IP Library Granted Patent US 10,862,928
Granted Patent B1
US 10,862,928 · App. 16/900,530 · Granted Dec 8, 2020

System and method for role validation in identity management artificial intelligence systems using analysis of network identity graphs

Inventors: Mohamed M. Badawy (Round Rock, TX); Jostine Fei Ho (Austin, TX); Rajat Kabra (Austin, TX)
Assignee: SAILPOINT TECHNOLOGIES, INC.
H04L63/205G06F21/604G06N5/02G06N5/04H04L63/102H04L63/104G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,862,928
App. No.
16/900,530
Granted
Dec 8, 2020
Kind
B1
Abstract

Systems and methods for embodiments of a graph based artificial intelligence systems for identity management are disclosed. Embodiments of the identity management systems disclosed herein may utilize a network graph approach to analyzing roles of a distributed networked enterprise computing environment. Specifically, in certain embodiments, an artificial intelligence based identity management systems may utilize role graphs to assess the role structure of a distributed enterprise computing environment.

Claims (59)

1. An identity management system, comprising:

a data store;

a processor;

a non-transitory, computer-readable storage medium, including computer instructions, when executed by the processor, cause the system to perform the steps of:

obtaining identity management data from one or more identity management systems in a distributed enterprise computing environment, the identity management data comprising data on a set of roles, a set of entitlements, and a set of identities, wherein the set of roles, set of entitlements and set of identities are utilized in identity management in the distributed enterprise computing environment;

evaluating the identity management data to determine the set or roles, identities of the set of identities associated with each of the set of roles and entitlements of the set of entitlements associated with the set of roles;

generating a first role graph from the identity management data by:

creating a node of the first role graph for each of the determined set of roles;

for each first identity and second identity that share at least one entitlement of the set of entitlements or at least one identity of the set of identities, creating an edge of the first role graph between a first node representing a first role and a second node of the first role graph representing a second role; and

generating a weight for each edge of the first role graph between each first node representing the first role and second node representing the second role based on the at least one entitlement or the at least one identity shared between the first role represented by the first node and the second role represented by the second node;

storing the first role graph in the data store;

obtaining a pruning threshold associated with the first role graph;

pruning the set of edges of the first role graph based on the pruning threshold and the weight for each of the set of edges to generate a second role graph;

storing the second role graph in the data store;

determining a health metric for the set of roles associated with the distributed enterprise computing environment based on a structure of the second role graph; and

presenting the health metric and the second role graph to a user through a user interface.

2. The system of claim 1 , wherein the each edge is an access similarity relationship and the weight generated for each edge of the first role graph between each first node and second node is an access similarity weight based on a number of shared entitlements between the first role represented by the first node and the second role represented by the second node.

3. The system of claim 1 , wherein the each edge is a concurrency similarity relationship and the weight generated for each edge of the first role graph between each first node and second node is a concurrent similarity weight based on a number of identities that have both the first role represented by the first node and the second role represented by the second node.

4. The system of claim 3 , wherein the pruning of the first role graph is based on a concurrency count comprising the number of identities that include both roles.

5. The system of claim 1 , wherein the health metric for the set of roles associated with the distributed enterprise computing environment is a scaling metric that measures a deviation from an optimal structure of the second role graph.

6. The system of claim 5 , wherein the deviation from the optimal structure is determined based on the number of edges in the second role graph.

7. The system of claim 1 , wherein the health metric is based on a number of identities or entitlements associated with each role represented in the second role graph.

8. A method for managing roles, comprising the steps of:

obtaining identity management data from one or more identity management systems in a distributed enterprise computing environment via one or more of computer network connections, the identity management data comprising data on a set of roles, a set of entitlements, and a set of identities, wherein the set of roles, set of entitlements and set of identities are utilized in identity management in the distributed enterprise computing environment;

evaluating the identity management data to determine the set or roles, identities of the set of identities associated with each of the set of roles and entitlements of the set of entitlements associated with the set of roles;

generating a first role graph from the identity management data by:

creating a node of the first role graph for each of the determined set of roles;

for each first identity and second identity that share at least one entitlement of the set of entitlements or at least one identity of the set of identities, creating an edge of the first role graph between a first node representing a first role and a second node of the first role graph representing a second role; and

generating a weight for each edge of the first role graph between each first node representing the first role and second node representing the second role based on the at least one entitlement or the at least one identity shared between the first role represented by the first node and the second role represented by the second node;

storing the first role graph in the data store;

obtaining a pruning threshold associated with the first role graph;

pruning the set of edges of the first role graph based on the pruning threshold and the weight for each of the set of edges to generate a second role graph;

storing the second role graph;

determining a health metric for the set of roles associated with the distributed enterprise computing environment based on a structure of the second role graph; and

presenting the health metric and the second role graph to a user through a user interface.

9. The method of claim 8 , wherein the each edge is an access similarity relationship and the weight generated for each edge of the first role graph between each first node and second node is an access similarity weight based on a number of shared entitlements between the first role represented by the first node and the second role represented by the second node.

