Invention Grant
- Patent Title: Client-server security enhancement using information accessed from access tokens
-
Application No.: US17511820Application Date: 2021-10-27
-
Publication No.: US11750612B2Publication Date: 2023-09-05
- Inventor: Anshul Dube , Xiaoqin Zhu , Andrew Burke Ryan , Shankaranand Arunachalam , Gokay Hurmali , Dmitri Gavrilov , Ganesh Pandey , Parul Manek
- Applicant: Microsoft Technology Licensing, LLC
- Applicant Address: US WA Redmond
- Assignee: MICROSOFT TECHNOLOGY LICENSING, LLC
- Current Assignee: MICROSOFT TECHNOLOGY LICENSING, LLC
- Current Assignee Address: US WA Redmond
- Agency: Kelly, Holt & Christenson PLLC
- Agent Christopher J. Volkmann
- Main IPC: H04L9/40
- IPC: H04L9/40

Abstract:
A service computing system receives an API call in which an authorization token, that contains an identifier in the content of the authorization token, is included in a header of the API call. The identifier is also included as a parameter passed in with the API call. The service computing system parses the API call to obtain the authorization token, and the identifier included in the authorization token. It also obtains the identifier passed in as a parameter of the API call. The service computing system compares the identifier obtained from the authorization token to the identifier passed in as a parameter of the API call to determine whether they match. If they do not match, the API call is processed as an unauthorized API call. A security system in the service computing system authorizes the API call based on the comparison.
Information query