IP Library › Granted Patent US 12,476,961
Granted Patent B2
US 12,476,961 · App. 18/470,198 · Granted Nov 18, 2025

Systems and methods for generating digital access tokens independently comsumable by a piggy-back service system

Inventors: Alan Vangpat (Pittsburgh, PA); Koson Thambundit (San Francisco, CA)
H04L63/083H04L63/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,476,961
App. No.
18/470,198
Granted
Nov 18, 2025
Kind
B2
Abstract

A method and system for generating a digital access token consumable by a piggy-back service system has been developed. A request for a digital access token for a client is received. The digital access token is associated with a tenant. At least one standard claim associated with a client attribute of the client is generated. The digital access token includes a header, a payload, and a signature. The payload includes the at least one standard claim associated with the client attribute. The digital access token enables the piggy-back service system to independently authorize access by the client to at least one service at the piggy-back service system based on the at least one standard claim. The digital access token is transmitted to a first device associated with the client.

Claims (72)

1 . A method for generating a digital access token consumable by a piggy-back service system, the method comprising:

receiving a request for the digital access token for a client, the digital access token being associated with a tenant;

generating at least one standard claim associated with a client attribute of the client;

generating the digital access token comprising a header, a payload, and a signature, wherein the payload includes the at least one standard claim associated with the client attribute and the digital access token enables the piggy-back service system to independently authorize access by the client to at least one service at the piggy-back service system based on the at least one standard claim; and

transmitting the digital access token to a first device associated with the client.

2 . The method of claim 1 , wherein the method further comprises:

determining a first client attribute, the first client attribute being a tenant identifier for the tenant;

generating a first standard claim comprising the tenant identifier for inclusion in the payload; and

generating the signature based on the header and the payload using a tenant specific private key associated with the tenant wherein the first standard claim in the payload enables the piggy-back service system to fetch a tenant specific public key associated with the tenant identifier to validate the signature.

3 . The method of claim 1 , wherein the method further comprises:

generating a digital token type of the digital access token, the digital token type defining a format and a version of the digital access token including the at least one standard claim in the payload; and

generating the header to include the digital token type to enable the piggy-back service system to assess the digital access token for authorization in accordance with the digital token type.

4 . The method of claim 1 , wherein the method further comprises:

determining a second client attribute, the second client attribute being a role with respect to the tenant; and

generating a second standard claim comprising the role for inclusion in the payload, wherein the second standard claim in the payload enables the piggy-back service system to authorize at least one permission associated with the access by the client to the at least one service at the piggy-back service system based on the role.

5 . The method of claim 4 , further comprising:

receiving a first token scope handler tied to a first open authorization scope, the first open authorization scope being associated with the inclusion of the role in the payload as the second standard claim; and

injecting the role as the second standard claim in the payload of the digital access token in accordance with the first open authorization scope using the first token scope handler.

6 . The method of claim 1 , wherein the method further comprises:

determining a third client attribute, the third client attribute being tenant level access provided to the client by the tenant; and

generating a third standard claim comprising the tenant level access for inclusion in the payload, wherein the third standard claim in the payload enables the piggy-back service system to authorize at least one permission associated with the access by the client to the at least one service at the piggy-back service system based on the tenant level access.

7 . The method of claim 6 , further comprising:

receiving a second token scope handler tied to a second open authorization scope, the second open authorization scope being associated with the inclusion of the tenant level access in the payload as the third standard claim; and

injecting the tenant level access as the third standard claim in the payload of the digital access token in accordance with the second open authorization scope using the second token scope handler.

8 . The method of claim 1 , wherein the payload includes a standard subject claim and the method further comprises:

receiving an identity of the client;

determining a fourth client attribute, the fourth client attribute being an identity type based on one of the identity of the client and a user authorizing the request for the digital access token; and

generating the standard subject claim to including the identity and the identity type for inclusion in the payload, wherein the standard subject claim in the payload enables the piggy-back service system to authorize permissions associated with the access by the client to the at least one service at the piggy-back service system based on the identify type.

