granted Patent US 11,757,635
Granted Patent B2
US 11,757,635 · App. 17/177,793 · Granted Sep 12, 2023

Client authentication and access token ownership validation

Inventors: Ahmad Muhanna (Richardson, TX); Peter J. McCann (Bridgewater, NJ)
Assignee: Mavenir Networks, Inc.
H04L9/3213H04L9/083H04L9/085H04L9/3236H04L9/3247H04L9/3263
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,757,635
App. No.
17/177,793
Granted
Sep 12, 2023
Kind
B2
Abstract

A method of performing validation of an access token under OAuth 2.0 protocol includes: providing, by an authorization server, the access token for service to a client in response to a request for the access token; adding, by the client, a client signature to at least the access token; forwarding, by the client, the access token as part of a service request to a resource server; and validating, by the resource server, whether the client is a valid owner of the access token, wherein the validation is based on at least the client signature of the access token. The validation is based on a hash of a combination of the service request, the access token and a shared secret key common to the client and the resource server, the output of which hash is added to the service request, and the resource server validates the hash.

Claims (30)

1. A method of performing validation of an access token for wireless communication, comprising:

providing, by an authorization server, the access token for service to a client in response to a request for the access token;

adding, by the client, a client signature to at least the access token;

forwarding, by the client, the access token as part of a service request to a resource server; and

validating, by the resource server, whether the client is a valid owner of the access token, wherein the validation is based on at least the client signature of the access token;

wherein an increasing random number is associated with the access token signed by the client and forwarded as part of the service request, and wherein the increasing random number is protected by the signature of the client on the access token, and wherein the client signature is provided for the entire service request including the access token, and wherein the access token is signed by the authorization server, whereby the access token is associated with the service request forwarded to the resource server by the proxy node.

2. The method of claim 1 , wherein the resource server validates the client signature using a client server public key included in a client server certificate signed by a trusted certificate authority (CA).

3. The method of claim 2 , wherein the client server certificate is added to the service request by the proxy node, and wherein the resource server receives the client server certificate in the service request.

4. The method of claim 2 , wherein the client server certificate is added to the service request by the client server, and wherein the resource server receives the client server certificate in the service request.

5. A method of performing validation of an access token for wireless communication, comprising:

providing, by an authorization server, the access token for service to a client in response to a request for the access token;

adding, by the client, a client signature to at least the access token;

forwarding, by the client, the access token as part of a service request to a resource server; and

validating, by the resource server, whether the client is a valid owner of the access token, wherein the validation is based on at least the client signature of the access token;

wherein a hash of the service request is associated with the access token signed by the client and forwarded as part of the service request, and wherein the hash of the service request is protected by the signature of the client on the access token, and wherein the client signature is provided for the entire service request including the access token, and wherein the access token is signed by the authorization server, whereby the access token is associated with the service request forwarded to the resource server by the proxy node.

6. The method of claim 5 , wherein the resource server validates the client signature using a client server public key included in a client server certificate signed by a trusted certificate authority (CA).

7. The method of claim 6 , wherein the client server certificate is added to the service request by the proxy node, and wherein the resource server receives the client server certificate in the service request.

8. The method of claim 6 , wherein the client server certificate is added to the service request by the client server, and wherein the resource server receives the client server certificate in the service request.

9. A method of performing validation of an access token for wireless communication, comprising:

providing, by an authorization server, the access token for service to a client in response to a request for the access token;

adding, by the client, a client signature to at least the access token;

forwarding, by the client, the access token as part of a service request to a resource server; and

validating, by the resource server, whether the client is a valid owner of the access token, wherein the validation is based on at least the client signature of the access token;

wherein an increasing random number is associated with the access token signed by the client and forwarded as part of the service request, and wherein the increasing random number is protected by the signature of the client on the access token, and wherein the validation is based on a hash of a combination of the service request, the access token and a shared secret key common to the client and the resource server, and wherein the output of the hash is added to the service request, and wherein the resource server validates the hash by i) hashing the service request including the access token and the shared secret key, and ii) comparing the output of the hashing by the resource server with the hash added to the service request received via the proxy node.

