IP Library Granted Patent US 12,452,228
Granted Patent B2
US 12,452,228 · App. 18/343,188 · Granted Oct 21, 2025

Technologies for token-based authentication and authorization of distributed computing resources

Inventor: Scott Edward Blasi (Littleton, CO)
Assignee: Worldpay, LLC
H04L63/0807G06F9/54G06F21/105G06F21/33H04L9/3213H04L9/3239H04L9/3247H04L63/0442H04L63/0815H04L63/126
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,452,228
App. No.
18/343,188
Granted
Oct 21, 2025
Kind
B2
Abstract

Technologies for token-based access authorization to an application program interface (API) include an access management server to receive a service request message from an application executed by a remote computing device. The service request message includes a digitally signed license token previously generated by the access management server and distributed to the remote computing device. The service request message also includes a request from the executed application to access data or a service of the resource server via an exposed API. The access management server verifies the digital signature of the digitally signed license token and generates a digitally signed Security Assertion Markup Language (SAML) token. The digitally signed SAML token is transmitted to the resource server for verification and local caching. The resource server receives the service request message and determines whether access to the requested data or service is authorized based on the locally-cached SAML token.

Claims (37)

1. A method for authenticating a distributed computing resource of a requesting entity to access a resource or a service of a resource server, the method comprising:

receiving, by the resource server, a token including one or more entitlements for the requesting entity from an access management server;

decrypting, by the resource server, a digital signature appended to the token to obtain a previously-generated hash value of the token;

generating, by the resource server, a new hash value of the token;

locally caching, by the resource server, the token and the one or more entitlements, based on determining that the previously-generated hash value of the token matches the new hash value of the token;

determining, by the resource server, that the requesting entity is authorized to access the resource or the service of the resource server, based on the token and the one or more entitlements that are locally-cached by the resource server; and

granting, by the resource server, access to the resource or the service of the resource server, based on determining that the requesting entity is authorized to access the resource or the service of the resource server.

2. The method of claim 1 , wherein the token is a Security Assertion Markup Language (SAML) token.

3. The method of claim 1 , wherein the requesting entity is an independent software vendor (ISV) application executed on a remote computing device.

4. The method of claim 1 , wherein the one or more entitlements define access rights or permissions of the requesting entity with respect to the resource server.

5. The method of claim 1 , wherein the decrypting, by the resource server, the digital signature appended to the token to obtain the previously-generated hash value of the token comprises decrypting, by the resource server, the digital signature appended to the token to obtain the previously-generated hash value of the token using a public key that corresponds to a private key used by the access management server to generate the new hash value of the token.

6. The method of claim 1 , wherein the granting, by the resource server, access to the resource or the service of the resource server comprises granting, by the resource server, access to an application programming interface (API) of the resource server.

7. A resource server comprising:

a memory configured to store instructions; and

a processor configured to execute the instructions to perform operations for authenticating a distributed computing resource of a requesting entity to access a resource or a service of the resource server, the operations comprising:

receiving a token including one or more entitlements for the requesting entity from an access management server;

decrypting a digital signature appended to the token to obtain a previously-generated hash value of the token;

generating a new hash value of the token;

locally caching the token and the one or more entitlements, based on determining that the previously-generated hash value of the token matches the new hash value of the token;

determining that the requesting entity is authorized to access the resource or the service of the resource server, based on the token and the one or more entitlements that are locally-cached by the resource server; and

granting access to the resource or the service of the resource server, based on determining that the requesting entity is authorized to access the resource or the service of the resource server.

8. The resource server of claim 7 , wherein the token is a Security Assertion Markup Language (SAML) token.

9. The resource server of claim 7 , wherein the requesting entity is an independent software vendor (ISV) application executed on a remote computing device.

10. The resource server of claim 7 , wherein the one or more entitlements define access rights or permissions of the requesting entity with respect to the resource server.

11. The resource server of claim 7 , wherein the decrypting the digital signature appended to the token to obtain the previously-generated hash value of the token comprises decrypting the digital signature appended to the token to obtain the previously-generated hash value of the token using a public key that corresponds to a private key used by the access management server to generate the new hash value of the token.

12. The resource server of claim 7 , wherein the granting access to the resource or the service of the resource server comprises granting access to an application programming interface (API) of the resource server.

13. A non-transitory computer-readable medium storing instructions that, when executed by a processor of a resource server, cause the processor to perform operations for authenticating a distributed computing resource of a requesting entity to access a resource or a service of the resource server, the operations comprising:

receiving a token including one or more entitlements for the requesting entity from an access management server;

decrypting a digital signature appended to the token to obtain a previously-generated hash value of the token;

generating a new hash value of the token;

locally caching the token and the one or more entitlements, based on determining that the previously-generated hash value of the token matches the new hash value of the token;

determining that the requesting entity is authorized to access the resource or the service of the resource server, based on the token and the one or more entitlements that are locally-cached by the resource server; and

granting access to the resource or the service of the resource server, based on determining that the requesting entity is authorized to access the resource or the service of the resource server.