9 . The method of claim 8 , further comprising:

receiving a third token scope handler tied to a third open authorization scope, the third open authorization scope being associated with the inclusion of the identity type in the standard subject claim of the payload; and

injecting the identity and the identity type as the standard subject claim in the payload of the digital access token in accordance with the third open authorization scope using the third token scope handler.

10 . The method of claim 1 , further comprising:

identifying at least one tenant specific token setting for association with the digital access token; and

enabling the at least one tenant specific token setting of the digital access token prior to transmission of the digital access token to the first device.

11 . The method of claim 10 , further comprising:

receiving a fourth token scope handler tied to a fourth open authorization scope, the fourth open authorization scope being associated with the at least one tenant specific setting; and

associating the at least one tenant specific token setting with the digital access token in accordance with the fourth open authorization scope using the fourth token scope handler.

12 . A system for generating a digital access token consumable by a piggy-back service system, the system comprising:

at least one processor; and

at least one non-transitory machine-readable storage medium that stores instructions configurable to be executed by the at least one processor to:

receive a request for the digital access token for a client, the digital access token being associated with a tenant;

generate at least one standard claim associated with a client attribute of the client;

generate the digital access token comprising a header, a payload, and a signature, wherein the payload includes the at least one standard claim associated with the client attribute and the digital access token enables the piggy-back service system to independently authorize access by the client to at least one service at the piggy-back service system based on the at least one standard claim; and

transmit the digital access token to a first device associated with the client.

13 . The system of claim 12 , wherein the instructions are configurable to be executed by the at least one processor to

determine a first client attribute, the first client attribute being a tenant identifier associated with the tenant;

generate a first standard claim comprising the tenant identifier for inclusion in the payload; and

generate the signature based on the header and the payload using a tenant specific private key associated with the tenant, wherein the first standard claim in the payload enables the piggy-back service system to fetch a tenant specific public key associated with the tenant identifier to validate the signature.

14 . The system of claim 12 , wherein the instructions are configurable to be executed by the at least one processor to:

determine a second client attribute, the first second client attribute being a role with respect to the tenant; and

generate a second standard claim comprising the role for inclusion in the payload, wherein the second standard claim in the payload enables the piggy-back service system to authorize at least one permission associated with the access by the client to the at least one service at the piggy-back service system based on the role.

15 . The system of claim 12 , wherein the instructions are configurable to be executed by the at least one processor to:

determine a third client attribute, the third client attribute being tenant level access provided to the client by the tenant; and

generate a third standard claim comprising the tenant level access for inclusion in the payload, wherein the third standard claim in the payload enables the piggy-back service system to authorize at least one permission associated with the access by the client to the at least one service at the piggy-back service system based on the tenant level access.

16 . A non-transitory machine-readable storage medium that stores instructions executable by at least one processor, the instructions configurable to cause the at least one processor to perform operations comprising:

receiving a request for a digital access token for a client, the digital access token being associated with a tenant;

generating at least one standard claim associated with a client attribute of the client;

generating the digital access token comprising a header, a payload, and a signature, wherein the payload includes the at least one standard claim associated with the client attribute and the digital access token enables a piggy-back service system to independently authorize access by the client to at least one service at the piggy-back service system based on the at least one standard claim; and

transmitting the digital access token to a first device associated with the client.

17 . The non-transitory machine-readable storage medium of claim 16 , wherein the instructions are configurable to cause the at least one processor to further perform operations comprising:

determining a first client attribute, the first client attribute being a tenant identifier of the tenant;

generating a first standard claim comprising the tenant identifier for inclusion in the payload; and

generating the signature based on the header and the payload using a tenant specific private key associated with the tenant, wherein the first standard claim in the payload enables the piggy-back service system to fetch a tenant specific public key associated with the tenant identifier to validate the signature.

18 . The non-transitory machine-readable storage medium of claim 16 , wherein the instructions are configurable to cause the at least one processor to further perform operations comprising:

generating at least one tenant specific token setting for association with the digital access token; and

enabling the at least one tenant specific token setting of the digital access token prior to transmission of the digital access token to the first device.

19 . The non-transitory machine-readable storage medium of claim 16 , wherein the instructions are configurable to cause the at least one processor to further perform operations comprising:

determining a second client attribute, the first second client attribute being a role with respect to the tenant; and

generating a second standard claim comprising the role for inclusion in the payload, wherein the second standard claim in the payload enables the piggy-back service system to authorize at least one permission associated with the access by the client to the at least one service at the piggy-back service system based on the role.

