IP Library Granted Patent US 11,516,203
Granted Patent B2
US 11,516,203 · App. 16/942,416 · Granted Nov 29, 2022

System and method for identity management of cloud based computing services in identity management artificial intelligence systems

Inventors: Brian Eric Rose (Austin, TX); Nicholas Ryan Wellinghoff (Austin, TX)
Assignee: SailPoint Technologies, Inc.
H04L63/0815H04L63/102H04L63/20H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,516,203
App. No.
16/942,416
Granted
Nov 29, 2022
Kind
B2
Abstract

Systems and methods for embodiments of artificial intelligence systems for identity management are disclosed. Specifically, embodiments of an identity management system may provide identity management in association with cloud services used by an enterprise and, in particular, may provide identity management in association with cloud based services that may be accessed through federated access providers.

Claims (53)

1. An identity management system for identify management of cloud based computing services in a distributed network computer environment, comprising:

a hardware processor;

a non-transitory, computer-readable storage medium, including computer instructions executable by the hardware processor for:

obtaining identity management data from one or more source systems associated with a distributed enterprise computing environment, the identity management data comprising data on a set of identity management artifacts utilized in identity management for the distributed enterprise computing environment, wherein the source systems include a federated access provider and a cloud service provider;

determining a set of identities and a set of entitlements associated with the set of identities from the identity management data, including:

determining, from the identity management data, an identity and Access Management (IAM) entity entitlement representing a first access right associated with an IAM entity of the cloud service provider, the IAM entity associated with an enterprise of the distributed enterprise computing environment, and

determining, from the identity management data, a cloud access entitlement associated with the federated access provider, wherein the cloud access entitlement represents a second access right associated with the IAM entity of the cloud service provider, the second access right provided through the federated access provider to enable a user of the enterprise to access the cloud service provider;

obtaining a synthetic role definition comprising a mapping between the IAM entity entitlement and the cloud access entitlement;

creating a synthetic role at the identity management system based on the received synthetic role definition, wherein the created synthetic role associates the IAM entity entitlement and the cloud access entitlement;

assigning the created synthetic role to a first identity and interacting with the federated service provider of the enterprise to provision a native account at the federated service provider associated with the first identity;

obtaining an event log from the cloud service provider, wherein the event log includes events associated with the IAM entity of the cloud service provider;

determining one or more events of the event log associated with the first identity; and

associating the one or more events with the first identity associated with the native account based on the IAM entity entitlement representing the first access right for the IAM entity.

2. The system of claim 1 , wherein the instructions are further for causing a native account at the federated service provider associated with the first identity to be provisioned with the cloud access entitlement based on the assignment of the synthetic role to the first identity.

3. The system of claim 1 , wherein the synthetic role definition is created by a user.

4. The system of claim 1 , wherein the IAM entity is an IAM role, an IAM user, or an IAM group.

5. The system of claim 1 , wherein the synthetic role is assigned to the first identity based on access request submitted by a user.

6. The system of claim 1 , wherein each of the one or more events comprises a unique identifier associated with the first identity.

7. The system of claim 6 , wherein the unique identifier was passed in a Security Assertion Markup Language (SAML) claim between the federated access provider and the cloud service provider when the IAM entity was accessed through the federated service provider.

8. A method for identity management of cloud based computing services in a distributed network computer environment, comprising:

obtaining identity management data from one or more source systems associated with a distributed enterprise computing environment, the identity management data comprising data on a set of identity management artifacts utilized in identity management for the distributed enterprise computing environment, wherein the source systems include a federated access provider and a cloud service provider;

determining a set of identities and a set of entitlements associated with the set of identities from the identity management data, including:

determining, from the identity management data, an identity and Access Management (IAM) entity entitlement representing a first access right associated with an IAM entity of the cloud service provider, the IAM entity associated with an enterprise of the distributed enterprise computing environment, and

determining, from the identity management data, a cloud access entitlement associated with the federated access provider, wherein the cloud access entitlement represents a second access right associated with the IAM entity of the cloud service provider, the second access right provided through the federated access provider to enable a user of the enterprise to access the cloud service provider;

obtaining a synthetic role definition comprising a mapping between the IAM entity entitlement and the cloud access entitlement;

creating a synthetic role at the identity management system based on the received synthetic role definition, wherein the created synthetic role associates the IAM entity entitlement and the cloud access entitlement;

assigning the created synthetic role to a first identity and interacting with the federated service provider of the enterprise to provision a native account at the federated service provider associated with the first identity;

obtaining an event log from the cloud service provider, wherein the event log includes events associated with the IAM entity of the cloud service provider;

determining one or more events of the event log associated with the first identity; and

associating the one or more events with the first identity associated with the native account based on the IAM entity entitlement representing the first access right for the IAM entity.

