IP Library › Granted Patent US 12,355,747
Granted Patent B1
US 12,355,747 · App. 18/416,194 · Granted Jul 8, 2025

Client registration for authorization

Inventors: Alejandro Vera (San Antonio, TX); Miguel Solís, Jr. (San Antonio, TX); Hieu Nguyen (Southlake, TX); Jason Paul Hendry (New Braunfels, TX); Nathan Mahoney (New Braunfels, TX); Debra Randall Casillas (Helotes, TX)
Assignee: United Services Automobile Association (USAA)
H04L63/0807G06F16/1824G06F16/1834H04L9/0643H04L63/0884H04L67/51H04L9/50H04L2209/56
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,355,747
App. No.
18/416,194
Granted
Jul 8, 2025
Kind
B1
Abstract

Techniques are described for client registration for authorizing an aggregator service to access data on behalf of an application, through self-registration of an application client identifier and issuance of authorization token(s) based on the application client identifier. Implementations provide a technique for dynamic client registration that avoids the need for manual vetting and manual generation of the client credential grant. Additionally, the implementations described herein enforce domain values around the scope and/or purpose of the client grant. This allows for support of application providers through a single point of registration that supports multi-layer and channel. This also allows for support of a scalable authorization solution for any suitable number of clients. The dynamic client registration process adds an additional layer of security through the OAuth client grant and mutual authentication.

Claims (46)

1. A computer-implemented method executed by at least one processor, the method comprising:

receiving a plurality of access requests from a service on behalf of an application, each access request including a token, the token having previously been issued to the service responsive to:

(A) a first communication from the service requesting issuance of an application client identifier (ID), wherein the application client ID is issued to the service in response to the first communication, and

(B) a second communication from the service including the application client ID and requesting issuance of the token; and

responsive to each of the plurality of access requests from the service that include the token:

providing access to data of an end-user in accordance with a permission scope indicated by the token included with the respective access request; and

adding, to a block in a blockchain, data associated with the respective access request, wherein the block in the blockchain holds a history of access requests made by the service.

2. The method of claim 1 , wherein a second block in the blockchain includes a list of one or more client application associated with the token.

3. The method of claim 2 , wherein the token comprises a blockchain address.

4. The method of claim 3 , wherein the token comprises a hashed version of the blockchain address.

5. The method of claim 2 , further comprising, responsive to each access request, determining that the respective access request is valid by comparing a current blockchain record with a previous blockchain record.

6. The method of claim 2 , wherein the first communication indicates at least one scope governing access to the service, and

wherein the permission scope of the token is corresponds with the at least one scope indicated by the first communication.

7. The method of claim 6 , wherein the first communication indicates a purpose for the access to the service by the application, and

wherein the application client ID is generated and issued based at least partly on determining that the at least one scope is appropriate for the purpose.

8. The method of claim 2 , wherein the token is generated and issued based at least partly on receiving permission, from the end-user, to access data of the end-user maintained by the service.

9. The method of claim 8 , wherein the permission is received through a user interface (UI) dialog that is presented to the end-user by the service.

10. A system comprising:

at least one processor; and

a memory communicatively coupled to the at least one processor, the memory storing instructions which, when executed by the at least one processor, cause the at least one processor to perform operations comprising:

receiving a plurality of access requests from a service on behalf of an application, each access request including a token, the token having previously been issued to the service responsive to:

(A) a first communication from the service requesting issuance of an application client identifier (ID), wherein the application client ID is issued to the service in response to the first communication, and

(B) a second communication from the service including the application client ID and requesting issuance of the token; and

responsive to each of the plurality of access requests from the service that include the token:

providing access to data of an end-user in accordance with a permission scope indicated by the token included with the respective access request; and

adding, to a block in a blockchain, data associated with the respective access request, wherein the block in the blockchain holds a history of access requests made by the service.

11. The system of claim 10 , wherein a second block in the blockchain includes a list of one or more client application associated with the token.

12. The system of claim 11 , wherein the token comprises a blockchain address.

13. The system of claim 12 , wherein the token comprises a hashed version of the blockchain address.

14. The system of claim 11 , further comprising, responsive to each access request, determining that the respective access request is valid by comparing a current blockchain record with a previous blockchain record.

