The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Apr. 06, 2021

Filed:

Jun. 14, 2017
Applicant:

Ebay Inc., San Jose, CA (US);

Inventors:

Anand Baldeodas Bahety, San Jose, CA (US);

Nebojsa Pesic, Los Gatos, CA (US);

Mallikarjuna Potta, San Jose, CA (US);

Assignee:

eBay Inc., San Jose, CA (US);

Attorney:
Primary Examiner:
Assistant Examiner:
Int. Cl.
CPC ...
H04L 9/32 (2006.01); G06Q 20/40 (2012.01); H04L 29/06 (2006.01); G06Q 20/38 (2012.01); G06Q 30/06 (2012.01); H04L 9/08 (2006.01);
U.S. Cl.
CPC ...
H04L 9/3213 (2013.01); G06Q 20/3821 (2013.01); G06Q 20/40 (2013.01); G06Q 30/0601 (2013.01); H04L 9/0861 (2013.01); H04L 9/3234 (2013.01); H04L 9/3242 (2013.01); H04L 9/3297 (2013.01); H04L 63/0807 (2013.01); H04L 63/0884 (2013.01); H04L 63/0815 (2013.01); H04L 2463/121 (2013.01);
Abstract

A system, method, and computer program product are provided for securing authorization tokens using client instance specific secrets. Tokens are valid for service requests only if time constraints and additional security constraints are met by additional information stored in the token in hashed form. A required comparison of a timestamp in a client service request header to the current server time limits the useful token life, e.g., to a few minutes. The service request header also includes data generated based on a secret previously assigned to a specific client instance. The secret may be generated by the server according to a public/private key scheme and sent to a particular client instance only once, e.g., during initial device registration. The secret may be omitted from service requests for public information. Service request headers may include device identifiers, so that service requests from known rogue clients may be ignored.


Find Patent Forward Citations

Loading…