Method for provision of access grant

US12184634B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12184634-B2
Application numberUS-202117444413-A
CountryUS
Kind codeB2
Filing dateAug 4, 2021
Priority dateAug 5, 2020
Publication dateDec 31, 2024
Grant dateDec 31, 2024

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method for validating an access request with respect to an application is provided. The method includes: receiving an access request from a user with respect to an application; retrieving, from a memory, group identification information that relates to at least one group to which the user belongs; retrieving, from the memory, scope information that indicates qualifications and/or characteristics of a relationship between the user and the at least one group; and generating a token that notifies the application of the group identification information and the scope information, and is usable by the application for validating the access request. The method may be implemented in an Active Directory Federation Services (AD FS) environment.

First claim

Opening claim text (preview).

What is claimed is: 1. A method for validating an access request with respect to an application, the method being implemented by at least one processor, the method comprising: receiving, from a user, an access request with respect to an application; generating, by the at least one processor, a relying party object (RPO) for the application in an active directory (AD) memory; retrieving, by the at least one processor from a memory, group identification information that relates to at least one group to which the user belongs; analyzing, by the at least one processor, the group identification information to determine a group identity for each of the at least one group and scope information for each of the at least one group, wherein the scope information relates to at least one characteristic of a relationship between the user and the at least one group; generating, by the at least one processor, at least one string of characters associated with the user, wherein each at least one string includes the group identity of at least one of the at least one group to which the user belongs and at least one identity of the scope information; determining, by the at least one processor for each of the at least one string, whether the string matches an identity of the application; generating, by the at least one processor, a relying party link between the user and the application for each string that matches the identity of the application, wherein the relying party link contains the RPO; generating, by the at least one processor, a token that includes each string having the relying party link, the token being usable to validate the access request; and transmitting, to the application, the token in order to facilitate a validation of the access request. 2. The method of claim 1 , wherein the at least one processor includes a processor that is hosted on an Active Directory Federation Services (AD FS) server, and the memory includes the AD memory. 3. The method of claim 1 , wherein the group identification information includes information that relates to at least one from among a job title and a job function of the user. 4. The method of claim 1 , wherein the retrieving of the scope information comprises retrieving the relying party link, wherein the relying party link is created in a direction from the user to the application. 5. The method of claim 4 , wherein the scope information includes information that relates to at least one from among a product restriction, a geographical restriction, and an authorization level restriction. 6. The method of claim 4 , wherein the generating of the token comprises retrieving information that identifies the user in conjunction with all existing links between the application and the user. 7. The method of claim 1 , wherein when the application includes a trading application that is usable for executing trades of security instruments, the scope information includes information that relates to at least one restriction for a trade to be executed by the user. 8. The method of claim 1 , further comprising: creating a link between the user and the application for each scope information for each at least one group to which the user belongs. 9. The method of claim 1 , further comprising: translating, by the at least one processor via the AD, the RPO to a uniform resource indicator (URI). 10. A computing apparatus for validating an access request with respect to an application, the computing apparatus comprising: a processor; a memory; and a communication interface coupled to each of the processor and the memory, wherein the processor is configured to: receive, from a user via the communication interface, an access request with respect to an application; generate a relying party object (RPO) for the application in an active directory (AD) memory; retrieve, from the memory, group identification information that relates to at least one group to which the user belongs; analyze the group identification information to determine a group identity for each of the at least one group and scope information for each of the at least one group, wherein the scope information relates to at least one characteristic of a relationship between the user and the at least one group; generate at least one string of characters associated with the user, wherein each at least one string includes the group identity of at least one of the at least one group to which the user belongs and at least one identity of the scope information; determine, for each of the at least one string, whether the string matches an identity of the application; generate a relying party link between the user and the application for each string that matches the identity of the application, wherein the relying party link contains the RPO; generate a token that includes each string having the relying party link, the token being usable to validate the access request; and transmit, to the application via the communication interface, the token in order to facilitate a validation of the access request. 11. The computing apparatus of claim 10 , wherein the processor is hosted on an Active Directory Federation Services (AD FS) server, and the memory includes the AD memory. 12. The computing apparatus of claim 10 , wherein the group identification information includes information that relates to at least one from among a job title and a job function of the user. 13. The computing apparatus of claim 10 , wherein the processor is further configured to retrieve the scope information by retrieving the relying party link, wherein the relying party link is created in a direction from the user to the application. 14. The computing apparatus of claim 13 wherein the scope information includes information that relates to at least one from among a product restriction, a geographical restriction, and an authorization level restriction. 15. The computing apparatus of claim 13 , wherein the processor is further configured to generate the token by retrieving information that identifies the user in conjunction with all existing links between the application and the user. 16. The computing apparatus of claim 10 , wherein when the application includes a trading application that is usable for executing trades of security instruments, the scope information includes information that relates to at least one restriction for a trade to be executed by the user. 17. The computing apparatus of claim 10 , further comprising: creating a link between the user and the application for each scope information for each at least one group to which the user belongs. 18. The computing apparatus of claim 10 , further comprising: translate, via the AD, the RPO to a uniform resource indicator (URI). 19. A non-transitory computer readable storage medium storing instructions for validating an access request with respect to an application, the storage medium comprising executable code which, when executed by a processor, causes the processor to: receive, from a user, an access request with respect to an application; generate a relying party object (RPO) for the application in an active directory (AD) memory; retrieve, from a memory, group identification information that relates to at least one group to which the user belongs; analyze the group identification information to determine a group identity for each of the at least one group and scope information for each of the at least one group, wherein the scope information relates to at least one characteristic of a relationship between the user

Assignees

Inventors

Classifications

  • using tickets or tokens, e.g. Kerberos (network architectures or network communication protocols for entities authentication using tickets in a packet data network H04L63/0807) · CPC title

  • Entity profiles · CPC title

  • Grouping of entities · CPC title

  • Multiple levels of security · CPC title

  • using tickets, e.g. Kerberos (cryptographic mechanisms or cryptographic arrangements for entity authentication using tickets or tokens H04L9/3213) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12184634B2 cover?
A method for validating an access request with respect to an application is provided. The method includes: receiving an access request from a user with respect to an application; retrieving, from a memory, group identification information that relates to at least one group to which the user belongs; retrieving, from the memory, scope information that indicates qualifications and/or characterist…
Who is the assignee on this patent?
Jpmorgan Chase Bank Na
What technology area does this patent fall under?
Primary CPC classification H04L63/0815. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Dec 31 2024 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).