15. The system of claim 11 , wherein the first communication indicates at least one scope governing access to the service, and

wherein the permission scope of the token is corresponds with the at least one scope indicated by the first communication.

16. The system of claim 15 , wherein the first communication indicates a purpose for the access to the service by the application; and

wherein the application client ID is generated and issued based at least partly on determining that the at least one scope is appropriate for the purpose.

17. The system of claim 11 , wherein the token is generated and issued based at least partly on receiving permission, from the end-user, to access data of the end-user maintained by the service.

18. The system of claim 17 , wherein the permission is received through a user interface (UI) dialog that is presented to the end-user by the service,

wherein the first communication includes a logo of the application, and

wherein the UI dialog is presented with the logo.

19. One or more non-transitory computer-readable media storing instructions which, when executed by at least one processor, cause the at least one processor to perform operations comprising:

receiving a plurality of access requests from a service on behalf of an application, each access request including a token, the token having previously been issued to the service responsive to:

(A) a first communication from the service requesting issuance of an application client identifier (ID), wherein the application client ID is issued to the service in response to the first communication, and

(B) a second communication from the service including the application client ID and requesting issuance of the token; and

responsive to each of the plurality of access requests from the service that include the token:

providing access to data of an end-user in accordance with a permission scope indicated by the token included with the respective access request; and

adding, to a block in a blockchain, data associated with the respective access request, wherein the block in the blockchain holds a history of access requests made by the service.

20. The media of claim 19 , wherein a second block in the blockchain includes a list of one or more client application associated with the token.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 29, 2024
From: VERA, ALEJANDRO; SOLÍS, MIGUEL, JR.; NGUYEN, HIEU; HENDRY, JASON PAUL; MAHONEY, NATHAN; CASILLAS, DEBRA RANDALL
To: UIPCO, LLC
Reel/Frame 066273/0697 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 29, 2024
From: UIPCO, LLC
To: UNITED SERVICES AUTOMOBILE ASSOCIATION (USAA)
Reel/Frame 066273/0761 →
Continuity (4)
Continuation 17356863 · Jun 24, 2021
Continuation 17112439 · Dec 4, 2020
Continuation 16218191 · Dec 12, 2018
Provisional Application 62597754 · Dec 12, 2017
References Cited (24)
US 9996835B2 · Dill et al. · 2018 [cited by applicant]
US 10819709B1 · M'Raihi et al. · 2020 [cited by applicant]
US 10887301B1 · Vera et al. · 2021 [cited by applicant]
US 11063925B1 · Vera et al. · 2021 [cited by applicant]
US 11888837B1 · Vera et al. · 2024 [cited by applicant]
US 20070136197A1 · Morris · 2007 [cited by applicant]
US 20100100952A1 · Sample et al. · 2010 [cited by applicant]
US 20110321131A1 · Austel et al. · 2011 [cited by applicant]
US 20120227087A1 · Brown et al. · 2012 [cited by applicant]
US 20120227098A1 · Obasanjo · 2012 [cited by examiner]
US 20130086670A1 · Vangpat et al. · 2013 [cited by applicant]
US 20130104198A1 · Grim · 2013 [cited by applicant]
US 20140282880A1 · Herter et al. · 2014 [cited by applicant]
US 20150058930A1 · Mitchell et al. · 2015 [cited by applicant]
US 20150312038A1 · Palanisamy · 2015 [cited by examiner]
US 20170034172A1 · Biggs et al. · 2017 [cited by applicant]
US 20170295157A1 · Chavez · 2017 [cited by examiner]
US 20180034795A1 · Los et al. · 2018 [cited by applicant]
US 20180262510A1 · Su · 2018 [cited by applicant]
US 20180337784A1 · Jain et al. · 2018 [cited by applicant]
US 20190020661A1 · Zhang · 2019 [cited by examiner]
US 20190050551A1 · Goldman-Kirst et al. · 2019 [cited by applicant]
US 20190287085A1 · Seidler · 2019 [cited by examiner]
US 20200007316A1 · Krishnamacharya et al. · 2020 [cited by applicant]