IP Library Granted Patent US 11,457,028
Granted Patent B2
US 11,457,028 · App. 16/725,541 · Granted Sep 27, 2022

Systems and methods for emergency shutdown and restore of access entitlements responsive to security breach

Inventors: Neal Kaye (Austin, TX); Rohit Gupta (Pittsford, NY)
Assignee: SAILPOINT TECHNOLOGIES, INC.
H04L63/1416G06F16/2379H04L63/102
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,457,028
App. No.
16/725,541
Granted
Sep 27, 2022
Kind
B2
Abstract

Responsive to a user instruction or a security breach occurring in an enterprise computing environment, an emergency shutdown and restore module is adapted to obtain and evaluate an identity population definition to determine a population of identities (e.g., a forensic team) associated with accounts distributed across applications in the enterprise computing environment. The emergency shutdown and restore module is further adapted to determine source systems of such accounts and communicate with those source systems via source-specific connectors. The emergency shutdown and restore module can respectively request the source systems to shut down access to the applications by the accounts associated with the population of identities, or to exclude the accounts associated with the population of identities in shutting down access to the applications. After performing a security breach analysis, the emergency shutdown and restore module can request the source systems to restore access respectively, significantly reducing impact to enterprise operations.

Claims (47)

1. A method, comprising:

obtaining, by an emergency shutdown and restore module in response to a user instruction or a security breach occurring in an enterprise computing environment, an identity population definition, the identity population definition defining a population of identities in the enterprise computing environment based on a set of attributes of identity management artifacts;

determining, by the emergency shutdown and restore module based at least on the identity population definition, a set of accounts associated with the population of identities, the set of accounts distributed across applications in the enterprise computing environment;

determining, by the emergency shutdown and restore module, source systems of the set of accounts, each of the source systems having a source-specific connector; and

requesting, by the emergency shutdown and restore module via the source-specific connector respectively, each of the source systems to shut down access to the applications by the set of accounts associated with the population of identities, or to exclude the set of accounts associated with the population of identities in shutting down access to the applications in the enterprise computing environment.

2. The method according to claim 1 , wherein the identity management artifacts comprise at least one of an identity, entitlement, role, event, access profile, or account activity imported or determined from data obtained from a set of source systems within the enterprise computing environment.

3. The method according to claim 1 , wherein the set of attributes comprises at least one of an identity or account attribute, source or entitlement information, an existing access right, a job title, an employment identification, location information, or a risk score.

4. The method according to claim 1 , wherein the identity management artifacts are stored in an identity management data store of an identity management system and wherein the identity management system comprises the emergency shutdown and restore module.

5. The method according to claim 1 , further comprising:

providing a user interface for creating or configuring the identity population definition, wherein the identity population definition is defined dynamically through the user interface at a time of the security breach occurring in the enterprise computing environment.

6. The method according to claim 1 , further comprising:

providing a user interface for creating or configuring the identity population definition, wherein the identity population definition is predefined through the user interface independently of the security breach occurring in the enterprise computing environment; and

storing the identity population definition in an identity management data store accessible by the emergency shutdown and restore module.

7. The method according to claim 1 , further comprising:

requesting, by the emergency shutdown and restore module via the source-specific connector respectively, each of the source systems to restore access to the applications by the set of accounts associated with the population of identities, or to exclude the set of accounts associated with the population of identities in restoring access to the applications in the enterprise computing environment.

8. An emergency shutdown and restore system, comprising:

a processor;

a non-transitory computer-readable medium; and

stored instructions translatable by the processor for:

obtaining, in response to a user instruction or a security breach occurring in an enterprise computing environment, an identity population definition, the identity population definition defining a population of identities in the enterprise computing environment based on a set of attributes of identity management artifacts;

determining, based at least on the identity population definition, a set of accounts associated with the population of identities, the set of accounts distributed across applications in the enterprise computing environment;

determining source systems of the set of accounts, each of the source systems having a source-specific connector; and

requesting, via the source-specific connector respectively, each of the source systems to shut down access to the applications by the set of accounts associated with the population of identities, or to exclude the set of accounts associated with the population of identities in shutting down access to the applications in the enterprise computing environment.