20 . The non-transitory machine-readable storage medium of claim 16 , wherein the instructions are configurable to cause the at least one processor to further perform operations comprising:

determining a third client attribute, the third client attribute being tenant level access provided to the client by the tenant; and

generating a third standard claim comprising the tenant level access for inclusion in the payload, wherein the third standard claim in the payload enables the piggy-back service system to authorize at least one permission associated with the access by the client to the at least one service at the piggy-back service system based on the tenant level access.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 13, 2025
From: VANGPAT, ALAN; THAMBUNDIT, KOSON
To: SALESFORCE, INC.
Reel/Frame 070508/0764 →
Continuity (1)
Related Publication 20250097215A1 · Mar 20, 2025
References Cited (154)
US 5577188A · Zhu · 1996 [cited by applicant]
US 5608872A · Schwartz et al. · 1997 [cited by applicant]
US 5649104A · Carleton et al. · 1997 [cited by applicant]
US 5715450A · Ambrose et al. · 1998 [cited by applicant]
US 5761419A · Schwartz et al. · 1998 [cited by applicant]
US 5819038A · Carleton et al. · 1998 [cited by applicant]
US 5821937A · Tonelli et al. · 1998 [cited by applicant]
US 5831610A · Tonelli et al. · 1998 [cited by applicant]
US 5873096A · Lim et al. · 1999 [cited by applicant]
US 5918159A · Fomukong et al. · 1999 [cited by applicant]
US 5963953A · Cram et al. · 1999 [cited by applicant]
US 6092083A · Brodersen et al. · 2000 [cited by applicant]
US 6161149A · Achacoso et al. · 2000 [cited by applicant]
US 6169534B1 · Raffel et al. · 2001 [cited by applicant]
US 6178425B1 · Brodersen et al. · 2001 [cited by applicant]
US 6189011B1 · Lim et al. · 2001 [cited by applicant]
US 6216135B1 · Brodersen et al. · 2001 [cited by applicant]
US 6233617B1 · Rothwein et al. · 2001 [cited by applicant]
US 6266669B1 · Brodersen et al. · 2001 [cited by applicant]
US 6295530B1 · Ritchie et al. · 2001 [cited by applicant]
US 6324568B1 · Diec et al. · 2001 [cited by applicant]
US 6324693B1 · Brodersen et al. · 2001 [cited by applicant]
US 6336137B1 · Lee et al. · 2002 [cited by applicant]
US D454139S · Feldcamp et al. · 2002 [cited by applicant]
US 6367077B1 · Brodersen et al. · 2002 [cited by applicant]
US 6393605B1 · Loomans · 2002 [cited by applicant]
US 6405220B1 · Brodersen et al. · 2002 [cited by applicant]
US 6434550B1 · Warner et al. · 2002 [cited by applicant]
US 6446089B1 · Brodersen et al. · 2002 [cited by applicant]
US 6535909B1 · Rust · 2003 [cited by applicant]
US 6549908B1 · Loomans · 2003 [cited by applicant]
US 6553563B2 · Ambrose et al. · 2003 [cited by applicant]
US 6560461B1 · Fomukong et al. · 2003 [cited by applicant]
US 6574635B2 · Stauber et al. · 2003 [cited by applicant]
US 6577726B1 · Huang et al. · 2003 [cited by applicant]
US 6601087B1 · Zhu et al. · 2003 [cited by applicant]
US 6604117B2 · Lim et al. · 2003 [cited by applicant]
US 6604128B2 · Diec · 2003 [cited by applicant]
US 6609150B2 · Lee et al. · 2003 [cited by applicant]
US 6621834B1 · Scherpbier et al. · 2003 [cited by applicant]
US 6654032B1 · Zhu et al. · 2003 [cited by applicant]
US 6665648B2 · Brodersen et al. · 2003 [cited by applicant]
