IP Library Granted Patent US 12,132,837
Granted Patent B2
US 12,132,837 · App. 18/153,587 · Granted Oct 29, 2024

System and method for a token gateway environment

Inventors: Alpa Modi Jain (Laguna Niguel, CA); Praveen Kumar Soni (Costa Mesa, CA); Frederic Vander Elst (London, GB)
Assignee: Experian Information Solutions, Inc.
H04L9/3213H04L9/0894H04L9/3247H04L63/0428H04L63/08H04L63/10H04L63/0807H04L63/0815
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,132,837
App. No.
18/153,587
Granted
Oct 29, 2024
Kind
B2
Abstract

Embodiments include a method for providing tokens which includes: receiving from a user system an encrypted data packet including user credentials and a request for an authentication token to access protected resources; extracting the user's security information; transmitting a data packet to a security and access management system, where the data packet includes the user's security information and a request for user validation; receiving, from the security and access management system, user validation and additional data; generating a thin token and a fat token; storing the thin token in association with the fat token; transmitting the thin token to the user system; receiving, from the user system, a request to access protected resources from a protected resource system, the request including the thin token; validating the received thin token; accessing the fat token associated with the thin token; and transmitting the fat token to the protected resource system.

Claims (63)

1. A system for providing tokens to facilitate authentication and access to protected resources, the system comprising:

a token gateway computing system in electronic communication with a user computing system, at least one access management computing system, and a protected resource computing system, wherein the token gateway computing system is configured to:

receive, from the user computing system, a first data packet including user credentials of a user and a request for an authentication token to access one or more protected resources from the protected resource computing system;

transmit a second data packet to the at least one access management computing system based on a type associated with the one or more protected resources requested;

receive, from the at least one access management computing system, validation of the user, and private data;

generate a first token;

generate a second token using the private data, wherein the second token comprises a first portion of the first token and additional data, and wherein the first token and the second token are based on a JavaScript Object Notation (JSON) web token standard;

transmit the first token to the user computing system;

receive, from the user computing system, a request to access one or more protected resources from the protected resource computing system, the request comprising the first token;

validate the received first token; and

transmit the second token to the protected resource computing system.

2. The system of claim 1 , wherein the first token is a thin token and the second token is a fat token.

3. The system of claim 1 , wherein the first portion of the first token comprises a payload.

4. The system of claim 1 , wherein the first token and second token headers each include a public key and a type associated with the token.

5. The system of claim 1 , wherein the first portion of the first token includes at least a username, an email, a first name, an issuer of the token, a last name, an expiry time, an issue time, and a unique identifier.

6. The system of claim 1 , wherein the additional data in the second token include details regarding the protected resources.

7. The system of claim 6 , wherein the additional data includes:

a product name of a protected resource as identified in the at least one access management computing system;

product options associated with the product name; and

additional custom information requested by users and administrators of the protected resource computing system.

8. A computer-implemented method for providing tokens to facilitate authentication and access to protected resources, the computer-implemented method comprising, as implemented by one or more computing devices within a token gateway system configured with specific executable instructions:

receiving, from a user computing system, a first data packet including user credentials of a user and a request for an authentication token to access one or more protected resources from a protected resource computing system;

transmitting a second data packet to at least one access management computing system based on a type associated with the one or more protected resources requested;

receiving, from the at least one access management computing system, validation of the user, and private data;

generating a first token;

generating a second token using the private data, wherein the second token comprises a first portion of the first token and additional data, and wherein the first token and the second token are based on a JavaScript Object Notation (JSON) web token standard;

transmitting the first token to the user computing system;

receiving, from the user computing system, a request to access one or more protected resources from the protected resource computing system, the request comprising the first token;

validating the received first token; and

transmitting the second token to the protected resource computing system.

9. The computer-implemented method of claim 8 , wherein the first token and second token headers each include a public key and a type associated with the token.

10. The computer-implemented method of claim 8 , wherein the additional data in the second token include details regarding the protected resources.

11. The computer-implemented method of claim 10 , wherein the additional data includes:

a product name of a protected resource as identified in the at least one access management computing system;

product options associated with the product name; and

additional custom information requested by users and administrators of the protected resource computing system.

12. The computer-implemented method of claim 8 , wherein the first token is a thin token and the second token is a fat token.

13. The computer-implemented method of claim 8 , wherein the first portion of the first token comprises a payload.

14. A non-transitory computer storage medium storing computer-executable instructions that, when executed by a processor, cause the processor to at least:

receive, from a user computing system, a first data packet including user credentials of a user and a request for an authentication token to access one or more protected resources from a protected resource computing system;

transmit a second data packet to at least one access management computing system based on a type associated with the one or more protected resources requested;

receive, from the at least one access management computing system, validation of the user, and private data;

generate a first token;

generate a second token using the private data, wherein the second token comprises a first portion of the first token and additional data, and wherein the first token and the second token are based on a JavaScript Object Notation (JSON) web token standard;

transmit the first token to the user computing system;

receive, from the user computing system, a request to access one or more protected resources from the protected resource computing system, the request comprising the first token;

validate the received first token; and

transmit the second token to the protected resource computing system.

15. The non-transitory computer storage medium of claim 14 , wherein the first token includes a key pointing to the second token.

16. The non-transitory computer storage medium of claim 14 , wherein the computer-executable instructions, when executed by the processor, cause the processor to additionally:

receive, from the user computing system, a request for a refreshed first token;

validate a header within the request;

generate a refreshed first token;

store the refreshed token in association with the first token; and

send the refreshed token back to the user computing system.

17. The non-transitory computer storage medium of claim 16 , wherein the first token includes an expiry date.

18. The non-transitory computer storage medium of claim 17 , wherein the refreshed token includes a different expiry date than the expiry date of the first token.

19. The non-transitory computer storage medium of claim 18 , wherein the computer-executable instructions, when executed by the processor, cause the processor to additionally:

receive, from the user computing system, a request for revoking the first token;

validate a header within the request;

revoke the first token; and

alter the stored first token.

20. The non-transitory computer storage medium of claim 14 , wherein the first portion of the first token comprises a payload.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 12, 2023
From: JAIN, ALPA MODI; SONI, PRAVEEN KUMAR; ELST, FREDERIC VANDER
To: EXPERIAN INFORMATION SOLUTIONS, INC.
Reel/Frame 064881/0952 →
Continuity (4)
Continuation 17123568 · Dec 16, 2020
Continuation 16051339 · Jul 31, 2018
Provisional Application 62688887 · Jun 22, 2018
Related Publication 20230421376A1 · Dec 28, 2023
Cited By (3)
US 12,243,110 US 12,346,984 US 12,657,589