Invention Grant
- Patent Title: Authenticating API service invocations
-
Application No.: US16377194Application Date: 2019-04-06
-
Publication No.: US11102196B2Publication Date: 2021-08-24
- Inventor: Rong Chang , Maoyuan Qu , Yew-Huey Liu , Jim Laredo , Robert Calhoun
- Applicant: INTERNATIONAL BUSINESS MACHINES CORPORATION
- Applicant Address: US NY Armonk
- Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
- Current Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
- Current Assignee Address: US NY Armonk
- Agency: Intelletek Law Group, PLLC
- Agent Gabriel Daniel, Esq.
- Main IPC: G06F21/00
- IPC: G06F21/00 ; H04L29/06 ; G06F21/31 ; H04L29/12 ; G06F9/54

Abstract:
A computer-implemented method and system for authenticating API is provided. An API invocation request associated with a user is received. An API operation and the shareable API key includes validating API key credentials of the shareable API key associated with the API invocation request. There is an additional validation of user credentials of the user associated with the API invocation request. It is determined whether the user having the validated user credentials is authorized to use the shareable API key to invoke the API operation. The API operation is executed in response to determining the user having validated user credentials is authorized to use the shareable API key to invoke the API operation. The authentication integrates validation of the user and the shareable API key, and determines whether a user is a subscriber of a multi-tenant subscription service.
Public/Granted literature
- US20200322324A1 Authenticating API Service Invocations Public/Granted day:2020-10-08
Information query