Invention Grant
- Patent Title: Long-lasting refresh tokens in self-contained format
-
Application No.: US18148935Application Date: 2022-12-30
-
Publication No.: US12113903B2Publication Date: 2024-10-08
- Inventor: Radoslav Ivanov Sugarev
- Applicant: SAP SE
- Applicant Address: DE Walldorf
- Assignee: SAP SE
- Current Assignee: SAP SE
- Current Assignee Address: DE Walldorf
- Agency: Fish & Richardson P.C.
- Main IPC: H04L9/32
- IPC: H04L9/32 ; H04L9/08

Abstract:
The present disclosure relates to computer-implemented methods, software, and systems for securely generating a new access token based on relatively long-lasting refresh tokens in self-contained format. A first request to generate a new access token for authorization of a client application with an application server is received and includes a first protected version of a refresh token. The first protected version of the refresh token is an encrypted version of the refresh token based on a first client identifier. The first protected version of the refresh token is decrypted to determine content of the refresh token based on a second client identifier of the client application that is externally invoked for validating the authorization. In response to successfully decrypting the first protected version, performing a validation of the refresh token. In response to successfully validating the refresh token, generating the new access token and providing it to the client application.
Public/Granted literature
- US20230138368A1 LONG-LASTING REFRESH TOKENS IN SELF-CONTAINED FORMAT Public/Granted day:2023-05-04
Information query