IP Library › Granted Patent US 12,659,305
Granted Patent B2
US 12,659,305 · App. 18/458,094 · Granted Jun 16, 2026

Systems and methods for authentication brokering

Inventors: Richard Seidenstein (New York, NY); Kanishka Hettiarachchi (Chatham, NJ); Ish K Ahluwalia (East Brunswick, NJ); Darshak Kothari (Freehold, NJ); Vimal Gangaraju (McKinney, TX); Lakshmiprasanna Ummaneni (Bengaluru, IN); Karabi Sarma (Bangalore, IN)
Assignee: JPMORGAN CHASE BANK, N.A.
H04L63/0807H04L63/0884G06F8/77
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,659,305
App. No.
18/458,094
Granted
Jun 16, 2026
Kind
B2
Abstract

In some aspects, the techniques described herein relate to a method including: receiving, at a credential broker, a request including a unique identifier of a client application, wherein the request is from a token software development kit; querying, by the credential broker, an application attestation datastore using the unique identifier of the client application as a lookup key; receiving, at the credential broker and as a result of the querying, a service identifier for a network service; requesting a service ticket from a key distribution center, wherein the service ticket facilitates authentication with the network service; and responding to the token software development kit with a return communication, wherein the return communication includes the service ticket.

Claims (28)

1 . A method comprising:

receiving, at a credential broker, a request for a service ticket comprising a unique identifier for a client application, wherein the request is from a token software development kit included in the client application;

querying, by the credential broker, an application attestation datastore for network services that the client application is authorized to make service requests to using the unique identifier of the client application as a lookup key;

receiving, at the credential broker and as a result of the querying, a service identifier for one of the network services;

requesting, by the credential broker, a ticket granting ticket from a key distribution center;

receiving, by the credential broker, the ticket granting ticket from the key distribution center, wherein the ticket granting ticket is encrypted;

requesting, by the credential broker, a service ticket from the key distribution center, wherein the service ticket facilitates authentication with the network service;

receiving, by the credential broker, the service ticket from the key distribution center; and

generating, by the credential broker, a response to the token software development kit comprising the service ticket;

wherein the token software development kit is configured to instantiate in-memory objects context object;

wherein the client application is configured to use context object to connect and authenticate to the network service.

2 . The method of claim 1 , wherein the service ticket is Kerberos service ticket.

3 . The method of claim 2 , wherein the key distribution center comprises a ticket granting service.

4 . The method of claim 3 , wherein the service ticket is provided by the ticket granting service.

5 . The method of claim 1 , comprising:

returning, by the key distribution center, a payload to the credential broker.

6 . The method of claim 5 , comprising:

paring, by the credential broker, data from the payload resulting in pared data.

7 . The method of claim 6 , wherein the pared data includes the service ticket.

8 . The method of claim 1 , comprising:

generating, by the credential broker, a binary representation of the service ticket.

9 . The method of claim 8 , wherein the binary representation of the service ticket comprises a byte array.

10 . The method of claim 1 , wherein the unique identifier is a workload identifier.

11 . The method of claim 10 , wherein the workload identifier comprises a plurality of identifying components.

12 . The method of claim 1 , comprising:

receiving, at a service registration processor, the service identifier.

13 . The method of claim 12 , comprising:

persisting, by the service registration processor, the service identifier in the application attestation datastore.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 3, 2024
From: SEIDENSTEIN, RICHARD; HETTIARACHCHI, KANISHKA; AHLUWALIA, ISH K.; KOTHARI, DARSHAK; GANGARAJU, VIMAL; UMMANENI, LAKSHMIPRASANNA; SARMA, KARABI
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 066989/0235 →
Priority Claims (1)
IN 202311046697 · Jul 11, 2023 · national
Continuity (1)
Related Publication 20250023859A1 · Jan 16, 2025
References Cited (5)
US 5684950A · Dare · 1997 [cited by examiner]
US 10454899B1 · Gabrielson · 2019 [cited by examiner]
US 20090259757A1 · Ben-Shachar · 2009 [cited by examiner]
US 20140331297A1 · Innes · 2014 [cited by examiner]
US 20160277400A1 · Maurya · 2016 [cited by examiner]