10. A method of performing validation of an access token for wireless communication, comprising:

providing, by an authorization server, the access token for service to a client in response to a request for the access token;

adding, by the client, a client signature to at least the access token;

forwarding, by the client, the access token as part of a service request to a resource server; and

validating, by the resource server, whether the client is a valid owner of the access token, wherein the validation is based on at least the client signature of the access token;

wherein a hash of the service request is associated with the access token signed by the client and forwarded as part of the service request, and wherein the hash of the service request is protected by the signature of the client on the access token, and wherein the validation is based on a hash of a combination of the service request, the access token and a shared secret key common to the client and the resource server, and wherein the output of the hash is added to the service request, and wherein the resource server validates the hash by i) hashing the service request including the access token and the shared secret key, and ii) comparing the output of the hashing by the resource server with the hash added to the service request received via the proxy node.

Assignments (13)
RELEASE OF SECURITY INTEREST IN COLLATERAL RECORDED AT REEL 069115 AND FRAME 0815 Recorded Jul 31, 2025
From: GLAS USA LLC
To: MAVENIR NETWORKS, INC.
Reel/Frame 072307/0408 →
GRANT OF SECURITY INTEREST - PATENTS Recorded Jul 29, 2025
From: MAVENIR NETWORKS, INC.; MAVENIR SYSTEMS, INC.; ARGYLE DATA, INC.; MAVENIR, INC.; AQUTO CORPORATION; MAVENIR IPA UK LIMITED; MAVENIR SYSTEMS UK LIMITED; MAVENIR LTD.; MAVENIR US INC.
To: GLAS USA LLC
Reel/Frame 072245/0764 →
RELEASE OF SECURITY INTERESTS (SIDECAR) Recorded Jul 29, 2025
From: JPMORGAN CHASE BANK, N.A.
To: MAVENIR NETWORKS, INC.
Reel/Frame 072262/0363 →
RELEASE OF SECURITY INTERESTS (SYNDICATED) Recorded Jul 29, 2025
From: JPMORGAN CHASE BANK, N.A.
To: MAVENIR NETWORKS, INC.
Reel/Frame 072262/0409 →
RELEASE OF SECURITY INTEREST IN COLLATERAL RECORDED AT REEL 067554 AND FRAME 0789 Recorded Jul 29, 2025
From: WILMINGTON SAVINGS FUND SOCIETY, FSB
To: MAVENIR NETWORKS, INC.
Reel/Frame 072263/0211 →
SECURITY INTEREST Recorded Jul 28, 2025
From: MAVENIR NETWORKS, INC.; MAVENIR SYSTEMS, INC.; ARGYLE DATA, INC.; MAVENIR, INC.; AQUTO CORPORATION; MAVENIR IPA UK LIMITED; MAVENIR SYSTEMS UK LIMITED; MAVENIR LTD.; MAVENIR US INC.
To: BLUE TORCH FINANCE LLC
Reel/Frame 072268/0439 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Oct 4, 2024
From: MAVENIR NETWORKS, INC.
To: GLAS USA LLC
Reel/Frame 069115/0815 →
RELEASE OF SECURITY INTEREST RECORDED AT R/F 068453/0642 Recorded Oct 4, 2024
From: WILMINGTON SAVINGS FUND SOCIETY, FSB
To: MAVENIR NETWORKS, INC.
Reel/Frame 069117/0074 →
SECURITY INTEREST Recorded Aug 30, 2024
From: MAVENIR NETWORKS, INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB
Reel/Frame 068453/0642 →
SECURITY INTEREST Recorded May 29, 2024
From: MAVENIR NETWORKS, INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB
Reel/Frame 067554/0789 →
SECURITY AGREEMENT Recorded Jul 13, 2022
From: MAVENIR NETWORKS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 060640/0125 →
SECURITY AGREEMENT Recorded Aug 18, 2021
From: MAVENIR NETWORKS, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 057221/0866 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 17, 2021
From: MUHANNA, AHMAD; MCCANN, PETER J.
To: MAVENIR NETWORKS, INC.
Reel/Frame 055297/0945 →
Continuity (2)
Provisional Application 62989170 · Mar 13, 2020
Related Publication 20210288802A1 · Sep 16, 2021
Cited By (1)
US 12,495,039