IP Library Granted Patent US 12,326,948
Granted Patent B2
US 12,326,948 · App. 17/506,516 · Granted Jun 10, 2025

Identity time machine

Inventors: Sudhakar Peddibhotla (San Francisco, CA); Sandesh More (San Francisco, CA); Peter Barker (Austin, TX)
Assignee: Ping Identity International, Inc.
G06F21/6218G06F16/219G06F2221/2101G06F2221/2141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,326,948
App. No.
17/506,516
Granted
Jun 10, 2025
Kind
B2
Abstract

The disclosed technology teaches a computer-implemented method of enabling identity governance administration to examine the state of identity management objects at an arbitrary prior time. The method includes maintaining a data store of identity management objects used for identity governance administration, including specification of user roles from which permissions or authorizations derive and recording in the data store copies of identity management objects with an as-of time stamp at each creation, change and deletion of each identity management object. Also included is retaining time-stamped versions of the objects for a queryable time window. The method also includes receiving a query with an as-of time criteria for at least some of the identity management objects and returning responsive objects from which the permissions or authorizations were derived at the as-of-time. Responding to the query with the responsive objects that correspond to the as-of time criteria in the query is also disclosed.

Claims (29)

1. A computer-implemented method of enabling identity governance administration to examine state of identity management objects at an arbitrary prior time, including:

maintaining a data store of identity management objects used for identity governance administration that are stored separately from data defining a respective user, account, entitlement, application, or role to which each respective identity management object pertains, including specification of user roles from which permissions or authorizations derive;

recording, in the data store, copies of identity management objects with an as-of time stamp at each creation, change and deletion of each identity management object;

retaining time-stamped versions of the identity management objects for a queryable time window; and

receiving a query with an as-of time criteria with an as-of time for at least some of the identity management objects and returning responsive identity management objects from which the permissions or authorizations were derived at the as-of time.

2. The computer-implemented method of claim 1 , further including responding to the query with the responsive identity management objects that correspond to the as-of time criteria in the query.

3. The computer-implemented method of claim 1 , further including in the data store pre-joined identity management objects, whereby queries over fields in multiple types of identity management objects are accelerated by pre-calculation of a join over the fields.

4. The computer-implemented method of claim 3 , wherein the pre-joined identity management objects include one of user, account, entitlement, application and role.

5. The computer-implemented method of claim 1 , further including joining identity management objects retrieved in response to the query.

6. The computer-implemented method of claim 1 , wherein the recording in the data store utilizes a cloud-based computing service which is one of Google Cloud Platform (abbreviated GCP), Amazon Web Services (abbreviated AWS) or Microsoft Azure Virtual Platform.

7. The computer-implemented method of claim 1 , further including applying analytics to the identity management objects returned.

8. A tangible non-transitory computer readable storage media, including program instructions loaded into memory that, when executed on one or more processors, cause the one or more processors to implement a method of enabling identity governance administration to examine state of identity management objects at an arbitrary prior time, including:

maintaining a data store of identity management objects used for identity governance administration that are stored separately from data defining a respective user, account, entitlement, application, or role to which each respective identity management object pertains, including specification of user roles from which permissions or authorizations derive;

recording, in the data store, copies of identity management objects with an as-of time stamp at each creation, change and deletion of each identity management object;

retaining time-stamped versions of the identity management objects for a queryable time window; and

receiving a query with an as-of time criteria with an as-of time for at least some of the identity management objects and returning responsive identity management objects from which the permissions or authorizations were derived at the as-of time.

9. The tangible non-transitory computer readable storage media of claim 8 , further including responding to the query with the responsive identity management objects that correspond to the as-of time criteria in the query.

10. The tangible non-transitory computer readable storage media of claim 8 , further including in the data store pre-joined identity management objects, whereby queries over fields in multiple types of identity management objects are accelerated by pre-calculation of a join over the fields.

11. The tangible non-transitory computer readable storage media of claim 10 , wherein the pre-joined identity management objects include one of user, account, entitlement, application and role.

12. The tangible non-transitory computer readable storage media of claim 8 , further including joining identity management objects retrieved in response to the query.

13. The tangible non-transitory computer readable storage media of claim 8 , wherein the recording in the data store utilizes a cloud-based computing service which is one of Google Cloud Platform (abbreviated GCP), Amazon Web Services (abbreviated AWS) or Microsoft Azure Virtual Platform.

14. The tangible non-transitory computer readable storage media of claim 8 , further including applying analytics to the identity management objects returned.

15. A system for enabling identity governance administration to examine state of identity management objects at an arbitrary prior time, the system including a processor, memory coupled to the processor and computer instructions from the tangible non-transitory computer readable storage media of claim 8 loaded into the memory.

16. The system of claim 15 , further including responding to the query with the responsive identity management objects that correspond to the as-of time criteria in the query.

17. The system of claim 15 , further including in the data store pre-joined identity management objects, whereby queries over fields in multiple types of identity management objects are accelerated by pre-calculation of a join over the fields.

18. The system of claim 17 , wherein the pre-joined identity management objects include one of user, account, entitlement, application and role.

19. The system of claim 15 , further including joining identity management objects retrieved in response to the query.

20. The system of claim 15 , wherein the recording in the data store utilizes a cloud-based computing service which is one of Google Cloud Platform (abbreviated GCP), Amazon Web Services (abbreviated AWS) or Microsoft Azure Virtual Platform.

21. The system of claim 15 , further including applying analytics to the identity management objects returned.

Assignments (5)
RELEASE OF SECURITY INTEREST AT R/F 65335/0890 Recorded Nov 14, 2025
From: BLUE OWL CAPITAL CORPORATION
To: PING IDENTITY CORPORATION (FORMERLY KNOWN AS FORGEROCK INC.)
Reel/Frame 073564/0791 →
SECURITY INTEREST Recorded Nov 13, 2025
From: PING IDENTITY CORPORATION; PING IDENTITY INTERNATIONAL, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 073557/0093 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 6, 2024
From: FORGEROCK, INC.
To: PING IDENTITY INTERNATIONAL, INC.
Reel/Frame 066358/0483 →
GRANT OF SECURITY INTEREST IN PATENT RIGHTS Recorded Oct 24, 2023
From: FORGEROCK, INC.
To: BLUE OWL CAPITAL CORPORATION (FORMERLY KNOWN AS OWL ROCK CAPITAL CORPORATION), AS COLLATERAL AGENT
Reel/Frame 065335/0890 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 21, 2021
From: PEDDIBHOTLA, SUDHAKAR; MORE, SANDESH; BARKER, PETER
To: FORGEROCK, INC.
Reel/Frame 058451/0978 →
Continuity (1)
Related Publication 20230117846A1 · Apr 20, 2023
References Cited (5)
US 20130124500A1 · Beavin · 2013 [cited by examiner]
US 20160180113A1 · Patton · 2016 [cited by examiner]
US 20180189334A1 · Cong · 2018 [cited by examiner]
US 20210297387A1 · Tobias · 2021 [cited by examiner]
Forgerock, Inc.. Maximize the Value of Your Identity Solution with AI-Driven Identity Analytics, 2020, 10 pgs. [cited by applicant]