IP Library Granted Patent US 11,997,207
Granted Patent B2
US 11,997,207 · App. 18/114,054 · Granted May 28, 2024

Identifying group membership through discharge macaroon access tokens

Inventor: Neil Edward Madden (Stroud, GB)
Assignee: Ping Identity International, Inc.
H04L9/3213H04L9/0891H04L9/3242H04L9/50H04L2209/84
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,997,207
App. No.
18/114,054
Granted
May 28, 2024
Kind
B2
Abstract

The disclosed technology teaches delegating authorization to access a resource server contingent upon group membership confirmation by a third-party identity management provider. As part of the technology, a client obtains a Macaroon Access Token with a third-party caveat that requires the client to obtain a one-time Discharge Macaroon Authorization from a third-party authority, and identifies both user group membership that needs to be checked, and a hint how to find the third-party authority. The client provides the Macaroon Access Token to the third-party authority. The client obtains, from the third-party authority, a Discharge Macaroon Access Token that identifies user group membership, and sends the Macaroon Access Token and the Discharge Macaroon Authorization to the resource server as proof of authorization.

Claims (38)

1. A method of delegating authorization to access a resource server contingent upon group membership confirmation by a third-party identity management provider, including:

a client obtaining a Macaroon Access Token (MAT) with a third-party caveat that:

requires the client to obtain a one-time discharge Macaroon authorization (DMAT) from a third-party authority; and

identifies

group membership of the client that needs to be checked by the third-party authority, and

a hint how to find the third-party authority;

the client providing the MAT to the third-party authority;

the client obtaining, from the third-party authority, a Discharge Macaroon Access Token (DMAT) that confirms the group membership of the client;

sending the MAT and the DMAT to the resource server as proof of authorization; and

the client obtaining access to the resource server after the resource server receives an introspection response that validates the MAT and DMAT.

2. The method of claim 1 , further including the MAT and DMAT being compatible with OAuth 2.0 or OAuth 2.1 drafts as of November 2020.

3. The method of claim 1 , further including the client obtaining access to a resource, wherein the access is granted through the resource server.

4. The method of claim 3 , wherein the resource is associated with the group.

5. The method of claim 1 , wherein the hint for finding the third-party authority is an internet address.

6. The method of claim 1 , further including the client modifying the MAT to add a first party caveat.

7. The method of claim 6 , wherein the first party caveat is expiry time.

8. The method of claim 6 , wherein the first party caveat limits a scope of the authorization provided by the MAT obtained.

9. A non-transitory computer readable medium including program instructions that, when executed on hardware, implement actions of delegating authorization to access a resource server contingent upon group membership confirmation by a third-party identity management provider the actions including:

a client obtaining a Macaroon Access Token (MAT) with a third-party caveat that:

requires the client to obtain a one-time discharge Macaroon authorization (DMAT) from a third-party authority; and

identifies

group membership of the client that needs to be checked by the third-party authority, and

a hint how to find the third-party authority;

the client providing the MAT to the third-party authority;

the client obtaining, from the third-party authority, a Discharge Macaroon Access Token (DMAT) that confirms the group membership of the client;

sending the MAT and the DMAT to the resource server as proof of authorization; and

the client obtaining access to the resource server after the resource server receives an introspection response that validates the MAT and DMAT.

10. The non-transitory computer readable medium of claim 9 , further including the MAT and DMAT being compatible with OAuth 2.0 or OAuth 2.1 drafts as of November 2020.

11. The non-transitory computer readable medium of claim 9 , further implementing the client obtaining access to a resource, wherein the access is granted through the resource server.

12. The non-transitory computer readable medium of claim 11 , wherein the resource is associated with the group.

13. The non-transitory computer readable medium of claim 9 , wherein the hint for finding the third-party authority is an internet address.

14. A system including hardware coupled to the non-transitory computer readable medium of claim 13 .

15. The non-transitory computer readable medium of claim 9 , further implementing the client modifying the MAT to add a first party caveat.

16. A system including hardware coupled to the non-transitory computer readable medium of claim 15 .

17. The non-transitory computer readable medium of claim 15 , wherein the first party caveat is expiry time.

18. The non-transitory computer readable medium of claim 15 , wherein the first party caveat limits a scope of the authorization provided by the MAT obtained.

19. A system including hardware coupled to the non-transitory computer readable medium of claim 18 .

20. A system including hardware coupled to the non-transitory computer readable medium of claim 9 .

Assignments (5)
RELEASE OF SECURITY INTEREST AT R/F 65335/0890 Recorded Nov 14, 2025
From: BLUE OWL CAPITAL CORPORATION
To: PING IDENTITY CORPORATION (FORMERLY KNOWN AS FORGEROCK INC.)
Reel/Frame 073564/0791 →
SECURITY INTEREST Recorded Nov 13, 2025
From: PING IDENTITY CORPORATION; PING IDENTITY INTERNATIONAL, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 073557/0093 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 6, 2024
From: FORGEROCK, INC.
To: PING IDENTITY INTERNATIONAL, INC.
Reel/Frame 066358/0483 →
GRANT OF SECURITY INTEREST IN PATENT RIGHTS Recorded Oct 24, 2023
From: FORGEROCK, INC.
To: BLUE OWL CAPITAL CORPORATION (FORMERLY KNOWN AS OWL ROCK CAPITAL CORPORATION), AS COLLATERAL AGENT
Reel/Frame 065335/0890 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 24, 2023
From: MADDEN, NEIL EDWARD
To: FORGEROCK, INC.
Reel/Frame 062800/0667 →
Continuity (2)
Continuation 17124982 · Dec 17, 2020
Related Publication 20230239151A1 · Jul 27, 2023
Cited By (3)
US 12,316,762 US 12,626,424 US 12,688,622