10. The method of claim 8 , wherein the each edge is a concurrency similarity relationship and the weight generated for each edge of the first role graph between each first node and second node is a concurrent similarity weight based on a number of identities that have both the first role represented by the first node and the second role represented by the second node.

11. The method of claim 10 , wherein the pruning of the first role graph is based on a concurrency count comprising the number of identities that include both roles.

12. The method of claim 8 , wherein the health metric for the set of roles associated with the distributed enterprise computing environment is a scaling metric that measures a deviation from an optimal structure of the second role graph.

13. The method of claim 12 , wherein the deviation from the optimal structure is determined based on the number of edges in the second role graph.

14. The method of claim 8 , wherein the health metric is based on a number of identities or entitlements associated with each role represented in the second role graph.

15. A non-transitory computer readable medium, comprising computer instructions, when executed by a computer processor, cause the computer process to perform the steps of:

obtaining identity management data from one or more identity management systems in a distributed enterprise computing environment, the identity management data comprising data on a set of roles, a set of entitlements, and a set of identities, wherein the set of roles, set of entitlements and set of identities are utilized in identity management in the distributed enterprise computing environment;

evaluating the identity management data to determine the set or roles, identities of the set of identities associated with each of the set of roles and entitlements of the set of entitlements associated with the set of roles;

generating a first role graph from the identity management data by:

creating a node of the first role graph for each of the determined set of roles, for each first identity and second identity that share at least one entitlement of the set of entitlements or at least one identity of the set of identities, creating an edge of the first role graph between a first node representing a first role and a second node of the first role graph representing a second role; and

generating a weight for each edge of the first role graph between each first node representing the first role and second node representing the second role based on the at least one entitlement or the at least one identity shared between the first role represented by the first node and the second role represented by the second node;

storing the first role graph in the data store;

obtaining a pruning threshold associated with the first role graph;

pruning the set of edges of the first role graph based on the pruning threshold and the weight for each of the set of edges to generate a second role graph;

storing the second role graph;

determining a health metric for the set of roles associated with the distributed enterprise computing environment based on a structure of the second role graph; and

presenting the health metric and the second role graph to a user through a user interface.

16. The non-transitory computer readable medium of claim 15 , wherein the each edge is an access similarity relationship and the weight generated for each edge of the first role graph between each first node and second node is an access similarity weight based on a number of shared entitlements between the first role represented by the first node and the second role represented by the second node.

17. The non-transitory computer readable medium of claim 15 , wherein the each edge is a concurrency similarity relationship and the weight generated for each edge of the first role graph between each first node and second node is a concurrent similarity weight based on a number of identities that have both the first role represented by the first node and the second role represented by the second node.

18. The non-transitory computer readable medium of claim 17 , wherein the pruning of the first role graph is based on a concurrency count comprising the number of identities that include both roles.

19. The non-transitory computer readable medium of claim 15 , wherein the health metric for the set of roles associated with the distributed enterprise computing environment is a scaling metric that measures a deviation from an optimal structure of the second role graph.

20. The non-transitory computer readable medium of claim 19 , wherein the deviation from the optimal structure is determined based on the number of edges in the second role graph.

21. The non-transitory computer readable medium of claim 15 , wherein the health metric is based on a number of identities or entitlements associated with each role represented in the second role graph.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded Jun 27, 2025
From: GOLUB CAPITAL MARKETS LLC
To: SAILPOINT TECHNOLOGIES, INC.; SAILPOINT TECHNOLOGIES HOLDINGS, INC.
Reel/Frame 071776/0411 →
PATENT SECURITY AGREEMENT Recorded Jun 25, 2025
From: SAILPOINT TECHNOLOGIES, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071724/0511 →
SECURITY INTEREST Recorded Aug 17, 2022
From: SAILPOINT TECHNOLOGIES, INC.
To: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 061202/0540 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 14, 2020
From: BADAWY, MOHAMED M.; HO, JOSTINE FEI; KABRA, RAJAT
To: SAILPOINT TECHNOLOGIES, INC.
Reel/Frame 053502/0795 →
Cited By (58)
US 50,632 US 12,196,437 US 12,197,299 US 12,197,508 US 12,210,324 US 12,229,156 US 12,231,255 US 12,231,496 US 12,235,617 US 12,242,600 US 12,270,560 US 12,271,163 US 12,273,215 US 12,292,720 US 12,333,657 US 12,339,825 US 12,341,624 US 12,346,381 US 12,349,027 US 12,367,443 US 12,372,955 US 12,379,718 US 12,386,827 US 12,393,611 US 12,395,818 US 12,399,467 US 12,399,475 US 12,400,035 US 12,401,580 US 12,405,581 US 12,406,193 US 12,412,003 US 12,432,277 US 12,474,679 US 12,481,259 US 12,482,014 US 12,523,975 US 12,523,999 US 12,529,491 US 12,541,182 US 12,542,830 US 12,554,687 US 12,556,893 US 12,572,267 US 12,572,953 US 12,578,696 US 12,579,874 US 12,597,772 US 12,598,207 US 12,664,444 US 12,669,790 US 12,687,827 US 12,687,831 US 12,688,437 US 12,699,367 US 12,699,732 US 12,711,287 US 12,711,288