IP Library Granted Patent US 12,568,079
Granted Patent B2
US 12,568,079 · App. 18/642,869 · Granted Mar 3, 2026

Authorizing front-end devices with tokens

Inventor: Tejen Shrestha (Denver, CO)
Assignee: Capital One Services, LLC
H04L63/0853H04L63/102
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,568,079
App. No.
18/642,869
Granted
Mar 3, 2026
Kind
B2
Abstract

In some implementations, a token client may transmit, to a token server, a request for a token associated with the front-end device and derived from a secret associated with the front-end device. The token client may receive, from the token server, the token in response to the request for the token and may transmit, to the front-end device, the token. The token client may determine an expiry associated with the token. The token client may transmit, to the token server, a request for a new token prior to the expiry associated with the token. The token client may receive, from the token server, the new token in response to the request for the new token and may transmit, to the front-end device, the new token.

Claims (60)

1 . A method of authorizing a front-end device, comprising:

receiving, from a token client, a web token associated with the front-end device and derived from information associated with the front-end device;

verifying the web token by decrypting the web token using a cryptographic key corresponding to the front-end device;

authenticating the front-end device based on the verified web token;

storing the web token in a registry corresponding to the front-end device, wherein the registry is configured to periodically update the web token based on a predefined schedule and detect token expiry;

transmitting, to a proxy device, a request corresponding to an action based at least in part on the stored web token; and

outputting, via an output component corresponding to the front-end device, status information indicating a status of the action, the status information corresponding to a status message received from the proxy device.

2 . The method of claim 1 , wherein storing the web token comprises:

storing the web token in a registry corresponding to the front-end device.

3 . The method of claim 1 , wherein receiving the web token comprises:

transmitting, to a token client, a request for authorization; and

receiving, from the token client, the web token in response to the request for authorization.

4 . The method of claim 1 , wherein the web token is a first token, and wherein the method further comprises:

receiving, from a token client, a second token associated with the front-end device, the second token including a signature derived from the information using a cryptographic algorithm; and

overwriting the first token with the second token.

5 . The method of claim 1 , wherein the request includes the web token in a header of the request.

6 . The method of claim 1 , further comprising:

detecting expiry of the web token; and

transmitting, to a token client, a request for authorization based on the expiry of the web token.

7 . The method of claim 1 , wherein the status message indicates the status of the action based at least in part on an authorization attempt using the web token.

8 . The method of claim 1 , wherein the web token indicates an expiry time or use threshold, and

wherein the method further comprises:

decoding the web token to identify the expiry time or a use-based expiry corresponding to the web token.

9 . A system for authorizing a front-end device, the system comprising:

one or more memories; and

one or more processors, coupled to the one or more memories, configured to:

receive, from the front-end device, a request to perform an action, wherein the request includes a web token associated with the front-end device;

verify the web token by decrypting the web token using a cryptographic key corresponding to the front-end device;

authenticate the front-end device based on the verified web token;

store the web token in a registry associated with the front-end device, wherein the registry is configured to periodically update the web token based on a predefined schedule and detect token expiry:

transmit, to a token server, a request for a new token prior to an expiry corresponding to the web token;

receive, from the token server, the new token in response to the request for the new token; and

transmit, to the front-end device, the new token.

10 . The system of claim 9 , wherein the one or more processors are further configured to:

receive, from the front-end device, a request for authorization, wherein the request for the web token is transmitted based on the request for authorization.

11 . The system of claim 9 , wherein the one or more processors, to transmit the request for the new token, are configured to:

transmit the request for the new token according to a schedule, wherein the schedule is associated with an interval that ends earlier than the expiry associated with the web token.

12 . The system of claim 9 , wherein the request for the web token includes an identifier associated with the front-end device.

13 . The system of claim 12 , wherein the one or more processors are further configured to:

receive, from the front-end device, the identifier associated with the front-end device.