9. The emergency shutdown and restore system of claim 8 , wherein the identity management artifacts comprise at least one of an identity, entitlement, role, event, access profile, or account activity imported or determined from data obtained from a set of source systems within the enterprise computing environment.

10. The emergency shutdown and restore system of claim 8 , wherein the set of attributes comprises at least one of an identity or account attribute, source or entitlement information, an existing access right, a job title, an employment identification, location information, or a risk score.

11. The emergency shutdown and restore system of claim 8 , wherein the identity management artifacts are stored in an identity management data store of an identity management system and wherein the identity management system comprises the emergency shutdown and restore system.

12. The emergency shutdown and restore system of claim 8 , wherein the stored instructions are further translatable by the processor for:

providing a user interface for creating or configuring the identity population definition, wherein the identity population definition is defined dynamically through the user interface at a time of the security breach occurring in the enterprise computing environment.

13. The emergency shutdown and restore system of claim 8 , wherein the stored instructions are further translatable by the processor for:

providing a user interface for creating or configuring the identity population definition, wherein the identity population definition is predefined through the user interface independently of the security breach occurring in the enterprise computing environment; and

storing the identity population definition in an identity management data store accessible by the emergency shutdown and restore system.

14. The emergency shutdown and restore system of claim 8 , wherein the stored instructions are further translatable by the processor for:

requesting, via the source-specific connector respectively, each of the source systems to restore access to the applications by the set of accounts associated with the population of identities, or to exclude the set of accounts associated with the population of identities in restoring access to the applications in the enterprise computing environment.

15. A computer program product for emergency shutdown and restore, the computer program product comprising a non-transitory computer-readable medium storing instructions translatable by a processor for:

obtaining, in response to a user instruction or a security breach occurring in an enterprise computing environment, an identity population definition, the identity population definition defining a population of identities in the enterprise computing environment based on a set of attributes of identity management artifacts;

determining, based at least on the identity population definition, a set of accounts associated with the population of identities, the set of accounts distributed across applications in the enterprise computing environment;

determining source systems of the set of accounts, each of the source systems having a source-specific connector; and

requesting, via the source-specific connector respectively, each of the source systems to shut down access to the applications by the set of accounts associated with the population of identities, or to exclude the set of accounts associated with the population of identities in shutting down access to the applications in the enterprise computing environment.

16. The computer program product of claim 15 , wherein the identity management artifacts comprise at least one of an identity, entitlement, role, event, access profile, or account activity imported or determined from data obtained from a set of source systems within the enterprise computing environment.

17. The computer program product of claim 15 , wherein the set of attributes comprises at least one of an identity or account attribute, source or entitlement information, an existing access right, a job title, an employment identification, location information, or a risk score.

18. The computer program product of claim 15 , wherein the instructions are further translatable by the processor for:

providing a user interface for creating or configuring the identity population definition, wherein the identity population definition is defined dynamically through the user interface at a time of the security breach occurring in the enterprise computing environment.

19. The computer program product of claim 15 , wherein the instructions are further translatable by the processor for:

providing a user interface for creating or configuring the identity population definition, wherein the identity population definition is predefined through the user interface independently of the security breach occurring in the enterprise computing environment; and

storing the identity population definition in an identity management data store.

20. The computer program product of claim 15 , wherein the instructions are further translatable by the processor for:

requesting, via the source-specific connector respectively, each of the source systems to restore access to the applications by the set of accounts associated with the population of identities, or to exclude the set of accounts associated with the population of identities in restoring access to the applications in the enterprise computing environment.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded Jun 27, 2025
From: GOLUB CAPITAL MARKETS LLC
To: SAILPOINT TECHNOLOGIES, INC.; SAILPOINT TECHNOLOGIES HOLDINGS, INC.
Reel/Frame 071776/0411 →
PATENT SECURITY AGREEMENT Recorded Jun 25, 2025
From: SAILPOINT TECHNOLOGIES, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071724/0511 →
SECURITY INTEREST Recorded Aug 17, 2022
From: SAILPOINT TECHNOLOGIES, INC.
To: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 061202/0540 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 29, 2020
From: KAYE, NEAL; GUPTA, ROHIT
To: SAILPOINT TECHNOLOGIES, INC.
Reel/Frame 051664/0433 →
Continuity (1)
Related Publication 20210194895A1 · Jun 24, 2021