Token Store System for Secure OAuth Offline Token Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods for computer systems, such as browser-based and basic HTTP authentication, store username and password information in reversible formats, compromising security, and tokens like OAuth tokens require frequent reconfiguration due to expiration.

Innovation Solution

Implementing a token store system that generates and manages key-secret pairs associated with offline tokens, eliminating the need to store username and password credentials and automatically updating tokens to maintain security without user intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If username and password information is stored in reversible format, then authentication can be performed, but security is compromised allowing attackers to steal protected user information

Engineering Contradiction:
Improveauthentication capabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the password from the authentication process by using OAuth tokens instead. The application server obtains an access token from the authentication server, and this token is used for subsequent authentication requests to the monitored application, eliminating the need to store or transmit passwords.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an OAuth authentication server as an intermediary between the application server and the monitored application. The authentication server issues tokens that mediate the authentication process, allowing the application server to authenticate without directly handling passwords.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If OAuth tokens are used to replace username and password, then security is improved, but tokens expire requiring agent reconfiguration

Engineering Contradiction:
ImprovesecurityVSAvoidreconfiguration requirement
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent implements preliminary action by having the application server obtain and store the refresh token and key-secret pair in advance, before the access token expires. When the access token expires, the server can use the stored refresh token to obtain a new access token without requiring agent reconfiguration.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables self-service by implementing an automatic token refresh mechanism. The application server automatically detects when the access token expires and uses the refresh token to obtain a new token without human intervention, eliminating the need for manual agent reconfiguration.

Inventive Principle:
Principle #25Self-service

3Reliability

If access tokens are used for authentication, then security is enhanced, but token expiration causes communication interruption

Engineering Contradiction:
Improveauthentication securityVSAvoidtoken validity period
Core Design Contradiction:
ReliabilityVSDuration of action of stationary object

Solution Approach 1:

The patent ensures continuity of useful action by implementing an automatic token refresh mechanism. Before the access token expires, the system uses the refresh token to obtain a new access token, ensuring continuous authentication capability without interruption to the monitored communication.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS10382424B2Secret store for OAuth offline tokens
Publication Date: 2019.08.13 RED HAT INC
  • US10382424B2 patent drawing
  • US10382424B2 patent drawing
  • US10382424B2 patent drawing

AI summary

An authentication system includes an authentication server, an application having a proxy, and a token store. The token store receives an authentication request and sends the request to the authentication server. The authentication server authenticates the user based on the request. The token store requests an offline token from the authentication server. The authentication server sends the offline token to the token store. The token store generates a key-secret pair and stores the offline token and the key-secret pair in a database. The token store sends the authentication result of the user to the application. The application receives an authentication result and requests a key-secret pair from the token store. The token store sends the key-secret pair to the application. The key-secret pair is used to configure an agent, which adds the key-secret pair to a communication request sent to the application. The application processes the communication request.