18006726. SYNCHRONIZING A SESSION STATE ASSOCIATED WITH AN ACCESS TOKEN BETWEEN AN IDENTITY MANAGER (IDM) AND APPLICATION PROGRAMMING INTERFACE (API) GATEWAY simplified abstract (RAKUTEN SYMPHONY SINGAPORE PTE. LTD.)

From WikiPatents
Revision as of 05:07, 26 July 2024 by Wikipatents (talk | contribs) (Creating a new page)
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to navigation Jump to search

SYNCHRONIZING A SESSION STATE ASSOCIATED WITH AN ACCESS TOKEN BETWEEN AN IDENTITY MANAGER (IDM) AND APPLICATION PROGRAMMING INTERFACE (API) GATEWAY

Organization Name

RAKUTEN SYMPHONY SINGAPORE PTE. LTD.

Inventor(s)

Manoj Aswani of Indore (IN)

Hemant Sharma of Indore (IN)

Ayus Kumar of Indore (IN)

Sagar Kommu of Indore (IN)

Neeraj Patidar of Indore (IN)

SYNCHRONIZING A SESSION STATE ASSOCIATED WITH AN ACCESS TOKEN BETWEEN AN IDENTITY MANAGER (IDM) AND APPLICATION PROGRAMMING INTERFACE (API) GATEWAY - A simplified explanation of the abstract

This abstract first appeared for US patent application 18006726 titled 'SYNCHRONIZING A SESSION STATE ASSOCIATED WITH AN ACCESS TOKEN BETWEEN AN IDENTITY MANAGER (IDM) AND APPLICATION PROGRAMMING INTERFACE (API) GATEWAY

Simplified Explanation

The patent application describes a system that synchronizes the session state of an access token between different components, such as an Identity Manager (IDM) and an Application Programming Interface (API) Gateway.

  • The IDM generates an access token for a client device and stores session state information in a distributed cache.
  • When the client device logs out, the IDM removes the session state information from the storage device.
  • The API Gateway can request the session state information from the storage device to authenticate the access token and grant access to the client device.

Key Features and Innovation

  • Synchronization of session state between IDM and API Gateway.
  • Use of distributed cache for storing session state information.
  • Authentication of access token by API Gateway based on session state information.

Potential Applications

This technology can be applied in various systems where access control and authentication are required, such as secure login systems, user management platforms, and API security solutions.

Problems Solved

  • Ensures consistent session state across different components.
  • Improves security by authenticating access tokens.
  • Streamlines access control processes.

Benefits

  • Enhanced security for access control.
  • Seamless user experience with synchronized session state.
  • Efficient management of access tokens.

Commercial Applications

Title: Secure Access Control System This technology can be utilized in industries such as cybersecurity, cloud computing, and IoT to enhance security measures, streamline authentication processes, and improve overall system reliability.

Prior Art

Readers interested in exploring prior art related to this technology can start by researching patents or publications in the fields of access control, identity management, and API security.

Frequently Updated Research

Researchers in the fields of cybersecurity, data privacy, and network security may have ongoing studies related to access token management, session synchronization, and authentication protocols.

Questions about Synchronization of Session State

How does the system ensure the security of access tokens during synchronization?

The system uses authentication mechanisms and encrypted communication channels to secure access tokens and session state information during synchronization.

What are the potential scalability challenges of implementing this synchronization system in large-scale applications?

Scalability challenges may arise in managing a high volume of access tokens, ensuring real-time synchronization across distributed components, and optimizing performance for a large number of concurrent users.


Original Abstract Submitted

Synchronization of a session state of an access token is provided between elements in a system, such as between an Identity Manager (IDM) and an Application Programming Interface (API) Gateway. The IDM generates an access token that is provided to a client device and stores session state information of the access token at a distributed cache. When the client device logs out from the IDM, the IDM removes the session state information from the distributed storage device. The API Gateway is able to request the session state information from distributed storage device. Based on receiving the session state information, the API Gateway authenticates the access token and grants the client device access to an end service. Before requesting the session state information from the distributed storage device, the API Gateway is able to verify the access token is valid and that the access token has not expired.