14. The non-transitory computer-readable medium of claim 13 , wherein the token is a Security Assertion Markup Language (SAML) token.

15. The non-transitory computer-readable medium of claim 13 , wherein the requesting entity is an independent software vendor (ISV) application executed on a remote computing device.

16. The non-transitory computer-readable medium of claim 13 , wherein the one or more entitlements define access rights or permissions of the requesting entity with respect to the resource server.

17. The non-transitory computer-readable medium of claim 13 , wherein the decrypting the digital signature appended to the token to obtain the previously-generated hash value of the token comprises decrypting the digital signature appended to the token to obtain the previously-generated hash value of the token using a public key that corresponds to a private key used by the access management server to generate the new hash value of the token.

Assignments (6)
RELEASE OF SECURITY INTERESTS RECORDED AT REEL/FRAMES 066626/0655, 066625/0426, 066625/0347, AND 066625/0276 Recorded Jan 12, 2026
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: WORLDPAY, LLC; WORLDPAY ISO AND ECOMMERCE, LLC; PAYMETRIC, LLC; WORLDPAY US, LLC
Reel/Frame 074314/0622 →
RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY RECORDED AT R/F 066624/0719 Recorded Jan 12, 2026
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: WORLDPAY, LLC
Reel/Frame 074315/0412 →
SECURITY INTEREST Recorded Feb 19, 2024
From: WORLDPAY, LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 066624/0719 →
SECURITY INTEREST Recorded Feb 19, 2024
From: WORLDPAY, LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 066626/0655 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2023
From: BLASI, SCOTT EDWARD
To: VANTIV, LLC
Reel/Frame 064113/0936 →
CHANGE OF NAME Recorded Jun 29, 2023
From: VANTIV, LLC
To: WORLDPAY, LLC
Reel/Frame 064164/0654 →
Continuity (6)
Continuation 17895664 · Aug 25, 2022
Continuation 17154814 · Jan 21, 2021
Continuation 16456245 · Jun 28, 2019
Continuation 16010869 · Jun 18, 2018
Continuation 15162936 · May 24, 2016
Related Publication 20230353552A1 · Nov 2, 2023
References Cited (36)
US 8788836B1 · Hernacki · 2014 [cited by examiner]
US 9059853B1 · Bortz · 2015 [cited by examiner]
US 9135412B1 · Talvensaari · 2015 [cited by examiner]
US 9288208B1 · Roth · 2016 [cited by examiner]
US 9380050B2 · Tredoux · 2016 [cited by examiner]
US 9515836B2 · Tredoux · 2016 [cited by examiner]
US 9740759B1 · Zhang · 2017 [cited by examiner]
US 10057246B1 · Drozd · 2018 [cited by examiner]
US 10102526B1 · Madisetti · 2018 [cited by examiner]
US 20040025022A1 · Yach · 2004 [cited by examiner]
US 20050235148A1 · Scheidt · 2005 [cited by examiner]
US 20100146290A1 · Bachmann · 2010 [cited by examiner]
US 20120011244A1 · Zhu · 2012 [cited by examiner]
US 20120089841A1 · Boyer · 2012 [cited by examiner]
US 20120179907A1 · Byrd · 2012 [cited by examiner]
US 20130042115A1 · Sweet · 2013 [cited by examiner]
US 20130145150A1 · Yach et al. · 2013 [cited by applicant]
US 20130152180A1 · Nair · 2013 [cited by examiner]
US 20130226813A1 · Voltz · 2013 [cited by examiner]
US 20130305394A1 · Nozue · 2013 [cited by examiner]
US 20140075556A1 · Wicherski · 2014 [cited by examiner]
US 20140075568A1 · Sathyadevan · 2014 [cited by examiner]
US 20140208096A1 · Brandwine · 2014 [cited by examiner]
US 20150026049A1 · Theurer · 2015 [cited by examiner]
US 20150121462A1 · Courage · 2015 [cited by examiner]
US 20150121517A1 · Dimov · 2015 [cited by examiner]
US 20160134599A1 · Ross · 2016 [cited by examiner]
US 20160232214A1 · Bonda · 2016 [cited by examiner]
US 20160380773A1 · Woodworth · 2016 [cited by examiner]
US 20170026177A1 · Pilcher · 2017 [cited by examiner]
US 20170111336A1 · Davis · 2017 [cited by examiner]
US 20170346804A1 · Beecham · 2017 [cited by examiner]
US 20170346807A1 · Blasi · 2017 [cited by examiner]
US 20170372294A1 · Pelletier · 2017 [cited by examiner]
US 20180309746A1 · Blasi · 2018 [cited by examiner]
US 20190349363A1 · Layouni · 2019 [cited by examiner]