US 6665655B1 · Warner et al. · 2003 [cited by applicant]
US 6684438B2 · Brodersen et al. · 2004 [cited by applicant]
US 6711565B1 · Subramaniam et al. · 2004 [cited by applicant]
US 6724399B1 · Katchour et al. · 2004 [cited by applicant]
US 6728702B1 · Subramaniam et al. · 2004 [cited by applicant]
US 6728960B1 · Loomans et al. · 2004 [cited by applicant]
US 6732095B1 · Warshavsky et al. · 2004 [cited by applicant]
US 6732100B1 · Brodersen et al. · 2004 [cited by applicant]
US 6732111B2 · Brodersen et al. · 2004 [cited by applicant]
US 6754681B2 · Brodersen et al. · 2004 [cited by applicant]
US 6763351B1 · Subramaniam et al. · 2004 [cited by applicant]
US 6763501B1 · Zhu et al. · 2004 [cited by applicant]
US 6768904B2 · Kim · 2004 [cited by applicant]
US 6772229B1 · Achacoso et al. · 2004 [cited by applicant]
US 6782383B2 · Subramaniam et al. · 2004 [cited by applicant]
US 6804330B1 · Jones et al. · 2004 [cited by applicant]
US 6826565B2 · Ritchie et al. · 2004 [cited by applicant]
US 6826582B1 · Chatterjee et al. · 2004 [cited by applicant]
US 6826745B2 · Coker · 2004 [cited by applicant]
US 6829655B1 · Huang et al. · 2004 [cited by applicant]
US 6842748B1 · Warner et al. · 2005 [cited by applicant]
US 6850895B2 · Brodersen et al. · 2005 [cited by applicant]
US 6850949B2 · Warner et al. · 2005 [cited by applicant]
US 7062502B1 · Kesler · 2006 [cited by applicant]
US 7069231B1 · Cinarkaya et al. · 2006 [cited by applicant]
US 7181758B1 · Chan · 2007 [cited by applicant]
US 7289976B2 · Kihneman et al. · 2007 [cited by applicant]
US 7340411B2 · Cook · 2008 [cited by applicant]
US 7356482B2 · Frankland et al. · 2008 [cited by applicant]
US 7401094B1 · Kesler · 2008 [cited by applicant]
US 7412455B2 · Dillon · 2008 [cited by applicant]
US 7508789B2 · Chan · 2009 [cited by applicant]
US 7620655B2 · Larsson et al. · 2009 [cited by applicant]
US 7698160B2 · Beaven et al. · 2010 [cited by applicant]
US 7730478B2 · Weissman · 2010 [cited by applicant]
US 7779475B2 · Jakobson et al. · 2010 [cited by applicant]
US 8014943B2 · Jakobson · 2011 [cited by applicant]
US 8015495B2 · Achacoso et al. · 2011 [cited by applicant]
US 8032297B2 · Jakobson · 2011 [cited by applicant]
US 8082301B2 · Ahlgren et al. · 2011 [cited by applicant]
US 8095413B1 · Beaven · 2012 [cited by applicant]
US 8095594B2 · Beaven et al. · 2012 [cited by applicant]
US 8209308B2 · Rueben et al. · 2012 [cited by applicant]
US 8275836B2 · Beaven et al. · 2012 [cited by applicant]
US 8457545B2 · Chan · 2013 [cited by applicant]
US 8484111B2 · Frankland et al. · 2013 [cited by applicant]
US 8490025B2 · Jakobson et al. · 2013 [cited by applicant]
US 8504945B2 · Jakobson et al. · 2013 [cited by applicant]
US 8510045B2 · Rueben et al. · 2013 [cited by applicant]
US 8510664B2 · Rueben et al. · 2013 [cited by applicant]
US 8566301B2 · Rueben et al. · 2013 [cited by applicant]
US 8646103B2 · Jakobson et al. · 2014 [cited by applicant]
US 11716325B2 · Smolny · 2023 [cited by examiner]
US 20010044791A1 · Richter et al. · 2001 [cited by applicant]
US 20020072951A1 · Lee et al. · 2002 [cited by applicant]
US 20020082892A1 · Raffel · 2002 [cited by applicant]
US 20020129352A1 · Brodersen et al. · 2002 [cited by applicant]
