Token Store System for Secure OAuth Offline Token Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication methods for computer systems, such as browser-based and basic HTTP authentication, store username and password information in reversible formats, compromising security, and tokens like OAuth tokens require frequent reconfiguration due to expiration.
Innovation Solution
Implementing a token store system that generates and manages key-secret pairs associated with offline tokens, eliminating the need to store username and password credentials and automatically updating tokens to maintain security without user intervention.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If username and password information is stored in reversible format, then authentication can be performed, but security is compromised allowing attackers to steal protected user information
Solution Approach 1:
The patent extracts the password from the authentication process by using OAuth tokens instead. The application server obtains an access token from the authentication server, and this token is used for subsequent authentication requests to the monitored application, eliminating the need to store or transmit passwords.
Solution Approach 2:
The patent introduces an OAuth authentication server as an intermediary between the application server and the monitored application. The authentication server issues tokens that mediate the authentication process, allowing the application server to authenticate without directly handling passwords.
2Object-affected harmful factors
If OAuth tokens are used to replace username and password, then security is improved, but tokens expire requiring agent reconfiguration
Solution Approach 1:
The patent implements preliminary action by having the application server obtain and store the refresh token and key-secret pair in advance, before the access token expires. When the access token expires, the server can use the stored refresh token to obtain a new access token without requiring agent reconfiguration.
Solution Approach 2:
The patent enables self-service by implementing an automatic token refresh mechanism. The application server automatically detects when the access token expires and uses the refresh token to obtain a new token without human intervention, eliminating the need for manual agent reconfiguration.
3Reliability
If access tokens are used for authentication, then security is enhanced, but token expiration causes communication interruption
Solution Approach 1:
The patent ensures continuity of useful action by implementing an automatic token refresh mechanism. Before the access token expires, the system uses the refresh token to obtain a new access token, ensuring continuous authentication capability without interruption to the monitored communication.
Data Source
AI summary
An authentication system includes an authentication server, an application having a proxy, and a token store. The token store receives an authentication request and sends the request to the authentication server. The authentication server authenticates the user based on the request. The token store requests an offline token from the authentication server. The authentication server sends the offline token to the token store. The token store generates a key-secret pair and stores the offline token and the key-secret pair in a database. The token store sends the authentication result of the user to the application. The application receives an authentication result and requests a key-secret pair from the token store. The token store sends the key-secret pair to the application. The key-secret pair is used to configure an agent, which adds the key-secret pair to a communication request sent to the application. The application processes the communication request.


