Cloud Application Identity Token Issuance for Seamless Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud platforms, applications face challenges in establishing identities dynamically, leading to cumbersome authentication processes that drain valuable time and impact developer experience, as they need to interface with computer-network authentication protocols and manage token lifecycles without relying on physical assets.

Innovation Solution

A method that involves receiving a request to deploy an application instance, authenticating using owner credentials, deploying the instance, recording the association, issuing platform-local identity tokens, and obtaining enterprise tokens to authenticate with other applications, allowing seamless connection without traditional authentication methods like passwords.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If applications interface with computer-network authentication protocols and manage token lifecycles in cloud platforms, then application identity establishment is achieved, but the process becomes cumbersome and time-consuming

Engineering Contradiction:
Improveapplication identity establishmentVSAvoidauthentication process time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary authentication actions by establishing the application's identity and issuing identity tokens during the deployment phase, before the application actually runs. This allows the application to skip authentication steps during runtime, resolving the contradiction between reliable identity establishment and time-consuming authentication processes

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary identity token system that mediates between the application and authentication services. The identity token acts as a credential that the application carries, eliminating the need for direct authentication protocol interactions and reducing authentication time while maintaining security

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If applications run in dynamic cloud environments without physical assets, then cloud platform flexibility is achieved, but identity establishment becomes challenging

Engineering Contradiction:
Improvecloud platform flexibilityVSAvoididentity establishment complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system creates a digital copy of identity credentials in the form of identity tokens that can be transmitted and presented electronically. This copying approach eliminates the need for physical authentication assets while maintaining secure identity verification in dynamic cloud environments

Inventive Principle:
Principle #26Copying

Solution Approach 2:

An intermediary token issuance service bridges the gap between physical security infrastructure and virtual cloud environments. This mediator translates physical asset-based authentication into digital token-based authentication, enabling flexible cloud deployment without compromising identity establishment security

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If traditional authentication methods like passwords are used, then security verification is achieved, but seamless connections to other services cannot be established

Engineering Contradiction:
Improvesecurity verificationVSAvoidconnection seamlessness
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces manual password-based authentication mechanics with automated token-based authentication. The identity token enables programmatic authentication without human intervention, achieving both security verification and seamless connections to services

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The application uses its own identity token to authenticate itself to services without requiring external authentication assistance. This self-service authentication mechanism maintains security while enabling seamless, automated connections

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11366891B2Method and system for facilitating an identification of an application
Publication Date: 2022.06.21 JPMORGAN CHASE BANK NA
  • US11366891B2 patent drawing
  • US11366891B2 patent drawing
  • US11366891B2 patent drawing

AI summary

Systems and methods for facilitating an identification of an application that runs on a platform are provided. The method includes receiving a request to deploy an instance of the application on the platform and an authentication credential relating to an owner of the application; authenticating the request; deploying the instance of the application on the platform; recording an association between the owner and the instance of the application; initiating an execution of the instance of the application without the authentication credential; issuing a platform-local identity token to the instance of the application; authenticating a request for a token describing the application owner using the platform-local identity token; receiving the requested token; providing a platform identity to an enterprise service; receiving a token describing an enterprise identity; receiving an authentication credential relating to the application owner; and using the authentication credential with respect to at least one other application.