IP Library › Granted Patent US 10,887,301
Granted Patent B1
US 10,887,301 · App. 16/218,191 · Granted Jan 5, 2021

Client registration for authorization

Inventors: Alejandro Vera (San Antonio, TX); Miguel Solis, Jr. (San Antonio, TX); Hieu Nguyen (Southlake, TX); Jason Paul Hendry (Selma, TX); Nathan Mahoney (New Braunfels, TX); Debra Randall Casillas (Helotes, TX)
Assignee: United Services Automobile Association (USAA)
H04L63/0807G06F16/1824G06F16/1834H04L9/0643H04L63/0884H04L67/16H04L2209/38H04L2209/56
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,887,301
App. No.
16/218,191
Granted
Jan 5, 2021
Kind
B1
Abstract

Techniques are described for client registration for authorizing an aggregator service to access data on behalf of an application, through self-registration of an application client identifier and issuance of authorization token(s) based on the application client identifier. Implementations provide a technique for dynamic client registration that avoids the need for manual vetting and manual generation of the client credential grant. Additionally, the implementations described herein enforce domain values around the scope and/or purpose of the client grant. This allows for support of application providers through a single point of registration that supports multi-layer and channel. This also allows for support of a scalable authorization solution for any suitable number of clients. The dynamic client registration process adds an additional layer of security through the OAuth client grant and mutual authentication.

Claims (55)

1. A computer-implemented method performed by an authorizing service executed by at least one processor, the method comprising:

receiving, at the authorizing service, a first communication from an aggregator service requesting issuance of an application client identifier (ID) that is associated with both the aggregator service and an application, the first communication indicating at least one scope governing access to the authorizing service, wherein the aggregator service is requesting issuance of the application client ID to access the authorizing service on behalf of the application;

in response to the first communication, generating, by the authorizing service, the application client ID and issuing the application client ID to the aggregator service;

receiving, at the authorizing service, a second communication from the aggregator service requesting issuance of at least one authorization token for an end-user of the application, the second communication including the application client ID; and

in response to the second communication, generating, by the authorizing service, the at least one authorization token and issuing the at least one authorization token to the aggregator service that employs the at least one authorization token to access the authorizing service on behalf of the application,

wherein the at least one authorization token is generated and issued based at least partly on receiving permission, from the end-user, to access data of the end-user maintained by the authorizing service, and

wherein the at least one authorization token provides the access according to the at least one scope the permission is provided to access the data of the end-user according to the at least one scope.

2. The method of claim 1 , wherein:

the first communication indicates a purpose for the access to the authorizing service by the application; and

the application client ID is generated and issued based at least partly on determining that the at least one scope is appropriate for the purpose.

3. The method of claim 1 , wherein the permission is received through a user interface (UI) dialog that is presented to the end-user by the aggregator service.

4. The method of claim 3 , wherein:

the first communication includes a logo of the application; and

the UI dialog is presented with the logo.

5. The method of claim 1 , wherein the at least one authorization token includes a refresh token and an access token.

6. The method of claim 1 , wherein the at least one authorization token is associated with a blockchain in a block that corresponds to the aggregator service.

7. The method of claim 6 , wherein the at least one authorization token is a hashed version of a block address of a record in the block.

8. A system, comprising:

at least one processor; and

a memory communicatively coupled to the at least one processor, the memory storing instructions which, when executed by the at least one processor, cause the at least one processor to perform operations comprising:

receiving, at an authorizing service, a first communication from an aggregator service requesting issuance of an application client identifier (ID) that is associated with both the aggregator service and an application, the first communication indicating at least one scope governing access to the authorizing service, wherein the aggregator service is requesting issuance of the application client ID to access the authorizing service on behalf of the application;

in response to the first communication, generating, by the authorizing service, the application client ID and issuing the application client ID to the aggregator service;

receiving, at the authorizing service, a second communication from the aggregator service requesting issuance of at least one authorization token for an end-user of the application, the second communication including the application client ID; and

in response to the second communication, generating, by the authorizing service, the at least one authorization token and issuing the at least one authorization token to the aggregator service that employs the at least one authorization token to access the authorizing service on behalf of the application,

wherein the at least one authorization token is generated and issued based at least partly on receiving permission, from the end-user, to access data of the end-user maintained by the authorizing service, and

wherein the at least one authorization token provides the access according to the at least one scope the permission is provided to access the data of the end-user according to the at least one scope.

