IP Library Granted Patent US 12705321
Granted Patent B2
US 12705321 · App. 17/791,475 · Granted Aug 11, 2026

Integrated identity management and monitoring system, apparatus, and storage medium

Inventors: Jatin Wadhwa (Tokyo, JP); Anshul Bhatt (Tokyo, JP); Shiv Chandra Pathak (Tokyo, JP); Sahitya Jain (Tokyo, JP)
Assignee: RAKUTEN MOBILE, INC.
G06F21/31G06F21/45
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12705321
App. No.
17/791,475
Granted
Aug 11, 2026
Kind
B2
Abstract

A method for integrated authentication and monitoring, executed by an electronic device, the method comprising: authenticating user credentials of a user using an identity broker, wherein the identity broker identifies an identity provider associated with the user credentials; generating detailed logs related to events associated with the authenticating; analyzing the generated logs; and generating an alarm based on the analyzing of the generated logs.

Claims (86)

1 . A method for integrated authentication and monitoring, executed by an electronic device, the method comprising:

authenticating user credentials of a user using an identity broker of a centralized identity management system, wherein the identity broker identifies an identity provider, from among a plurality of identity providers, associated with the user credentials, the plurality of identity providers respectively associated with a plurality of applications such that each identity provider authenticates users via the identity broker to grant access rights to a corresponding application associated with that identity provider;

generating, by an observation framework integrated in the centralized identity management system, detailed logs related to events associated with the authenticating;

analyzing, by the observation framework, the generated logs; and

generating, by the observation framework, an alarm based on the analyzing of the generated logs,

wherein the authenticating comprises:

determining, by the identity broker, the identity provider associated with an application to which the user is attempting access, from among the plurality of identity providers respectively associated with the plurality of applications;

issuing, by the identity broker, an authentication request to the determined identity provider; and

providing, by the identity broker, the user access to the application based on a successful authentication by the determined identity provider,

wherein the analyzing comprises a comparison between the generated logs and historically logged data, and

wherein the method further comprises:

determining there is a delay in one or more events based on the comparison between the generated logs and the historically logged data; and

identifying a source of the delay, based on the generated logs.

2 . The method of claim 1 , wherein the authenticating further comprises:

receiving the user credentials of the user;

receiving a security token from the identity provider indicating a successful authentication of the user by the identity provider; and

generating an access token for the user to access the application associated with the identity provider.

3 . The method of claim 1 , wherein the generating detailed logs comprises:

logging actions performed during any of the authenticating, user profile changes, role assignments, and new application registrations;

calculating key performance metrics associated with user actions based on the logging; and

calculating key performance metrics associated with respective applications based on the logging.

4 . The method of claim 1 , wherein the generating the alarm comprises displaying a notification on a user interface wherein the notification indicates details about the delay and the source of the delay.

5 . The method of claim 1 , further comprising determining, based on the comparison, at least one of:

a memory utilization in a pod is higher than a first threshold,

a CPU utilization of the pod is higher than a second threshold, or

a heap usage for the pod is higher than a third threshold; and

generating the alarm comprises displaying a notification on a user interface wherein the notification indicates details about the at least one determining.

6 . The method of claim 1 , wherein

prior to authenticating the user credentials, the method further comprises storing default admin credentials in an encrypted data vault, and wherein subsequent to generating the alarm, the method comprises generating a request to retrieve the default admin credentials from the encrypted data vault; and

address a source of the alarm using the default admin credentials.

7 . The method of claim 1 , wherein prior to authenticating the user credentials, the method further comprises registering a new application, and wherein the registering the new application comprises:

storing client secret credentials in an encrypted data vault;

in response to determining that the new application needs to be deployed, generating a request to retrieve the client secret credentials from the encrypted data vault; and

deploying the new application using the client secret credentials.

8 . The method of claim 1 , wherein prior to authenticating the user credentials, the method further comprises storing sensitive information associated with a new application, and wherein the storing the sensitive information for the new application comprises:

receiving information associated with the new application, wherein the information includes confidential information relating to the new application and customers of the new application;

extracting the confidential information relating to the new application and the customers of the new application; and

storing the confidential information relating to the new application and the customers of the new application in an encrypted data vault.

