IP Library Granted Patent US 12695793
Granted Patent B1
US 12695793 · App. 19/382,040 · Granted Jul 28, 2026

Distributing security policies

Inventors: Philip David Hassey (Rye, CO); Patrick Richard Jakubowski (Seattle, WA); Kevin David Jamieson (North Vancouver, CA); William Craig Jones (Lake Charles, LA)
Assignee: Delinea Inc.
H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12695793
App. No.
19/382,040
Granted
Jul 28, 2026
Kind
B1
Abstract

Embodiments distribute security policies in network environments. Entity change entries associated with updating, adding or removing entities from an entity datastore may be obtained. A request to obtain a security state view may be employed to perform additional actions, including: obtaining a new log identifier based on a current log identifier associated with the request; obtaining log change entries associated with the new log identifier and the plurality of entities based on the entity change entries; collecting one or more entities based on other log change entries that may be associated with log identifiers that may be associated with the request; obtaining the security state view based on the one or more entities such that the security state view may be associated with the new log identifier and such that the security state view enforces security policies for the one or more entities in the computing environment.

Claims (80)

1 . A method for managing interactions with applications in a computing environment using one or more processors that are configured to execute instructions that cause performance of actions, comprising:

obtaining one or more entity change entries associated with updating, adding or removing a plurality of entities from an entity datastore; and

employing a request to obtain a security state view to perform further actions, including:

obtaining a new log identifier based on a current log identifier associated with the request;

obtaining one or more log change entries associated with the new log identifier and the plurality of entities based on the one or more entity change entries;

collecting one or more entities based on one or more other log change entries that are associated with one or more log identifiers that are associated with the request; and

obtaining the security state view based on the one or more entities, wherein the security state view is associated with the new log identifier, and wherein the security state view enforces one or more security policies for the one or more entities in the computing environment; and

obtaining a user interface that includes one or more display panels for content that includes a report associated with the security state view that is dynamically transformed and arranged for display to a user based on one or more of user interaction telemetry, user feedback or telemetry metrics.

2 . The method of claim 1 , further comprising:

monitoring one or more entity information sources that include one or more of a configuration database, an identity provider, a credential service, or a directory system;

obtaining one or more entity modifications from the one or more entity information sources;

collecting one or more entity attribute changes that are associated with policy enforcement; and

obtaining an entity change entry for each entity associated with the one or more entity attribute changes.

3 . The method of claim 1 , wherein obtaining the one or more entity change entries, further comprises:

collecting one or more entity identifiers that correspond to one or more updated entities; and

associating each of the one or more entity identifiers with an entity change entry.

4 . The method of claim 1 , wherein the one or more entities include one or more of a user account, a resource endpoint, an application service, a network segment, or a policy rule that is referenced by the one or more security policies.

5 . The method of claim 1 , further comprising:

collecting one or more mesh agents that are associated with another log identifier and another security state view; and

obtaining information associated with one or more differences between the security state view and the other security state views based on the security state view, the other log identifier, and the other security state view, wherein the information is communicated to the one or more mesh agents.

6 . The method of claim 1 , further comprising:

obtaining one or more active sessions that are associated with one or more security state views, wherein the one or more active sessions are associated with separate log identifiers;

preserving the one or more security state views that are associated with the one or more active sessions;

collecting one or more session completion events associated with the one or more active sessions; and

discarding the one or more security state views that are associated with the one or more session completion events.

7 . The method of claim 1 , wherein obtaining the security state view, further comprises:

obtaining one or more partial security state views based on the one or more security policies that reference the one or more entities; and

updating the security state view to include the one or more partial security state views.

8 . The method of claim 1 , further comprising:

obtaining one or more adapters configured to transform entity information from one or more entity datastore formats into one or more security state formats, wherein the one or more adapters include one or more of an instruction set, a data transformation rule, a format converter, or an entity attribute filter; and

converting the one or more entities from the one or more entity datastore formats into one or more security state view formats for inclusion in the security state view to enforce the one or more security policies.

9 . A network computer for managing interactions with applications, comprising:

a memory that stores at least instructions; and

one or more processors that execute instructions that are configured to cause actions, including:

obtaining one or more entity change entries associated with updating,

adding or removing a plurality of entities from an entity datastore; and

employing a request to obtain a security state view to perform further actions, including:

obtaining a new log identifier based on a current log identifier associated with the request;

obtaining one or more log change entries associated with the new log identifier and the plurality of entities based on the one or more entity change entries;

collecting one or more entities based on one or more other log change entries that are associated with one or more log identifiers that are associated with the request; and

obtaining the security state view based on the one or more entities, wherein the security state view is associated with the new log identifier, and wherein the security state view enforces one or more security policies for the one or more entities in the computing environment; and

obtaining a user interface that includes one or more display panels for content that includes a report associated with the security state view that is dynamically transformed and arranged for display to a user based on one or more of user interaction telemetry, user feedback or telemetry metrics.

