IP Library › Granted Patent US 12,292,961
Granted Patent B2
US 12,292,961 · App. 18/076,329 · Granted May 6, 2025

Access and usage of privileged credentials

Inventors: Matthew Murphy (Wigan, GB); Rocky Maufort (Delaware, OH)
Assignee: JPMORGAN CHASE BANK, N.A.
G06F21/45G06F21/604
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,292,961
App. No.
18/076,329
Granted
May 6, 2025
Kind
B2
Abstract

Implementations generally relate to access and usage of privileged credentials. In some implementations, a method includes receiving, from a mobile device, an access request for privileged credentials. The method further includes accessing one or more predetermined conditional access policies. The method further includes receiving location data associated with the mobile device. The method further includes performing a plurality of location-aware verification checks based on the one or more predetermined conditional access policies and the location data. The method further includes determining whether to grant or to deny the access request based on results from the plurality of location-aware verification checks.

Claims (44)

1. A system comprising:

one or more processors; and

logic encoded in one or more non-transitory computer-readable storage media for execution by the one or more processors and when executed operable to cause the one or more processors to perform operations comprising:

implementing a real-time decision engine comprising a location-aware privileged account access module and a privileged session module operating in conjunction with a conditional access proxy and a distributed event streaming platform;

receiving, at the real-time decision engine from a mobile device via the conditional access proxy, an access request for privileged credentials;

accessing one or more predetermined conditional access policies at the real-time decision engine;

receiving location data associated with the mobile device as transmitted to the real-time decision engine;

performing, by the real-time decision engine, a plurality of location-aware verification checks comprising a client-side verification and a server-side verification based on a continuous evaluation of the one or more predetermined conditional access policies with the location data comprising location events derived from a mobile application feed and from an indoor positioning feed via the distributed event streaming platform; and

determining, by the real-time decision engine, whether to grant or to deny the access request based on results from the performing the plurality of location-aware verification checks.

2. The system of claim 1 , wherein at least one of the predetermined conditional access policies requires at least one location-aware verification check associated with an access control system to pass in order to grant the access request.

3. The system of claim 1 , wherein at least one of the predetermined conditional access policies requires at least one location-aware verification check associated with a proximity beacon system to pass in order to grant the access request.

4. The system of claim 1 , wherein at least one of the predetermined conditional access policies requires at least one location-aware verification check associated with an ultrasonic tracking system that encodes ultrasonic sounds with the location data to create at least one from among advertisements and beacons to represent a building and a floor in the building to pass in order to grant the access request.

5. The system of claim 1 , wherein at least one of the predetermined conditional access policies requires at least one location-aware verification check associated with a wireless positioning system to pass in order to grant the access request.

6. The system of claim 1 , wherein at least one of the predetermined conditional access policies requires at least one location-aware verification check associated with an ultra-wideband technology system to pass in order to grant the access request.

7. The system of claim 1 , wherein the logic when executed is further operable to cause the one or more processors to perform operations comprising:

continuously re-evaluating the location data based on one or more location data access policies; and

determining whether to block access to resources and revoke credentials based on changes to location data.

8. A non-transitory computer-readable storage medium with program instructions stored thereon, the program instructions when executed by one or more processors are operable to cause the one or more processors to perform operations comprising:

implementing a real-time decision engine comprising a location-aware privileged account access module and a privileged session module operating in conjunction with a conditional access proxy and a distributed event streaming platform;

receiving, at the real-time decision engine from a mobile device via the conditional access proxy, an access request for privileged credentials;

accessing one or more predetermined conditional access policies at the real-time decision engine;

receiving location data associated with the mobile device as transmitted to the real-time decision engine;

performing, by the real-time decision engine, a plurality of location-aware verification checks comprising a client-side verification and a server-side verification based on a continuous evaluation of the one or more predetermined conditional access policies with the location data comprising location events derived from a mobile application feed and from an indoor positioning feed via the distributed event streaming platform; and

determining, by the real-time decision engine, whether to grant or to deny the access request based on results from the performing the plurality of location-aware verification checks.

9. The computer-readable storage medium of claim 8 , wherein at least one of the predetermined conditional access policies requires at least one location-aware verification check associated with an access control system to pass in order to grant the access request.