14 . The system of claim 9 , wherein the web token comprises a JavaScript object notation web token.

15 . A non-transitory computer-readable medium storing a set of instructions for authorizing an automated teller machine, the set of instructions comprising:

one or more instructions that, when executed by one or more processors of a device, cause the device to:

receive, from the automated teller machine, a request to perform an action, wherein the request includes a web token corresponding to the automated teller machine;

verify the web token by decrypting the web token using a cryptographic key corresponding to the automated teller machine;

authenticate the automated teller machine based on the verified web token; and

update a token status in a registry maintained by the device.

16 . The non-transitory computer-readable medium of claim 15 , wherein the one or more instructions, when executed by the one or more processors, further cause the device to:

extract the web token from a header of the request to perform the action.

17 . The non-transitory computer-readable medium of claim 15 , wherein the one or more instructions, that cause the device to verify the web token, cause the device to:

perform an application programming interface (API) call, including the web token as an argument, to an authentication function; and

verify the web token based on a response from the authentication function.

18 . The non-transitory computer-readable medium of claim 15 , wherein the one or more instructions, when executed by the one or more processors, further cause the device to:

receive, via a network, an additional request, including the web token;

determine that the web token is expired; and

transmit, via the network, a failure message based on expiry of the web token.

19 . The non-transitory computer-readable medium of claim 18 , wherein the one or more instructions, that cause the device to determine that the web token is expired, cause the device to:

perform an application programming interface (API) call, including the web token as an argument, to an authentication function; and

determine that the web token is expired based on a response from the authentication function.

20 . The non-transitory computer-readable medium of claim 15 , wherein the web token comprises a JavaScript object notation web token.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 23, 2024
From: SHRESTHA, TEJEN
To: CAPITAL ONE SERVICES, LLC
Reel/Frame 067191/0440 →
Continuity (2)
Continuation 18188983 · Mar 23, 2023
Related Publication 20240323183A1 · Sep 26, 2024
References Cited (17)
US 11510092B1 · Dawson · 2022 [cited by examiner]
US 11899670B1 · Bhagat · 2024 [cited by examiner]
US 20190007212A1 · Neve de Mevergnies · 2019 [cited by examiner]
US 20190372958A1 · Dunjic et al. · 2019 [cited by applicant]
US 20200125700A1 · Chang · 2020 [cited by examiner]
US 20200244066A1 · Kerhoas · 2020 [cited by examiner]
US 20210027279A1 · Hammad · 2021 [cited by applicant]
US 20210042743A1 · Green · 2021 [cited by examiner]
US 20220224535A1 · Coffing · 2022 [cited by applicant]
US 20220407866A1 · Tanutama et al. · 2022 [cited by applicant]
WO 2020076854A2 · 2020 [cited by applicant]
International Search Report and Written Opinion for International Application No. PCT/US2024/012340, mailed on Apr. 9, 2024, 10 Pages. [cited by applicant]
Adam S.I., et al., “Restful Web Service Implementation on Unklab Information System Using JSON Web Token (JWT),” 2020 2nd International Conference on Cybernetics and Intelligent System (ICORIS), 2020, 7 pages. [cited by applicant]
Co-pending U.S. Appl. No. 18/188,983, inventor Shrestha; Tejen, filed on Mar. 23, 2023. [cited by applicant]
Ethelbert O., et al., “A JSOM Token-based Authentication and Access Management Schema for Cloud SaaS Applications,” Institute of Informatics, 2017, 6 pages. [cited by applicant]
Jones M., et al., “JSON Web Token (JWT),” Internet Engineering Task Force (IETF), 2015, pp. 1-30. [cited by applicant]
Setiawan A., et al., “Implementasi JSON Web Token Berbasis Algoritma SHA-512 Untuk Otentikasi Aplikasi Batikkita,” Jurnal Resti, 2020, vol. 4(6), pp. 1036-1045. [cited by applicant]