IP Library › Granted Patent US 12,603,768
Granted Patent B2
US 12,603,768 · App. 18/499,137 · Granted Apr 14, 2026

Systems and methods for providing and maintaining secure client-based permission lists

Inventors: Ryan Boucher (Bear, DE); Aswathram Thirupulisamy Ravisankar (Wilmington, DE); Sujon Abul (New York, DE)
Assignee: JPMORGAN CHASE BANK, N.A.
H04L9/0861H04L9/0825H04L9/3242
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,603,768
App. No.
18/499,137
Granted
Apr 14, 2026
Kind
B2
Abstract

In some aspects, the techniques described herein relate to a method including: receiving, at an entitlement service and from a client application, a request for an entitlement token; signing, by the entitlement service, a permission file with a private key from a public-private key pair; generating, by the entitlement service, a composite key using a public key from the public-private key pair; encrypting, by the entitlement service, the permission file using the composite key as an encryption key in a symmetric encryption function, wherein encrypting the permission file generates the entitlement token; and sending the entitlement token to the client application.

Claims (25)

1 . A method comprising:

receiving, at a decoder library executing on a client device, a public key from a public-private key pair and a salt value;

generating, by the decoder library, a composite key using the public key from the public-private key pair, wherein generating the composite key includes providing a first output from a hashing function by hashing the public key as an input, wherein generating the composite key includes appending the salt value to the first output from the hashing function and providing the first output from the hashing function and the salt value appended to the first output from the hashing function to the hashing function as input, and receiving a second output from the hashing function, wherein the second output from the hashing function is converted into a byte array, and wherein the byte array is the composite key;

receiving, at the decoder library and from a client application, an encrypted entitlement token;

decrypting, by the decoder library, the encrypted entitlement token using the composite key as a symmetric key, wherein decrypting the encrypted entitlement token generates a signed permission file, and wherein the signed permission file is in clear text;

verifying, using the public key, that the signed permission file was signed using a private key from the public-private key pair;

determining, via a query of the signed permission file a permission indication for a service request; and

sending the permission indication to the client application.

2 . The method of claim 1 , wherein the first output from the hashing function is converted into a base64 string value.

3 . A system comprising at least one computer including a processor and a memory, wherein the at least one computer is configured to:

receive, at a decoder library executing on the at least one computer, a public key from a public-private key pair and a salt value;

generate, by the decoder library, a composite key using the public key from the public-private key pair, wherein generating the composite key includes providing a first output from a hashing function by hashing the public key as an input, wherein generating the composite key includes appending the salt value to the first output from the hashing function and providing the first output from the hashing function and the salt value appended to the first output from the hashing function to the hashing function as input, and receiving a second output from the hashing function, wherein the second output from the hashing function is converted into a byte array, and wherein the byte array is the composite key;

receive, at the decoder library and from a client application, an encrypted entitlement token;

decrypt, by the decoder library, the encrypted entitlement token using the composite key as a symmetric key, wherein decrypting the encrypted entitlement token generates a signed permission file, and wherein the signed permission file is in clear text;

verify, using the public key, that the signed permission file was signed using a private key from the public-private key pair;

determine, via a query of the signed permission file a permission indication for a service request; and

send the permission indication to the client application.

4 . A non-transitory computer readable storage medium, including instructions stored thereon, which instructions, when read and executed by one or more computer processors, cause the one or more computer processors to perform steps comprising:

receiving, at a decoder library executing on a client device, a public key from a public-private key pair and a salt value;

generating, by the decoder library, a composite key using the public key from the public-private key pair, wherein generating the composite key includes providing a first output from a hashing function by hashing the public key as an input, wherein generating the composite key includes appending the salt value to the first output from the hashing function and providing the first output from the hashing function and the salt value appended to the first output from the hashing function to the hashing function as input, and receiving a second output from the hashing function, wherein the second output from the hashing function is converted into a byte array, and wherein the byte array is the composite key;

receiving, at the decoder library and from a client application, an encrypted entitlement token;

decrypting, by the decoder library, the encrypted entitlement token using the composite key, wherein decrypting the encrypted entitlement token generates a signed permission file, and wherein the signed permission file is in clear text;

verifying, using the public key, that the signed permission file was signed using a private key from the public-private key pair;

determining, via a query of the signed permission file a permission indication for a service request; and

sending the permission indication to the client application.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 29, 2025
From: BOUCHER, RYAN; RAVISANKAR, ASWATHRAM THIRUPULISAMY; ABUL, SUJON
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 073322/0912 →
Continuity (1)
Related Publication 20250141672A1 · May 1, 2025
References Cited (15)
US 9292707B1 · Fontecchio · 2016 [cited by examiner]
US 10602094B1 · Longo · 2020 [cited by examiner]
US 20030163433A1 · Lam · 2003 [cited by examiner]
US 20050132182A1 · Challener · 2005 [cited by examiner]
US 20130326219A1 · Badam · 2013 [cited by examiner]
US 20140075582A1 · Hierro · 2014 [cited by examiner]
US 20140095874A1 · Desai · 2014 [cited by examiner]
US 20160078199A1 · Moore · 2016 [cited by examiner]
US 20170180367A1 · Warren · 2017 [cited by examiner]
US 20190207758A1 · Cambou · 2019 [cited by examiner]
US 20190245701A1 · Chen · 2019 [cited by examiner]
US 20190279199A1 · Sheets · 2019 [cited by examiner]
US 20190371104A1 · Suleiman · 2019 [cited by examiner]
US 20220092193A1 · Nijasure · 2022 [cited by examiner]
US 20240275607A1 · Yarabolu · 2024 [cited by examiner]