9. The system of claim 8 , wherein:

the first communication indicates a purpose for the access to the authorizing service by the application; and

the application client ID is generated and issued based at least partly on determining that the at least one scope is appropriate for the purpose.

10. The system of claim 8 , wherein the permission is received through a user interface (UI) dialog that is presented to the end-user by the aggregator service.

11. The system of claim 10 , wherein:

the first communication includes a logo of the application; and

the UI dialog is presented with the logo.

12. The system of claim 8 , wherein the at least one authorization token includes a refresh token and an access token.

13. The system of claim 8 , wherein:

the at least one authorization token is associated with a blockchain in a block that corresponds to the aggregator service; and

the at least one authorization token is a hashed version of a block address of a record in the block.

14. One or more non-transitory computer-readable media storing instructions which, when executed by at least one processor, cause the at least one processor to perform operations comprising:

receiving, at an authorizing service, a first communication from an aggregator service requesting issuance of an application client identifier (ID) that is associated with both the aggregator service and an application, the first communication indicating at least one scope governing access to the authorizing service, wherein the aggregator service is requesting issuance of the application client ID to access the authorizing service on behalf of the application;

in response to the first communication, generating, by the authorizing service, the application client ID and issuing the application client ID to the aggregator service;

receiving, at the authorizing service, a second communication from the aggregator service requesting issuance of at least one authorization token for an end-user of the application, the second communication including the application client ID; and

in response to the second communication, generating, by the authorizing service, the at least one authorization token and issuing the at least one authorization token to the aggregator service that employs the at least one authorization token to access the authorizing service on behalf of the application,

wherein the at least one authorization token is generated and issued based at least partly on receiving permission, from the end-user, to access data of the end-user maintained by the authorizing service, and

wherein the at least one authorization token provides the access according to the at least one scope the permission is provided to access the data of the end-user according to the at least one scope.

15. The media of claim 14 , wherein:

the first communication indicates a purpose for the access to the authorizing service by the application; and

the application client ID is generated and issued based at least partly on determining that the at least one scope is appropriate for the purpose.

16. The media of claim 14 , wherein the permission is received through a user interface (UI) dialog that is presented to the end-user by the aggregator service.

17. The media of claim 16 , wherein:

the first communication includes a logo of the application; and

the UI dialog is presented with the logo.

18. The media of claim 14 , wherein the at least one authorization token includes a refresh token and an access_token.

19. The media of claim 14 , wherein:

the at least one authorization token is associated with a blockchain in a block that corresponds to the aggregator service; and

the at least one authorization token is a hashed version of a block address of a record in the block.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 22, 2020
From: UIPCO, LLC
To: UNITED SERVICES AUTOMOBILE ASSOCIATION (USAA)
Reel/Frame 053849/0742 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 3, 2019
From: VERA, ALEJANDRO; SOLÍS, MIGUEL, JR.; NGUYEN, HIEU; HENDRY, JASON PAUL; MAHONEY, NATHAN; CASILLAS, DEBRA RANDALL
To: UIPCO, LLC
Reel/Frame 049347/0081 →
Continuity (1)
Provisional Application 62597754 · Dec 12, 2017
Cited By (16)
US 12,206,791 US 12,229,735 US 12,254,463 US 12,265,958 US 12,299,680 US 12,355,747 US 12,381,732 US 12,407,535 US 12,443,933 US 12,463,811 US 12,500,881 US 12,536,530 US 12,537,685 US 12,621,286 US 12,664,531 US 12,711,485