IP Library Granted Patent US 10,965,665
Granted Patent B1
US 10,965,665 · App. 17/023,158 · Granted Mar 30, 2021

Passwordless privilege access

Inventors: Ryan Privette (Denver, CO); Kris Keller (Cookeville, TN)
Assignee: SAILPOINT TECHNOLOGIES, INC
H04L63/0815G06F12/0802G06F2212/60
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,965,665
App. No.
17/023,158
Granted
Mar 30, 2021
Kind
B1
Abstract

Systems and methods for network security are provided. Various embodiments of the present technology provide systems and methods for an identity security gateway agent that provides for privileged access. Embodiments include a system and method that uses a single sign-on (SSO) (or similar) mechanism to facilitate a user accessing web-based service providers, but separates the assertion and entire SSO process from the user credential.

Claims (51)

1. A method of providing privilege access to a client to facilitate connections to target network components, the method comprising:

responsive to receiving a request from a user device to access to a target network component, an agent component requesting credentials from an identity provider (IDP);

receiving, by the agent component, user credentials corresponding to the request from the IDP;

generating, by the agent component, abstracted credentials;

providing, by the agent component, the abstracted credentials to the user device;

generating, by the user device, a first request intended for the target network component, the request including the abstracted credentials;

generating, by the agent component, a second request based on the first request by replacing the abstracted credentials with the user credentials;

sending the second request to the target network component;

receiving, by the agent component, a first response from the target network component, the first response including a session identifier, a response header, and a cookie;

generating, by the agent component, a second response based on the first response by replacing the session identifier with an abstracted session identifier, the response header with an abstracted response header, and the cookie with an abstracted cookie; and

sending the second response to the user device.

2. The method of claim 1 , wherein the user device communicates with the agent via a browser extension installed on the user device.

3. The method of claim 1 , wherein the user credentials comprise an SSO token.

4. The method of claim 3 , wherein the abstracted credentials is different from the SSO token.

5. The method of claim 1 , further comprising storing, by the agent component, the user credentials in a non-persistent cache.

6. The method of claim 5 , further comprising flushing the non-persistent cache after sending the second request to the target network component.

7. The method of claim 1 , further comprising wherein the first response is received from the target network component without the target network component requiring a password.

8. A system for providing privilege access to a client to facilitate connections to target network components, the system comprising:

a processor; and

a non-transitory computer readable medium storing instructions translatable by the processor, the instructions when translated by the processor perform:

responsive to receiving a request from a user device to access to a target network component, an agent component requesting credentials from an identity provider (IDP);

receiving, by the agent component, user credentials corresponding to the request from the IDP;

generating, by the agent component, abstracted credentials;

providing, by the agent component, the abstracted credentials to the user device; generating, by the user device, a first request intended for the target network component, the request including the abstracted credentials;

generating, by the agent component, a second request based on the first request by replacing the abstracted credentials with the user credentials;

sending the second request to the target network component;

receiving, by the agent component, a first response from the target network component, the first response including a session identifier, a response header, and a cookie;

generating, by the agent component, a second response based on the first response by replacing the session identifier with an abstracted session identifier, the response header with an abstracted response header, and the cookie with an abstracted cookie; and

sending the second response to the user device.

9. The system of claim 8 , wherein the user device communicates with the agent via a browser extension installed on the user device.

10. The method of claim 8 , wherein the user credentials comprise an SSO token.

11. The method of claim 10 , wherein the abstracted credentials is different from the SSO token.

12. The method of claim 8 , further comprising storing, by the agent component, the user credentials in a non-persistent cache.

13. The method of claim 12 , further comprising flushing the non-persistent cache after sending the second request to the target network component.

14. The method of claim 8 , further comprising wherein the first response is received from the target network component without the target network component requiring a password.

15. A computer program product comprising a non-transitory computer readable medium storing instructions translatable by a processor, the instructions when translated by the processor perform, in an enterprise computing network environment:

responsive to receiving a request from a user device to access to a target network component, an agent component requesting credentials from an identity provider (IDP);

receiving, by the agent component, user credentials corresponding to the request from the IDP;

generating, by the agent component, abstracted credentials;

providing, by the agent component, the abstracted credentials to the user device;

generating, by the user device, a first request intended for the target network component, the request including the abstracted credentials;

generating, by the agent component, a second request based on the first request by replacing the abstracted credentials with the user credentials;

sending the second request to the target network component;

receiving, by the agent component, a first response from the target network component, the first response including a session identifier, a response header, and a cookie;

generating, by the agent component, a second response based on the first response by replacing the session identifier with an abstracted session identifier, the response header with an abstracted response header, and the cookie with an abstracted cookie; and

sending the second response to the user device.

16. The computer program product of claim 15 , wherein the user device communicates with the agent via a browser extension installed on the user device.

17. The computer program product of claim 15 , wherein the user credentials comprise an SSO token.

18. The computer program product of claim 17 , wherein the abstracted credentials is different from the SSO token.

19. The computer program product of claim 15 , further comprising storing, by the agent component, the user credentials in a non-persistent cache.

20. The computer program product of claim 19 , further comprising flushing the non-persistent cache after sending the second request to the target network component.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded Jun 27, 2025
From: GOLUB CAPITAL MARKETS LLC
To: SAILPOINT TECHNOLOGIES, INC.; SAILPOINT TECHNOLOGIES HOLDINGS, INC.
Reel/Frame 071776/0411 →
PATENT SECURITY AGREEMENT Recorded Jun 25, 2025
From: SAILPOINT TECHNOLOGIES, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071724/0511 →
SECURITY INTEREST Recorded Aug 17, 2022
From: SAILPOINT TECHNOLOGIES, INC.
To: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 061202/0540 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 19, 2020
From: PRIVETTE, RYAN; KELLER, KRIS
To: SAILPOINT TECHNOLOGIES, INC.
Reel/Frame 054095/0270 →