9 . An apparatus for integrated identity management and monitoring, the apparatus comprising:

a memory configured to store instructions; and

one or more processors configured to execute the instructions to:

authenticate user credentials of a user using an identity broker of a centralized identity management system, wherein the identity broker identifies an identity provider, from among a plurality of identity providers, associated with the user credentials, the plurality of identity providers respectively associated with a plurality of applications such that each identity provider authenticates users via the identity broker to grant access rights to a corresponding application associated with that identity provider;

generate, by an observation framework integrated in the centralized identity management system, detailed logs related to events associated with the authenticating;

analyze, by the observation framework, the generated logs; and

generate, by the observation framework, an alarm based on the analyzing of the generated logs,

wherein the authenticating comprises:

determining, by the identity broker, the identity provider associated with an application to which the user is attempting access, from among the plurality of identity providers respectively associated with the plurality of applications;

issuing, by the identity broker, an authentication request to the determined identity provider; and

providing, by the identity broker, the user access to the application based on a successful authentication by the determined identity provider,

wherein the analyzing comprises a comparison between the generated logs and historically logged data, and

wherein prior to authenticating the user credentials, the one or more processors is further configured to store default admin credentials in an encrypted data vault, and wherein subsequent to generating the alarm, on or more processors is further configured to generate a request to retrieve the default admin credentials from the encrypted data vault; and address a source of the alarm using the default admin credentials.

10 . The apparatus of claim 9 , wherein the authenticating further comprises:

receiving the user credentials of the user;

receiving a security token from the identity provider indicating a successful authentication of the user by the identity provider; and

generating an access token for the user to access the application associated with the identity provider.

11 . The apparatus of claim 9 , wherein the generating the detailed logs comprises:

logging actions performed during any of the authenticating, user profile changes, role assignments, and new application registrations;

calculating key performance metrics associated with user actions based on the logging; and

calculating key performance metrics associated with respective applications based on the logging.

12 . The apparatus of claim 9 , wherein prior to authenticating the user credentials, the one or more processors is further configured to register a new application, and wherein the registering the new application comprises:

storing client secret credentials in an encrypted data vault;

in response to determining that the new application needs to be deployed, generating a request to retrieve the client secret credentials from the encrypted data vault; and

deploying the new application using the client secret credentials.

13 . The apparatus of claim 9 , wherein prior to authenticating the user credentials, the one or more processors is further configured to store sensitive information associated with a new application, and wherein the storing the sensitive information for the new application comprises:

receiving information associated with the new application, wherein the information includes confidential information relating to the new application and customers of the new application;

extracting the confidential information relating to the new application and the customers of the new application; and

storing the confidential information relating to the new application and the customers of the new application in an encrypted data vault.

14 . A non-transitory computer-readable medium storing instructions, the instructions comprising: one or more instructions that, when executed by one or more processors of a device for automatic troubleshooting, cause the one or more processors to:

authenticate user credentials of a user using an identity broker of a centralized identity management system, wherein the identity broker identifies an identity provider, from among a plurality of identity providers, associated with the user credentials, the plurality of identity providers respectively associated with a plurality of applications such that each identity provider authenticates users via the identity broker to grant access rights to a corresponding application associated with that identity provider;

generate, by an observation framework integrated in the centralized identity management system, detailed logs related to events associated with the authenticating;

analyze, by the observation framework, the generated logs; and

generate, by the observation framework, an alarm based on the analyzing of the generated logs,

wherein the authenticating comprises:

determining, by the identity broker, the identity provider associated with an application to which the user is attempting access, from among the plurality of identity providers respectively associated with the plurality of applications;

issuing, by the identity broker, an authentication request to the determined identity provider; and

providing, by the identity broker, the user access to the application based on a successful authentication by the determined identity provider,

wherein the analyzing comprises a comparison between the generated logs and historically logged data, and

wherein prior to authenticating the user credentials, the one or more processors is further configured to store default admin credentials in an encrypted data vault, and wherein subsequent to generating the alarm, on or more processors is further configured to generate a request to retrieve the default admin credentials from the encrypted data vault; and address a source of the alarm using the default admin credentials.

15 . The non-transitory computer-readable medium of claim 14 , wherein the authenticating further comprises:

receiving the user credentials of the user;

receiving a security token from the identity provider indicating a successful authentication of the user by the identity provider; and

generating an access token for the user to access the application associated with the identity provider.

16 . The non-transitory computer-readable medium of claim 14 , wherein the generating the detailed logs comprises:

logging actions performed during any of the authenticating, user profile changes, role assignments, and new application registrations;

calculating key performance metrics associated with user actions based on the logging; and

calculating key performance metrics associated with respective applications based on the logging.