Invention Grant
- Patent Title: Third-party authorization of access tokens
-
Application No.: US15797337Application Date: 2017-10-30
-
Publication No.: US10771463B2Publication Date: 2020-09-08
- Inventor: Chaya Berezin , Tamir Faibish , Lior Luker , Nitzan Nissim
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agency: Yee & Associates, P.C.
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L29/08

Abstract:
A computer system comprising a resource server running on the computer system. The resource server receives a client request from a client in which the client request includes an access token. The resource server sends an introspection request to an introspection gateway, wherein the introspection request is for introspection of the access token based on the client request, and wherein the introspection gateway uses a third-party authorization server from a plurality of third-party authorization servers to handle the introspection request. The resource server receives a response from the introspection gateway, wherein the response identifies a set of scopes for the access token. The resource server determines whether the access token has sufficient scope from a resource server response. The client is granted access to the resource server in response to the access token having the sufficient scope.
Public/Granted literature
- US20190132317A1 Third-Party Authorization of Access Tokens Public/Granted day:2019-05-02
Information query