9. The method of claim 8 , further comprising causing a native account at the federated service provider associated with the first identity to be provisioned with the cloud access entitlement based on the assignment of the synthetic role to the first identity.

10. The method of claim 8 , wherein the synthetic role definition is created by a user.

11. The method of claim 8 , wherein the IAM entity is an IAM role, an IAM user, or an IAM group.

12. The method of claim 8 , wherein the synthetic role is assigned to the first identity based on access request submitted by a user.

13. The method of claim 8 , wherein each of the one or more events comprises a unique identifier associated with the first identity.

14. The method of claim 13 , wherein the unique identifier was passed in a Security Assertion Markup Language (SAML) claim between the federated access provider and the cloud service provider when the IAM entity was accessed through the federated service provider.

15. A non-transitory computer readable storage medium having instructions stored thereon for identity management of cloud based computing services in a distributed network computer environment the instructions executable by a hardware processor to perform the steps of:

obtaining identity management data from one or more source systems associated with a distributed enterprise computing environment, the identity management data comprising data on a set of identity management artifacts utilized in identity management for the distributed enterprise computing environment, wherein the source systems include a federated access provider and a cloud service provider;

determining a set of identities and a set of entitlements associated with the set of identities from the identity management data, including:

determining, from the identity management data, an Identity and Access Management (IAM) entity entitlement representing a first access right associated with an IAM entity of the cloud service provider, the IAM entity associated with an enterprise of the distributed enterprise computing environment, and

determining, from the identity management data, a cloud access entitlement associated with the federated access provider, wherein the cloud access entitlement represents a second access right associated with the IAM entity of the cloud service provider, the second access right provided through the federated access provider to enable a user of the enterprise to access the cloud service provider;

obtaining a synthetic role definition comprising a mapping between the IAM entity entitlement and the cloud access entitlement;

creating a synthetic role at the identity management system based on the received synthetic role definition, wherein the created synthetic role associates the IAM entity entitlement and the cloud access entitlement;

assigning the created synthetic role to a first identity and interacting with the federated service provider of the enterprise to provision a native account at the federated service provider associated with the first identity;

obtaining an event log from the cloud service provider, wherein the event log includes events associated with the IAM entity of the cloud service provider;

determining one or more events of the event log associated with the first identity; and

associating the one or more events with the first identity associated with the native account based on the IAM entity entitlement representing the first access right for the IAM entity.

16. The non-transitory computer readable medium of claim 15 , wherein the instructions are further for causing a native account at the federated service provider associated with the first identity to be provisioned with the cloud access entitlement based on the assignment of the synthetic role to the first identity.

17. The non-transitory computer readable medium of claim 15 , wherein the synthetic role definition is created by a user.

18. The non-transitory computer readable medium of claim 15 , wherein the IAM entity is an IAM role, an IAM user, or an IAM group.

19. The non-transitory computer readable medium of claim 15 , wherein the synthetic role is assigned to the first identity based on access request submitted by a user.

20. The non-transitory computer readable medium of claim 15 , wherein each of the one or more events comprises a unique identifier associated with the first identity.

21. The non-transitory computer readable medium of claim 20 , wherein the unique identifier was passed in a Security Assertion Markup Language (SAML) claim between the federated access provider and the cloud service provider when the IAM entity was accessed through the federated service provider.

Assignments (5)
RELEASE OF SECURITY INTEREST Recorded Jun 27, 2025
From: GOLUB CAPITAL MARKETS LLC
To: SAILPOINT TECHNOLOGIES, INC.; SAILPOINT TECHNOLOGIES HOLDINGS, INC.
Reel/Frame 071776/0411 →
PATENT SECURITY AGREEMENT Recorded Jun 25, 2025
From: SAILPOINT TECHNOLOGIES, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071724/0511 →
SECURITY INTEREST Recorded Aug 17, 2022
From: SAILPOINT TECHNOLOGIES, INC.
To: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 061202/0540 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 22, 2020
From: WELLINGHOFF, NICHOLAS
To: SAILPOINT TECHNOLOGIES, INC.
Reel/Frame 054137/0682 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 22, 2020
From: ROSE, BRIAN ERIC
To: SAILPOINT TECHNOLOGIES, INC.
Reel/Frame 054137/0692 →
Continuity (3)
Continuation 16858026 · Apr 24, 2020
Provisional Application 62840469 · Apr 30, 2019
Related Publication 20200358756A1 · Nov 12, 2020
Cited By (1)
US 12,598,188