Invention Grant
- Patent Title: Two-token based authenticated session management
-
Application No.: US15395448Application Date: 2016-12-30
-
Publication No.: US10541992B2Publication Date: 2020-01-21
- Inventor: Guibin Kong , Naveen Agarwal
- Applicant: Google LLC
- Applicant Address: US CA Mountain View
- Assignee: Google LLC
- Current Assignee: Google LLC
- Current Assignee Address: US CA Mountain View
- Agency: Lerner, David, Littenberg, Krumholz & Mentlik, LLP
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L29/08 ; H04L12/24

Abstract:
A system maintains a web session across multiple web resources and/or devices using a two-token model. A user agent transmits an authentication request to a login endpoint. The user agent have access to a grant token, and it will receive an access token in response to the authentication request. The grant token is relatively long-lived and the first access token is relatively short-lived. The user agent will use the access token to access the first web resource and establish a web session. When the access token expires or is about to expire, the user agent will transmit a re-authentication request with the grant token to a re-authentication endpoint. The user agent will then receive a second access token from the re-authentication endpoint. The user agent will then use the second access token to access the web resource and maintain the web session.
Public/Granted literature
- US20180191700A1 TWO-TOKEN BASED AUTHENTICATED SESSION MANAGEMENT Public/Granted day:2018-07-05
Information query