IP Library Granted Patent US 12,694,143
Granted Patent B2
US 12,694,143 · App. 18/750,627 · Granted Jul 28, 2026

Federated identity management for data repositories

Inventors: Manav Ratan Mital (Mountain View, CA); Srinivas Nageswarrao Vadlamani (San Jose, CA); Pramod Chandraiah (Pleasanton, CA); Hugo Araújo de Sousa (Belo Horizonte, BR)
Assignee: Varonis Systems Inc.
G06F21/6218G06F11/3006G06F11/3438G06F11/3476G06F16/24547G06F21/31G06F21/604G06F21/6227G06F21/6254H04L63/0281H04L63/0884H04L63/101H04L63/102H04L63/104H04L63/105H04L63/1425H04L63/166H04L63/168H04L69/326H04L69/329G06F2221/2107H04L2463/082
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,694,143
App. No.
18/750,627
Granted
Jul 28, 2026
Kind
B2
Abstract

A method and system for performing federated identity management are described. The method and system include receiving a communication for a data source at a wrapper. The wrapper includes a dispatcher and a service. The dispatcher receives the communication and is data agnostic. The communication corresponds to end user credentials for an end user. The method and system include providing the communication from the dispatcher to the data source and to the service. The method and system also use the service to authenticate the end user based on the end user credentials and utilizing federated identity management.

Claims (54)

1 . A method, comprising:

receiving a communication for a data source at a wrapper, the wrapper including a dispatcher and a service, the dispatcher receiving the communication and being data agnostic, the communication corresponding to end user credentials for an end user;

providing the communication from the dispatcher to the data source and to the service;

authenticating, using the service, the end user based on the end user credentials and utilizing federated identity management;

performing a read only binding of the service to a federated identity management data source; and

preventing access to the data source if the end user is not authenticated utilizing the federated identity management;

wherein authenticating, using the service, the end user based on the end user credentials and utilizing federated identity management further comprises:

providing the end user credentials to the federated identity management data source; and

searching, using the read only binding, the federated identity management data source for the end user.

2 . The method of claim 1 , further comprising:

accessing the data source by the wrapper as a proxy for the end user if the end user is authenticated using the federated identity management.

3 . The method of claim 2 , further comprising:

logging end user activities for the data source.

4 . The method of claim 1 , wherein:

searching the federated identity management data source for the end user further comprises:

searching the federated identity management data source for at least one group to which the end user belongs.

5 . The method of claim 1 , further comprising:

binding the service to the federated identity management data source as a proxy for the end user if the end user is authenticated.

6 . A system, comprising:

a processor configured to:

receive a communication for a data source at a wrapper, the wrapper including a dispatcher and a service, the dispatcher receiving the communication and being data agnostic, the communication corresponding to end user credentials for an end user;

provide the communication from the dispatcher to the data source and to the service;

authenticate, using the service, the end user based on the end user credentials and utilizing federated identity management;

perform a read only binding of the service to a federated identity management data source; and

prevent access to the data source if the end user is not authenticated utilizing the federated identity management; and

a memory coupled to the processor and configured to provide the processor with instructions;

wherein to authenticate, using the service, the end user based on the end user credentials and utilizing federated identity management the processor is further configured to:

provide the end user credentials to the federated identity management data source; and

search, using the read only binding, the federated identity management data source for the end user.

7 . The system of claim 6 , wherein the processor is further configured to:

access the data source by the wrapper as a proxy for the end user if the end user is authenticated using the federated identity management.

8 . The system of claim 7 , wherein the processor is further configured to:

log end user activities for the data source.

9 . The system of claim 6 , wherein to search the federated identity management data source for the end user the processor is further configured to:

search the federated identity management data source for at least one group to which the end user belongs.

10 . The system of claim 6 , wherein the processor is further configured to:

bind the service to the federated identity management data source as a proxy for the end user if the end user is authenticated.

11 . A computer program product, the computer program product being embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

receiving a communication for a data source at a wrapper, the wrapper including a dispatcher and a service, the dispatcher receiving the communication and being data agnostic, the communication corresponding to end user credentials for an end user;

providing the communication from the dispatcher to the data source and to the service;

authenticating, using the service, the end user based on the end user credentials and utilizing federated identity management;

performing a read only binding of the service to a federated identity management data source; and

preventing access to the data source if the end user is not authenticated utilizing the federated identity management;

wherein authenticating, using the service, the end user based on the end user credentials and utilizing federated identity management further comprises:

providing the end user credentials to the federated identity management data source; and

searching, using the read only binding, the federated identity management data source for the end user.

12 . The computer program product of claim 11 , wherein the computer instructions further include computer instructions for:

accessing the data source by the wrapper as a proxy for the end user if the end user is authenticated using the federated identity management.

13 . The computer program product of claim 12 , wherein the computer instructions further include computer instructions for:

logging end user activities for the data source.

14 . The computer program product of claim 11 , wherein the computer instructions for searching the federated identity management data source for the end user further comprises further include computer instructions for:

searching the federated identity management data source for at least one group to which the end user belongs.

15 . The computer program product of claim 11 , wherein the computer instructions further include computer instructions for:

binding the service to the federated identity management data source as a proxy for the end user if the end user is authenticated.