IP Library › Granted Patent US 12,609,921
Granted Patent B2
US 12,609,921 · App. 18/405,965 · Granted Apr 21, 2026

Integrating just in time federated cross-domain authentication and access with cloud side passwordless access control

Inventors: Ricky Chan (Woodside, NY); Vijaya Basker Balakrishnan (Coppell, TX); Kanishka Hettiarachchi (Chatham, NJ); Robert Kong (Flushing, NY); Ross Indyke (NY, NY); Jeremy Wellmeier (Hilliard, OH); Ramesh Krishnamurthy (Prosper, TX); Robert Spinelli (Hazlet, NJ); George Irizarry (Celina, TX)
Assignee: JP Morgan Chase Bank, N.A.
H04L63/0815H04L63/105
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,609,921
App. No.
18/405,965
Granted
Apr 21, 2026
Kind
B2
Abstract

Per one example embodiment, a method is provided of shifting an OS (operating system) and associated native application platform from a private network to a cloud-based target environment, where the OS comprises an operating system not configured for web access. An image of the OS is provided that is suitable for installation on a target virtual machine in the cloud-based target platform. In lieu of moving user credentials of numerous current private network-based users of the OS—native application platform to the target environment, a passwordless credential-based OS command level communication brokering service is provided at the cloud-based target environment.

Claims (29)

1 . An apparatus comprising:

a federated authentication and access processing circuit configured to authenticate a given user seeking access to a cloud-based application, the authentication producing a temporary federated token identifying the given user and associated attributes; and

a cloud side access control system, separate from the federated authentication and access processing circuit, configured to use the temporary federated token solely as a prerequisite to provide the given user with passwordless access to an onboarded operating system and associated application on a virtual machine of a target cloud platform

wherein the cloud side access control system is further configured to enforce access by reference to security settings structured data defining per-endpoint and per-command role-based access control for the given user.

2 . The apparatus according to claim 1 , wherein the security settings structured data further include function limitations for specifying per function access control.

3 . The apparatus according to claim 1 , wherein the limitations comprise different sets of limitations, based on a role of the given user.

4 . The apparatus according to claim 3 , further comprising a direction circuit configured to direct the given user to a command interface at the target cloud platform.

5 . The apparatus according to claim 3 , wherein the cloud side access control system is configured to carry out a role based access control (RBAC) process for authenticating and granting access to the given user.

6 . The apparatus according to claim 5 , wherein the RBAC process relies on authentication information obtained by the federated authentication and access processing circuit.

7 . The apparatus according to claim 5 , wherein the cloud side access control system is configured to determine access to the given user based on a requested endpoint, and wherein the requested endpoint is configured to correspond to a role capability.

8 . The apparatus according to claim 7 , wherein the role capability comprises read only commands per one capability and read and write commands per another capability.

9 . A method comprising:

performing a federated authentication and access process to authenticate a given user seeking access to a cloud-based application, the process producing a temporary federated token identifying the given user and associated attributes, and upon authentication redirecting the given user to a command interface of a target cloud platform;

performing a cloud side access control process, distinct from the federated authentication and access process, wherein the cloud side access control process uses the temporary federated token solely to permit entry to a passwordless session and thereafter determines whether to grant the given user access to an onboarded operating system and associated application on a virtual machine of the target cloud platform,

wherein the determining includes enforcing per-command limitations based on security settings structured data defining per-endpoint and per-command role-based access control for the given user.

10 . The method according to claim 9 , wherein the security settings structured data further include function limitations for specifying per function access control.

11 . The method according to claim 9 , wherein the limitations comprise different sets of limitations, based on a role of the given user.

12 . The method according to claim 9 , further comprising directing the given user to a command interface at the target cloud platform.

13 . The method according to claim 11 , wherein the cloud side access control process includes carrying out a role based access control (RBAC) process for authenticating and granting access to the given user.

14 . The method according to claim 13 , wherein the RBAC process relies on authentication information obtained by the federated authentication and access process.

15 . The method according to claim 13 , wherein the cloud side access control process includes determining access for the given user based on a requested endpoint, and wherein the requested endpoint is configured to correspond to a role capability.

16 . The method according to claim 15 , wherein the role capability comprises read only commands per one capability and read and write commands per another capability.

17 . A non-transitory computer readable media encoded to cause with instructions that, when executed by one or more processors, cause the one or more processors to perform operations comprising:

performing a federated authentication and access process for a given user seeking access to a cloud-based application, including generating a temporary federated token identifying the given user and associated attributes;

redirect the given user, upon authentication, to a command interface of a target cloud platform; and

performing a cloud side access control process distinct from the federated authentication and access process, including using the temporary federated token solely as a prerequisite to initiate a passwordless session and thereafter enforcing per-command access for the given user to an onboarded operating system and associated application on a virtual machine of the target cloud platform, wherein the per-command access is enforced by reference to security settings structured data defining per-endpoint and per-command role-based access control for the given user.

18 . The computer readable media according to claim 17 , wherein the security settings structured data further include function limitations for specifying per function access control.

19 . The computer readable media according to claim 17 , wherein the limitations comprise different sets of limitations, based on a role of the given user.

20 . The computer readable media according to claim 19 , wherein the cloud side access control process includes carrying out a role based access control (RBAC) process for authenticating and granting access to the given user.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 16, 2024
From: WELLMEIER, JEREMY; INDYKE, ROSS; KONG, ROBERT; HETTIARACHCHI, KANISHKA; BALAKRISHNAN, VIJAYA BASKER; CHAN, RICKY; KRISHNAMURTHY, RAMESH; SPINELLI, ROBERT; IRIZARRY, GEORGE
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 067438/0847 →
Continuity (1)
Related Publication 20250227101A1 · Jul 10, 2025
References Cited (5)
US 10951624B2 · Kurup et al. · 2021 [cited by applicant]
US 20220038450A1 · Han · 2022 [cited by examiner]
US 20230129824A1 · Hettiarachchi · 2023 [cited by applicant]
US 20240259386A1 · Wu · 2024 [cited by examiner]
US 20240259389A1 · Wu · 2024 [cited by examiner]