Patents by Inventor Michael BAYLES

Michael BAYLES has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Publication number: 20260006027
    Abstract: Presented herein are systems and methods of authenticating clients to access data via proxy layers. A gateway on a proxy layer may receive a request from a client to access data in a compartment on the database layer. The request may include a token based at least on an encryption of an identifier of the compartment responsive to successful authentication of the request at an application layer. The gateway may, responsive to identifying the identifier as referencing the compartment, determine that the client is authorized to access the data in the compartment on the database layer through the proxy layer. The gateway may select a permission for the client to access the compartment through the proxy layer based on the context of the request. The gateway may generate an indication that the client is authorized to access the data in accordance with the permission.
    Type: Application
    Filed: September 2, 2025
    Publication date: January 1, 2026
    Applicant: Stripe, Inc.
    Inventors: Gael HATCHUE, Michael BAYLES, Benjamin MAYS, Karla BURNETT, Frank HUANG, Michael CHANG
  • Patent number: 12489631
    Abstract: Presented herein are systems and methods of generating security-aware tokens. A token may include (i) a first signature encrypted by the second service and (ii) an identification of the plurality of databases accessible using the first token. When a processor determines that the token is valid, the processor may generate a second signature using an encryption key of the first service and a third signature using the shared key of the second service. Thereby a second token derivative of the first token can be created to include (i) the second signature of the first service, (ii) the third signature generated from the shared key of the second service, and (iii) the identification of the plurality of databases accessible using the second token.
    Type: Grant
    Filed: December 11, 2023
    Date of Patent: December 2, 2025
    Assignee: Stripe, Inc.
    Inventors: Gael Hatchue, Julien Boeuf, Eric Woroshow, Adam Stubblefield, Michael Bayles
  • Patent number: 12413589
    Abstract: Presented herein are systems and methods of authenticating clients to access data via proxy layers. A gateway on a proxy layer may receive a request from a client to access data in a compartment on the database layer. The request may include a token based at least on an encryption of an identifier of the compartment responsive to successful authentication of the request at an application layer. The gateway may, responsive to identifying the identifier as referencing the compartment, determine that the client is authorized to access the data in the compartment on the database layer through the proxy layer. The gateway may select a permission for the client to access the compartment through the proxy layer based on the context of the request. The gateway may generate an indication that the client is authorized to access the data in accordance with the permission.
    Type: Grant
    Filed: December 11, 2023
    Date of Patent: September 9, 2025
    Assignee: Stripe, Inc.
    Inventors: Gael Hatchue, Michael Bayles, Benjamin Mays, Karla Burnett, Frank Huang, Michael Chang
  • Publication number: 20250193185
    Abstract: Presented herein are systems and methods of authenticating clients to access data via proxy layers. A gateway on a proxy layer may receive a request from a client to access data in a compartment on the database layer. The request may include a token based at least on an encryption of an identifier of the compartment responsive to successful authentication of the request at an application layer. The gateway may, responsive to identifying the identifier as referencing the compartment, determine that the client is authorized to access the data in the compartment on the database layer through the proxy layer. The gateway may select a permission for the client to access the compartment through the proxy layer based on the context of the request. The gateway may generate an indication that the client is authorized to access the data in accordance with the permission.
    Type: Application
    Filed: December 11, 2023
    Publication date: June 12, 2025
    Inventors: Gael HATCHUE, Michael BAYLES, Benjamin Mays, Karla BURNETT, Frank HUANG, Michael CHANG
  • Publication number: 20250193009
    Abstract: Presented herein are systems and methods of generating security-aware tokens. A token may include (i) a first signature encrypted by the second service and (ii) an identification of the plurality of databases accessible using the first token. When a processor determines that the token is valid, the processor may generate a second signature using an encryption key of the first service and a third signature using the shared key of the second service. Thereby a second token derivative of the first token can be created to include (i) the second signature of the first service, (ii) the third signature generated from the shared key of the second service, and (iii) the identification of the plurality of databases accessible using the second token.
    Type: Application
    Filed: December 11, 2023
    Publication date: June 12, 2025
    Inventors: Gael HATCHUE, Julien BOEUF, Eric WOROSHOW, Adam STUBBLEFIELD, Michael BAYLES