10. The computer-readable storage medium of claim 8 , wherein at least one of the predetermined conditional access policies requires at least one location-aware verification check associated with a proximity beacon system to pass in order to grant the access request.

11. The computer-readable storage medium of claim 8 , wherein at least one of the predetermined conditional access policies requires at least one location-aware verification check associated with an ultrasonic tracking system that encodes ultrasonic sounds with the location data to create at least one from among advertisements and beacons to represent a building and a floor in the building to pass in order to grant the access request.

12. The computer-readable storage medium of claim 8 , wherein at least one of the predetermined conditional access policies requires at least one location-aware verification check associated with a wireless positioning system to pass in order to grant the access request.

13. The computer-readable storage medium of claim 8 , wherein at least one of the predetermined conditional access policies requires at least one location-aware verification check associated with an ultra-wideband technology system to pass in order to grant the access request.

14. The computer-readable storage medium of claim 8 , wherein the instructions when executed are further operable to cause the one or more processors to perform operations comprising:

continuously re-evaluating the location data based on one or more location data access policies; and

determining whether to block access to resources and revoke credentials based on changes to location data.

15. A computer-implemented method comprising:

implementing a real-time decision engine comprising a location-aware privileged account access module and a privileged session module operating in conjunction with a conditional access proxy and a distributed event streaming platform;

receiving, at the real-time decision engine from a mobile device via the conditional access proxy, an access request for privileged credentials;

accessing one or more predetermined conditional access policies at the real-time decision engine;

receiving location data associated with the mobile device as transmitted to the real-time decision engine;

performing, by the real-time decision engine, a plurality of location-aware verification checks comprising a client-side verification and a server-side verification based on a continuous evaluation of the one or more predetermined conditional access policies with the location data comprising location events derived from a mobile application feed and from an indoor positioning feed via the distributed event streaming platform; and

determining, by the real-time decision engine, whether to grant or to deny the access request based on results from the performing the plurality of location-aware verification checks.

16. The computer-implemented method of claim 15 , wherein at least one of the predetermined conditional access policies requires at least one location-aware verification check associated with an access control system to pass in order to grant the access request.

17. The computer-implemented method of claim 15 , wherein at least one of the predetermined conditional access policies requires at least one location-aware verification check associated with a proximity beacon system to pass in order to grant the access request.

18. The computer-implemented method of claim 15 , wherein at least one of the predetermined conditional access policies requires at least one location-aware verification check associated with an ultrasonic tracking system that encodes ultrasonic sounds with the location data to create at least one from among advertisements and beacons to represent a building and a floor in the building to pass in order to grant the access request.

19. The computer-implemented method of claim 15 , wherein at least one of the predetermined conditional access policies requires at least one location-aware verification check associated with a wireless positioning system to pass in order to grant the access request.

20. The computer-implemented method of claim 15 , wherein at least one of the predetermined conditional access policies requires at least one location-aware verification check associated with an ultra-wideband technology system to pass in order to grant the access request.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 23, 2023
From: MAUFORT, ROCKY J
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 062458/0391 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 6, 2022
From: MURPHY, MATTHEW
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 062002/0777 →
Continuity (1)
Related Publication 20240184877A1 · Jun 6, 2024
References Cited (7)
US 20090025084A1 · Siourthas · 2009 [cited by examiner]
US 20140031011A1 · West · 2014 [cited by examiner]
US 20160050531A1 · Choi · 2016 [cited by examiner]
US 20190305954A1 · Hamel · 2019 [cited by examiner]
US 20220131871A1 · Huang · 2022 [cited by examiner]
Mustafa Al Lail. 2021. Poster: Towards Cloud-Based Software for Incorporating Time and Location into Access Control Decisions. In Proceedings of the 26th ACM Symposium on Access Control Models and Technologies (SACMAT '… [cited by examiner]
A. v. Cleeff, W. Pieters and R. Wieringa, “Benefits of Location-Based Access Control: A Literature Study,” 2010 IEEE/ACM Int'l Conference on Green Computing and Communications & Int'l Conference on Cyber, Physical and S… [cited by examiner]