US 12,225,378 B2
Forcing re-authentication of users for accessing online services
Kanakrai Chauhan, Snoqualmie, WA (US)
Assigned to T-Mobile USA, Inc., Bellevue, WA (US)
Filed by T-Mobile USA, Inc., Bellevue, WA (US)
Filed on Feb. 24, 2024, as Appl. No. 18/586,422.
Application 18/586,422 is a continuation of application No. 17/137,277, filed on Dec. 29, 2020, granted, now 11,943,618.
Prior Publication US 2024/0196217 A1, Jun. 13, 2024
This patent is subject to a terminal disclaimer.
Int. Cl. H04W 12/082 (2021.01); H04W 4/50 (2018.01); H04W 4/60 (2018.01); H04W 12/069 (2021.01); H04W 12/37 (2021.01); H04W 4/24 (2018.01)
CPC H04W 12/082 (2021.01) [H04W 4/50 (2018.02); H04W 4/60 (2018.02); H04W 12/069 (2021.01); H04W 12/37 (2021.01); H04W 4/24 (2013.01)] 20 Claims
OG exemplary drawing
 
1. A method, comprising:
receiving, at a communication service provider, a request to determine a current status of access rights of a user to access an online service provided by a third-party online service provider based on one or more conditions associated with an account of the user at the communication service provider, wherein the request is received from the third-party online service provider of the online service upon a determination that some predetermined amount of time has passed since a latest request to determine access rights was submitted, and wherein a user device of the user is granted access to the online service of the third-party online service provider via a session token that is generated by the third-party online service provider and stored by the communication service provider with the account of the user at the communication service provider, the session token comprising a string of random characters and being associated with a set of communications between the user device and the third-party online service provider of the online service;
determining, at the communication service provider, based on the one or more conditions associated with the account of the user at the communication service provider, the current status of access rights of the user to access the online service provided by the third-party online service provider; and
based on determining the current status of access rights of the user to access the online service provided by the third-party online service provider, determining whether to generate and output, to the user device, an instruction to modify the session token associated with the third-party online service provider.