10 . The network computer of claim 9 , wherein the one or more processors execute instructions that are configured to cause actions, further comprising:

monitoring one or more entity information sources that include one or more of a configuration database, an identity provider, a credential service, or a directory system;

obtaining one or more entity modifications from the one or more entity information sources;

collecting one or more entity attribute changes that are associated with policy enforcement; and

obtaining an entity change entry for each entity associated with the one or more entity attribute changes.

11 . The network computer of claim 9 , wherein obtaining the one or more entity change entries, further comprises:

collecting one or more entity identifiers that correspond to one or more updated entities; and

associating each of the one or more entity identifiers with an entity change entry.

12 . The network computer of claim 9 , wherein the one or more entities include one or more of a user account, a resource endpoint, an application service, a network segment, or a policy rule that is referenced by the one or more security policies.

13 . The network computer of claim 9 , wherein the one or more processors execute instructions that are configured to cause actions, further comprising:

collecting one or more mesh agents that are associated with another log identifier and another security state view; and

obtaining information associated with one or more differences between the security state view and the other security state views based on the security state view, the other log identifier, and the other security state view, wherein the information is communicated to the one or more mesh agents.

14 . The network computer of claim 9 , wherein the one or more processors execute instructions that are configured to cause actions, further comprising:

obtaining one or more active sessions that are associated with one or more security state views, wherein the one or more active sessions are associated with separate log identifiers;

preserving the one or more security state views that are associated with the one or more active sessions;

collecting one or more session completion events associated with the one or more active sessions; and

discarding the one or more security state views that are associated with the one or more session completion events.

15 . The network computer of claim 9 , wherein obtaining the security state view, further comprises:

obtaining one or more partial security state views based on the one or more security policies that reference the one or more entities; and

updating the security state view to include the one or more partial security state views.

16 . The network computer of claim 9 , wherein the one or more processors execute instructions that are configured to cause actions, further comprising:

obtaining one or more adapters configured to transform entity information from one or more entity datastore formats into one or more security state formats, wherein the one or more adapters include one or more of an instruction set, a data transformation rule, a format converter, or an entity attribute filter; and

converting the one or more entities from the one or more entity datastore formats into one or more security state view formats for inclusion in the security state view to enforce the one or more security policies.

17 . A processor readable non-transitory storage media that includes instructions configured for managing interactions with applications in a computing environment, wherein execution of the instructions by one or more processors on one or more network computers performs actions, comprising:

obtaining one or more entity change entries associated with updating, adding or removing a plurality of entities from an entity datastore; and

employing a request to obtain a security state view to perform further actions, including:

obtaining a new log identifier based on a current log identifier associated with the request;

obtaining one or more log change entries associated with the new log identifier and the plurality of entities based on the one or more entity change entries;

collecting one or more entities based on one or more other log change entries that are associated with one or more log identifiers that are associated with the request; and

obtaining the security state view based on the one or more entities, wherein the security state view is associated with the new log identifier, and wherein the security state view enforces one or more security policies for the one or more entities in the computing environment; and

obtaining a user interface that includes one or more display panels for content that includes a report associated with the security state view that is dynamically transformed and arranged for display to a user based on one or more of user interaction telemetry, user feedback or telemetry metrics.

18 . The media of claim 17 , wherein the one or more entities include one or more of a user account, a resource endpoint, an application service, a network segment, or a policy rule that is referenced by the one or more security policies.

19 . The media of claim 17 , further comprising:

collecting one or more mesh agents that are associated with another log identifier and another security state view; and

obtaining information associated with one or more differences between the security state view and the other security state views based on the security state view, the other log identifier, and the other security state view, wherein the information is communicated to the one or more mesh agents.

20 . The media of claim 17 , further comprising:

obtaining one or more adapters configured to transform entity information from one or more entity datastore formats into one or more security state formats, wherein the one or more adapters include one or more of an instruction set, a data transformation rule, a format converter, or an entity attribute filter; and

converting the one or more entities from the one or more entity datastore formats into one or more security state view formats for inclusion in the security state view to enforce the one or more security policies.