×

Methods and systems of data security in browser storage

  • US 9,231,764 B2
  • Filed: 02/13/2015
  • Issued: 01/05/2016
  • Est. Priority Date: 08/29/2011
  • Status: Active Grant
First Claim
Patent Images

1. A non-transitory computer-readable medium having stored thereon instructions that, when executed by one or more processors, cause the one or more processors to:

  • authenticate a client browser via an identity provider;

    grant permission for an service to access data and/or services of the identity provider;

    redirect, with the identity provider, the client browser to an endpoint provided by the service provider;

    send an authorization code, with the identity provider, during the redirect, the authorization code to be exchanged, by the service provider, for one or more refresh tokens and access to the data and/or services;

    wherein the client browser establishes communications with the service provider, the service provider prompts the user to set-up a passcode before obtaining the tokens and once the passcode is provided, and after the service provider obtains the tokens from the identity provider, the service provider encrypts the refresh token(s) by using the passcode and/or by a private key generated by the service provider; and

    wherein the encrypted token is returned to the client browser to be saved locally in local storage of the client browser;

    cause, during future attempts, the client browser to send the encrypted token along with the passcode to the service provider to access the data and/or services of the identity provider.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×