IP Library › Granted Patent US 11,902,289
Granted Patent B2
US 11,902,289 · App. 17/028,016 · Granted Feb 13, 2024

Methods and systems for controlling access to a protected resource

Inventors: Milos Dunjic (Oakville, CA); Anthony Haituyen Nguyen (Toronto, CA); Yubing Liu (Toronto, CA); Arthur Carroll Chow (Markham, CA); Casey Lyn Doyle (Ajax, CA); Richard John Frederick Thake (Cobourg, CA); Mengfei Wang (Toronto, CA); Aaron Ashish Hudali (Cambridge, CA); Gregory Albert Kliewer (Barrie, CA); Martin Albert Lozon (London, CA); Yusbel Garcia Diaz (Toronto, CA); Gareth Daly (Toronto, CA); Masashi Kobayashi (Toronto, CA); Randall John Bast (Oakville, CA)
Assignee: The Toronto-Dominion Bank
H04L63/123H04L9/0869H04L9/3213H04L9/3247H04L9/3268H04L63/0442H04L63/10H04L9/30
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,902,289
App. No.
17/028,016
Granted
Feb 13, 2024
Kind
B2
Abstract

A computer-implemented method is disclosed. The method includes: receiving, from a web server associated with a protected resource, a first signal including a request to validate a bearer token submitted by a client device to the web server, the bearer token including a digital signature; validating the bearer token, the validating including verifying the digital signature using a public key associated with an end user of the client device; and in response to validating the bearer token, sending to the web server a second signal including a notification that the bearer token is valid.

Claims (27)

1. A network device, comprising:

a communication interface connected to an external network;

a memory; and

a processor coupled to the communication interface and the memory, the processor being configured to:

receive, via the communication interface from a web server associated with a protected resource, a request to validate a bearer token submitted by a client device to the web server, the request including the bearer token, a cryptographic nonce that is based on a user identifier identifying an end user of an application executing on the client device, and a digital signature;

validate the bearer token, the validating including verifying the digital signature using a public key associated with the end user; and

in response to validating the bearer token, send to the web server via the communication interface a notification that the bearer token is valid.

2. The network device of claim 1 , wherein the processor is further configured to store the public key in the memory.

3. The network device of claim 1 , wherein the cryptographic nonce comprises a combination of a client identifier identifying the application executing on the client device, the user identifier identifying the end user of the application, and a salt value.

4. The network device of claim 1 , wherein the digital signature is generated based on a message that includes a combination of a first representation of an access token for accessing the protected resource and the cryptographic nonce.

5. The network device of claim 4 , wherein the digital signature is generated using a private key corresponding to the public key, the private key being stored in a hardware-based key manager that is isolated from the processor.

6. The network device of claim 5 , wherein the digital signature is generated in the hardware-based key manager.

7. The network device of claim 1 , wherein the bearer token has an associated expiry period and wherein the processor is further configured to store the cryptographic nonce in the memory for duration of the expiry period of the bearer token.

8. The network device of claim 1 , wherein sending the notification to the web server comprises generating a message and signing the generated message using a private key.

9. The network device of claim 1 , wherein the validating further includes verifying the cryptographic nonce.

10. A method comprising:

receiving, from a web server associated with a protected resource, a request to validate a bearer token submitted by a client device to the web server, the including the bearer token, a cryptographic nonce that is based on a user identifier identifying an end user of an application executing on the client device, and a digital signature;

validating the bearer token, the validating including verifying the digital signature using a public key associated with the end user; and

in response to validating the bearer token, sending to the web server a notification that the bearer token is valid.

11. The method of claim 10 , further comprising storing the public key in a memory.

12. The method of claim 10 , wherein the cryptographic nonce comprises a combination of a client identifier identifying the application executing on the client device, the user identifier identifying the end user of the application, and a salt value.

13. The method of claim 10 , wherein the digital signature is generated based on a message that includes a combination of a first representation of an access token for accessing the protected resource and the cryptographic nonce.

14. The method of claim 13 , wherein the digital signature is generated using a private key corresponding to the public key, the private key being stored in a hardware-based key manager.

15. The method of claim 14 , wherein the digital signature is generated in the hardware-based key manager.

16. The method of claim 10 , wherein the bearer token has an associated expiry period and wherein the method further comprises storing the nonce in a memory for duration of the expiry period of the bearer token.

17. The method of claim 10 , wherein sending the notification to the web server comprises generating a message and signing the generated message using a private key.

18. The method of claim 10 , wherein the validating further includes verifying the cryptographic nonce.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 22, 2020
From: DUNJIC, MILOS; NGUYEN, ANTHONY HAITUYEN; LIU, YUBING; CHOW, ARTHUR CARROLL; THAKE, RICHARD JOHN FREDERICK; DOYLE, CASEY LYN; WANG, MENGFEI; HUDALI, AARON ASHISH; KLIEWER, GREGORY ALBERT; LOZON, MARTIN ALBERT; DIAZ, YUSBEL GARCIA; DALY, GARETH; KOBAYASHI, MASASHI; BAST, RANDALL JOHN
To: THE TORONTO-DOMINION BANK
Reel/Frame 053842/0741 →
Continuity (2)
Continuation 16000086 · Jun 5, 2018
Related Publication 20210006566A1 · Jan 7, 2021
Cited By (3)
US 12,423,475 US 12,572,693 US 12,719,683