US 20020140731A1 · Subramanian et al. · 2002 [cited by applicant]
US 20020143997A1 · Huang et al. · 2002 [cited by applicant]
US 20020162090A1 · Parnell et al. · 2002 [cited by applicant]
US 20020165742A1 · Robbins · 2002 [cited by applicant]
US 20030004971A1 · Gong · 2003 [cited by applicant]
US 20030018705A1 · Chen et al. · 2003 [cited by applicant]
US 20030018830A1 · Chen et al. · 2003 [cited by applicant]
US 20030066031A1 · Laane et al. · 2003 [cited by applicant]
US 20030066032A1 · Ramachandran et al. · 2003 [cited by applicant]
US 20030069936A1 · Warner et al. · 2003 [cited by applicant]
US 20030070000A1 · Coker et al. · 2003 [cited by applicant]
US 20030070004A1 · Mukundan et al. · 2003 [cited by applicant]
US 20030070005A1 · Mukundan et al. · 2003 [cited by applicant]
US 20030074418A1 · Coker et al. · 2003 [cited by applicant]
US 20030120675A1 · Stauber et al. · 2003 [cited by applicant]
US 20030151633A1 · George et al. · 2003 [cited by applicant]
US 20030159136A1 · Huang et al. · 2003 [cited by applicant]
US 20030187921A1 · Diec et al. · 2003 [cited by applicant]
US 20030189600A1 · Gune et al. · 2003 [cited by applicant]
US 20030204427A1 · Gune et al. · 2003 [cited by applicant]
US 20030206192A1 · Chen et al. · 2003 [cited by applicant]
US 20030225730A1 · Warner et al. · 2003 [cited by applicant]
US 20040001092A1 · Rothwein et al. · 2004 [cited by applicant]
US 20040010489A1 · Rio et al. · 2004 [cited by applicant]
US 20040015981A1 · Coker et al. · 2004 [cited by applicant]
US 20040027388A1 · Berg et al. · 2004 [cited by applicant]
US 20040128001A1 · Levin et al. · 2004 [cited by applicant]
US 20040186860A1 · Lee et al. · 2004 [cited by applicant]
US 20040193510A1 · Catahan et al. · 2004 [cited by applicant]
US 20040199489A1 · Barnes-Leon et al. · 2004 [cited by applicant]
US 20040199536A1 · Barnes-Leon et al. · 2004 [cited by applicant]
US 20040199543A1 · Braud et al. · 2004 [cited by applicant]
US 20040249854A1 · Barnes-Leon et al. · 2004 [cited by applicant]
US 20040260534A1 · Pak et al. · 2004 [cited by applicant]
US 20040260659A1 · Chan et al. · 2004 [cited by applicant]
US 20040268299A1 · Lei et al. · 2004 [cited by applicant]
US 20050050555A1 · Exley et al. · 2005 [cited by applicant]
US 20050091098A1 · Brodersen et al. · 2005 [cited by applicant]
US 20060021019A1 · Hinton et al. · 2006 [cited by applicant]
US 20070294426A1 · Huang · 2007 [cited by examiner]
US 20080249972A1 · Dillon · 2008 [cited by applicant]
US 20090063414A1 · White et al. · 2009 [cited by applicant]
US 20090100342A1 · Jakobson · 2009 [cited by applicant]
US 20090177744A1 · Marlow et al. · 2009 [cited by applicant]
US 20110247051A1 · Bulumulla et al. · 2011 [cited by applicant]
US 20120042218A1 · Cinarkaya et al. · 2012 [cited by applicant]
US 20120218958A1 · Rangaiah · 2012 [cited by applicant]
US 20120233137A1 · Jakobson et al. · 2012 [cited by applicant]
US 20130212497A1 · Zelenko et al. · 2013 [cited by applicant]
US 20130218948A1 · Jakobson · 2013 [cited by applicant]
US 20130218949A1 · Jakobson · 2013 [cited by applicant]
US 20130218966A1 · Jakobson · 2013 [cited by applicant]
US 20130247216A1 · Cinarkaya et al. · 2013 [cited by applicant]
US 20210409400A1 · Palanisamy · 2021 [cited by examiner]
US 20230351030A1 · Wang · 2023 [cited by examiner]