IP Library Granted Patent US 12,463,813
Granted Patent B2
US 12,463,813 · App. 18/363,210 · Granted Nov 4, 2025

Method, device, and non-transitory computer readable medium for generating and managing cryptographic keys

Inventor: Valery Zubovsky (San Francisco, CA)
Assignee: CHARLES SCHWAB & CO., INC.
H04L9/3213H04L9/0891
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,463,813
App. No.
18/363,210
Granted
Nov 4, 2025
Kind
B2
Abstract

An authorization server, method, and non-transitory computer readable medium for generating and managing at least one access token associated with a client. The authorization server may include a memory configured to store computer readable instructions; and processing circuitry configured to execute the computer readable instructions to cause the authorization server to, compute an encryption key based on information associated with a user session, embed the encryption key into the at least one access token, map, within a database, the at least one access token to an access token handle associated with the client, return the access token handle to the client, and selectively provide the access token to at least one web Application Programming Interface (API) in response to receipt of the access token handle from the at least one web API.

Claims (46)

1 . A method of operating an authorization server, the method comprising:

computing an encryption key based on information associated with a user session with a client;

embedding the encryption key into at least one access token;

mapping, within a database, the at least one access token to an access token handle associated with the user session;

returning the access token handle to the client; and

selectively providing the access token to at least one web Application Programming Interface (API) in response to receipt of the access token handle from the at least one web API.

2 . The method of claim 1 , wherein the computing the encryption key comprises:

computing the encryption key based on a refresh token associated with the user session.

3 . The method of claim 2 , wherein the computing the encryption key based on the refresh token is such that, while the at least one access token having the encryption key embedded therein expires during the user session, the encryption key and the refresh token used to compute the encryption key remain same during the user session and are modified during a subsequent user session.

4 . The method of claim 2 , wherein the returning the access token handle to the client comprises:

returning the access token handle to the client in lieu of returning the access token, in response to receipt of an access token request containing the refresh token.

5 . An authorization server configured to generate and manage at least one access token associated with a client, the authorization server comprising:

a memory configured to store computer readable instructions; and

processing circuitry configured to execute the computer readable instructions to cause the authorization server to,

compute an encryption key based on information associated with a user session with the client,

embed the encryption key into the at least one access token,

map, within a database, the at least one access token to an access token handle associated with the client,

return the access token handle to the client, and

selectively provide the access token to at least one web Application Programming Interface (API) in response to receipt of the access token handle from the at least one web API.

6 . The authorization server of claim 5 , wherein the authorization server is configured to compute the encryption key based on a refresh token associated with the user session.

7 . The authorization server of claim 6 , wherein the authorization server is configured to compute the encryption key based on the refresh token such that, while the at least one access token having the encryption key embedded therein expires during the user session, the encryption key and the refresh token used to compute the encryption key remain same during the user session and are modified during a subsequent user session.

8 . The authorization server of claim 6 , wherein the authorization server is configured to return the access token handle to the client in lieu of returning the access token, in response to receipt of an access token request containing the refresh token.

9 . The authorization server of claim 6 , wherein upon validating the client, the authorization server is further configured to map the refresh token to an authorization code, and to return the authorization code to the client.

10 . The authorization server of claim 9 , wherein the authorization server is further configured to subsequently return the refresh token in response to receipt of the authorization code.

11 . The authorization server of claim 10 , wherein the authorization server is configured to subsequently return the refresh token to a web server in response to receipt of the authorization code from the web server, the refresh token being usable by the web server to retrieve the access token handle.

12 . The authorization server of claim 5 , wherein the client includes one of a web browser or a mobile application outside of a secure network, and the at least one web API is within the secure network, and the authorization server is configured to return the access token handle to the web browser or to the mobile application in lieu of returning the access token, and to selectively provide the access token to the at least one web API within the secure network such that the access token remains within the secure network.

13 . The authorization server of claim 5 , wherein the authorization server is configured to,

determine whether a match exists between the access token handle received from the at least one web API and the access token handle stored within the database, and

selectively provide the at least one access token to the at least one web API, in response to determining that the match exists.

14 . The authorization server of claim 5 , wherein the at least one web API includes a first web API and a second web API, and the authorization server is configured to,

embed the encryption key into a first access token of the at least one access token and provide the first access token to the first web API, and

embed the encryption key into a second access token of the at least one access token different from the first access token and provide the first access token to the first web API.

15 . The authorization server of claim 14 , wherein the authorization server is configured to embed the encryption key into the first access token and the second access token such that the encryption key is same in the first access token and the second access token.

16 . The authorization server of claim 14 , wherein

the first web API is configured to perform an encryption operation on data using the encryption key embedded in the first access token to generate encrypted data, and

the second web API is configured to perform a decryption operation on the encrypted data using the encryption key embedded in the second access token.

17 . A non-transitory computer readable medium comprising computer readable code that, when executed by an authorization server, configures the authorization server to:

compute an encryption key based on information associated with a user session with a client;

embed the encryption key into at least one access token;

map, within a database, the at least one access token to an access token handle associated with the user session;

return the access token handle to the client; and

selectively provide the access token to at least one web Application Programming Interface (API) in response to receipt of the access token handle from the at least one web API.

18 . The non-transitory computer readable medium of claim 17 , wherein the computer readable code, when executed by the authorization server, configures the authorization server to:

compute the encryption key based on a refresh token associated with the user session.

19 . The non-transitory computer readable medium of claim 18 , wherein the computer readable code, when executed by the authorization server, configures the authorization server to compute the encryption key based the refresh token such that, while the at least one access token having the encryption key embedded therein expires during the user session, the encryption key and the refresh token used to compute the encryption key remain same during the user session and are modified during a subsequent user session.

20 . The non-transitory computer readable medium of claim 18 , wherein the computer readable code, when executed by the authorization server, configures the authorization server to return the access token handle to the client in lieu of returning the access token, in response to receipt of an access token request containing the refresh token.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 2, 2023
From: ZUBOVSKY, VALERY
To: CHARLES SCHWAB & CO., INC
Reel/Frame 064467/0897 →
Continuity (1)
Related Publication 20250047490A1 · Feb 6, 2025
References Cited (12)
US 8020007B1 · Zubovsky · 2011 [cited by examiner]
US 8522323B1 · Zubovsky · 2013 [cited by examiner]
US 8713695B2 · Harada · 2014 [cited by examiner]
US 11810113B2 · Dey · 2023 [cited by examiner]
US 20100146613A1 · Hall · 2010 [cited by examiner]
US 20100306547A1 · Fallows · 2010 [cited by examiner]
US 20130073862A1 · Harada · 2013 [cited by examiner]
US 20200145384A1 · Chauhan · 2020 [cited by examiner]
US 20210288808A1 · Bahety · 2021 [cited by examiner]
US 20220038441A1 · Chauhan · 2022 [cited by examiner]
US 20230102161A1 · Dey · 2023 [cited by examiner]
US 20230283711A1 · Gupta · 2023 [cited by examiner]