IP Library › Granted Patent US 12,596,831
Granted Patent B1
US 12,596,831 · App. 19/388,609 · Granted Apr 7, 2026

Secure mainframe access for AI agents

Inventors: Gil Peleg (Wokingham, GB); Hanan Milman (Rishon le Ziyon, IL)
Assignee: Geniez AI Inc.
G06F21/6218G06F21/31
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,596,831
App. No.
19/388,609
Filed
Nov 13, 2025
Granted
Apr 7, 2026
Kind
B1
Examiner
NIPA, WASIKA
Art Unit
2433
USPC
726/18
Abstract

A method, system and computer program product, the method comprising: receiving, by an intermediate agent, from an AI client, a request for data or actions from a mainframe system (MF), the request comprising a previously generated token associated with a user identifier (uID) of the MF and with a set of privileges within the MF; providing by the intermediate agent the request to an MF agent executed by the MF, wherein the MF agent has a privilege to spawn an MF process associated with the uID, wherein the MF agent is restricted from accessing data or performing actions other than spawning the MF process; and spawning, by the MF agent, the MF process executed by the MF, wherein the MF process has the set of privileges associated with the uID, wherein the MF process is restricted from spawning another process, thereby implementing secure access to the MF.

Claims (52)

1 . A computer-implemented method for securing access to mainframe (MF) data from an Artificial Intelligence (AI) client, the method comprising:

receiving, by an intermediate agent, from the AI client, a request for data or actions from a mainframe (MF) system, the request comprising a token, the token was previously generated, the token is associated with a user identifier (uID) of the MF system, wherein the uID is associated with a set of privileges within the MF system;

providing by the intermediate agent the request to an MF agent executed by the MF system, wherein the MF agent has a privilege to spawn an MF process associated with the uID, wherein the MF agent is restricted from accessing data or performing actions other than spawning the MF process; and

spawning, by the MF agent, the MF process, the MF process is executed by the MF system, wherein the MF process has the set of privileges that is associated with the uID, wherein the MF process is restricted from spawning another process, thereby implementing secure access to the MF system,

wherein the token is generated by:

receiving by the intermediate agent from a client a request to generate the token for accessing the MF system, the request comprising the uID of the MF system and the set of privileges or a portion thereof;

sending by the intermediate agent a request to the AI client for a password associated with the uID of the MF system;

receiving by the intermediate agent the password from the AI client;

sending the by the intermediate agent uID and the password to the MF system for verification; and

subject to receiving by the intermediate agent from the MF system a verification that the password corresponds to the uID, generating the token.

2 . The method of claim 1 , further comprising:

providing by the MF agent the request to the MF process;

receiving by the MF agent a response to the request; and

providing by the MF agent the response to the intermediate agent.

3 . The method of claim 1 , wherein the intermediate agent is configured to receive the request through a generative Artificial Intelligence (genAI) protocol.

4 . The method of claim 3 , wherein the genAI protocol is Model Context Protocol (MCP).

5 . The method of claim 1 , wherein the AI client is implemented using a Large Language Model (LLM).

6 . A system for securing access to MF data from an LLM or an AI client, the system comprising: a hardware processor and a memory;

an intermediate agent configured to:

receive from the AI client, a request for data or actions from an MF system, the request comprising a token, the token was previously generated, the token is associated with a uID of the MF system, wherein the uID is associated with a set of privileges within the MF system; and

provide the request to an MF agent executed by the MF system, wherein the MF agent has a privilege to spawn an MF process associated with the uID, wherein the MF agent is restricted from accessing data or performing actions other than spawning the MF process; and

an MF agent configured to: upon receiving the request from the intermediate agent, spawning an MF process, the MF process is executed by the MF system, wherein the MF process has the set of privileges that is associated with the uID, wherein the MF process is restricted from spawning another process, thereby implementing secure access to the MF system,

wherein the intermediate agent is further configured to:

receive from a client a request to generate the token for accessing the MF system, the request comprising the uID of the MF system and the set of privileges or a portion thereof;

send a request to the AI client for a password associated with the uID of the MF system;

receive the password from the AI client;

send the uID and the password to the MF system for verification; and

generate the token subject to receiving from the MF system a verification that the password corresponds to the uID.

7 . The system of claim 6 , wherein the MF agent is further configured to:

provide the request to the MF process;

receive a response to the request; and

provide the response to the intermediate agent.

8 . The system of claim 6 , wherein the intermediate agent is configured to receive the request through a genAI protocol.

9 . The system of claim 8 , wherein the genAI protocol is MCP.

10 . The system of claim 6 , wherein the AI client is implemented using an LLM.

11 . A computer program product comprising a non-transitory computer readable storage medium retaining program instructions for securing access to MF data from an LLM or an AI client, the program instructions comprise:

receiving, by an intermediate agent, from an AI client, a request for data or actions from an MF system, the request comprising a token, the token was previously generated, the token is associated with a uID of the MF system, wherein the uID is associated with a set of privileges within the MF system;

providing by the intermediate agent the request to an MF agent executed by the MF system, wherein the MF agent has a privilege to spawn an MF process associated with the uID, wherein the MF agent is restricted from accessing data or performing actions other than spawning the MF process; and

spawning, by the MF agent, the MF process, the MF process is executed by the MF system, wherein the MF process has the set of privileges that is associated with the uID, wherein the MF process is restricted from spawning another process, thereby implementing secure access to the MF system,

wherein the token is generated by:

receiving by the intermediate agent from a client a request to generate the token for accessing the MF system, the request comprising the uID of the MF system and the set of privileges or a portion thereof;

sending by the intermediate agent a request to the AI client for a password associated with the uID of the MF system;

receiving by the intermediate agent the password from the AI client;

sending the by the intermediate agent uID and the password to the MF system for verification; and

subject to receiving by the intermediate agent from the MF system a verification that the password corresponds to the uID, generating the token.

12 . The computer program product of claim 11 , wherein the program instructions further comprise:

providing by the MF agent the request to the MF process;

receiving by the MF agent a response to the request; and

providing by the MF agent the response to the intermediate agent.

13 . The computer program product of claim 11 , wherein the intermediate agent is configured to receive the request through a genAI protocol.

14 . The computer program product of claim 13 , wherein the genAI protocol is MCP.

15 . The computer program product of claim 11 , wherein the AI client is implemented using an LLM.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 13, 2025
From: PELEG, GIL; MILMAN, HANAN
To: GENIEZ AI INC.
Reel/Frame 072898/0059 →
References Cited (3)
US 12489771B1 · Erlingsson · 2025 [cited by examiner]
US 20200344067A1 · Fradkin · 2020 [cited by examiner]
US 20220335125A1 · Goodridge · 2022 [cited by examiner]
Cited By (1)
US 12,711,207