EP3553719A1

System for reliably accessing a protected resource

Abstract

A client system obtains an access token for accessing a protected resource stored at a resource system. A storage resource of the system stores a plurality of grant method code portions, a plurality of authentication method code portions and a configurable database. The client system comprises processing circuitry configured to receive an access request from a user device. The access request comprises an instruction for the client system to access a protected resource and a request identifier indicative of an authorisation system for authorising access to the protected resource. The client system uses the configurable database and code portions to execute the grant and authentication methods supported by the authorisation system. The client system receives the access token from the authorisation sever, in response to executing the grant and authentication methods.

EP3553719A1, drawing sheet 1
Sheet 1 of 10

Term

11.5 yearsto projected expiry

Projected expiry 11 April 2038, counted from filing; an application has no term until it is granted.

  1. Priority and filed
  2. Published
  3. Today
  4. Projected expiry

15 claims: 2 independent, 13 dependent

  1. 1
    A computer-implemented method for obtaining an access token for providing access to a protected resource stored at a resource system, the method comprising:storing, at a client system: a plurality of grant method code portions each executable to obtain access to the access token using one of a plurality of types of grant method, wherein each respective type of grant method is different to the other types of grant method;and a plurality of authentication method code portions each executable to authenticate the client system using a different authentication method, wherein each respective type of authentication method is different to the other types of authentication method;storing, at the client system, a configurable database comprising a plurality of authorisation system identifiers each indicative of a respective authorisation system, wherein each of the plurality of authorisation system identifiers is associated with one or more of the plurality of types of grant method which are supported by the respective authorisation system, and each of the plurality of authorisation system identifiers is associated with one or more of the plurality of types of authentication method which are supported by the respective authorisation system;receiving, at the client system, from a user device an access request comprising an instruction for the client system to access a protected resource, the instruction comprising a request identifier indicative of an authorisation system for authorising access to the protected resource;identifying, in the configurable database, a selected grant method type from one or more of the grant method types associated with an authorisation system identifier corresponding to the request identifier;identifying, in the configurable database, a selected authentication method type, from one or more of the authentication method types associated with the authorisation system identifier corresponding to the request identifier;executing, at the client system, the grant method code portion corresponding to the selected grant method type to request the access token for accessing the protected resource;executing, at the client system, the authentication method code portion corresponding to the selected authentication method type to authenticate the client system at the authorisation system;and receiving the access token at the client system from the authorisation sever, in response to executing the grant method code portion and the authentication method code portion.
  2. 15
    A client system for obtaining an access token for accessing a protected resource stored at a resource system, the client system comprising:a storage resource configured to store: a plurality of grant method code portions each executable to obtain access to the access token using one of a plurality of types of grant method, wherein each respective type of grant method is different to the other types of grant method;a plurality of authentication method code portions each executable to authenticate the client system using a different authentication method, wherein each respective type of authentication method is different to the other types of authentication method;and a configurable database comprising a plurality of authorisation system identifiers each indicative of a respective authorisation system, wherein each of the plurality of authorisation system identifiers is associated with one or more of the plurality of types of grant method which are supported by the respective authorisation system, and each of the plurality of authorisation system identifiers is associated with one or more of the plurality of types of authentication method which are supported by the respective authorisation system;the client system further comprising processing circuitry configured to: receive, from a user device, an access request comprising an instruction for the client system to access a protected resource, the instruction comprising a request identifier indicative of an authorisation system for authorising access to the protected resource;identify a selected grant method type, in the configurable database, from one or more of the grant method types associated with an authorisation system identifier corresponding to the request identifier;identify a selected authentication method type, in the configurable database, from one or more of the authentication method types associated with the authorisation system identifier corresponding to the request identifier;execute the grant method code portion corresponding to the selected grant method type to request the access token for accessing the protected resource;execute the authentication method code portion corresponding to the selected authentication method type to authenticate the client system at the authorisation system;and receive the access token from the authorisation sever, in response to executing the grant method code portion and the authentication method code portion.