IP Library Granted Patent US 12,032,664
Granted Patent B2
US 12,032,664 · App. 17/698,178 · Granted Jul 9, 2024

Systems and methods for network security using identity management data

Inventors: Matthew Lee Domsch (Austin, TX); Rohit Gupta (Pittsford, NY)
Assignee: SAILPOINT TECHNOLOGIES, INC.
G06F21/31G06F21/6218G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,032,664
App. No.
17/698,178
Granted
Jul 9, 2024
Kind
B2
Abstract

Systems and methods for embodiments of artificial intelligence systems for identity management are disclosed. Embodiments of the identity management systems disclosed herein may support the correlation of identities determined authoritative source systems with uncorrelated accounts within an enterprise using artificial intelligence techniques.

Claims (56)

1. A network security system, comprising:

a processor;

a non-transitory, computer-readable storage medium, including computer instructions for:

obtaining identity management data associated with a source system in an enterprise computing environment, the identity management data comprising account data on accounts of the source system and identity data on identities of the enterprise computing environment;

determining uncorrelated accounts of the accounts from the source system and correlated accounts from the accounts from the source system, wherein each of the correlated accounts is associated with an identity of the identities from the source system;

determining a similarity measure based on an uncorrelated account of the set of uncorrelated accounts and the set of correlated accounts;

clustering the accounts to determine account clusters, the clustering based on the similarity measure based on the uncorrelated account and the set of correlated accounts, wherein an account cluster of the account clusters comprises the uncorrelated account and one or more correlated accounts;

managing network security of the distributed enterprise computing environment by:

for the uncorrelated account of the uncorrelated accounts, determining the account cluster including the uncorrelated account;

determining a peer correlated account in the account cluster, wherein the peer correlated account is one of the correlated accounts included in the account cluster;

determining a crowdsourcing target based on the peer correlated account, wherein the crowdsourcing target is a first identity associated with the peer correlated account;

sending a crowdsourcing communication associated with the uncorrelated account to the crowdsourcing target;

determining a response to the crowdsourcing communication associated with the uncorrelated account; and

managing network security of the enterprise computing environment by managing access of the uncorrelated account within the enterprise computing environment based on the response.

2. The system of claim 1 , wherein determining a crowdsourcing target comprises: determining a second identity that is correlated with the peer correlated accounts and determining that the first identity that is related to the second identity.

3. The system of claim 2 , wherein determining that the first identity that is related to the second identity is based on the identity management data.

4. The system of claim 1 , wherein the first identity is associated with the source system associated with the peer correlated account.

5. The system of claim 1 , wherein the source system includes a non-authoritative source system and an authoritative source system.

6. The system of claim 5 , wherein the uncorrelated accounts are from the non-authoritative source system and the correlated are from the non-authoritative source systems, wherein each of the set of correlated accounts is associated with at least one of the identities from the authoritative source system.

7. The system of claim 1 , wherein the similarity measure is determined between each uncorrelated account and each of the set of correlated accounts.

8. A method, comprising:

obtaining identity management data associated with a source system in an enterprise computing environment, the identity management data comprising account data on accounts of the source system and identity data on identities of the enterprise computing environment;

determining uncorrelated accounts of the accounts from the source system and correlated accounts from the accounts from the source system, wherein each of the correlated accounts is associated with an identity of the identities from the source system;

determining a similarity measure based on an uncorrelated account of the set of uncorrelated accounts and the set of correlated accounts;

clustering the accounts to determine account clusters, the clustering based on the similarity measure based on the uncorrelated account and the set of correlated accounts, wherein an account cluster of the account clusters comprises the uncorrelated account and one or more correlated accounts;

managing network security of the distributed enterprise computing environment by:

for the uncorrelated account of the uncorrelated accounts, determining the account cluster including the uncorrelated account;

determining a peer correlated account in the account cluster, wherein the peer correlated account is one of the correlated accounts included in the account cluster;

determining a crowdsourcing target based on the peer correlated account, wherein the crowdsourcing target is a first identity associated with the peer correlated account;

sending a crowdsourcing communication associated with the uncorrelated account to the crowdsourcing target;

determining a response to the crowdsourcing communication associated with the uncorrelated account; and

managing network security of the enterprise computing environment by managing access of the uncorrelated account within the enterprise computing environment based on the response.

9. The method of claim 8 , wherein determining a crowdsourcing target comprises: determining a second identity that is correlated with the peer correlated accounts and determining that the first identity that is related to the second identity.

10. The method of claim 9 , wherein determining that the first identity that is related to the second identity is based on the identity management data.

11. The method of claim 8 , wherein the first identity is associated with the source system associated with the peer correlated account.

12. The method of claim 8 , wherein the source system includes a non-authoritative source system and an authoritative source system.

13. The method of claim 12 , wherein the uncorrelated accounts are from the non-authoritative source system and the correlated are from the non-authoritative source systems, wherein each of the set of correlated accounts is associated with at least one of the identities from the authoritative source system.

14. The method of claim 8 , wherein the similarity measure is determined between each uncorrelated account and each of the set of correlated accounts.

15. A non-transitory computer readable medium, comprising instructions for:

obtaining identity management data associated with a source system in an enterprise computing environment, the identity management data comprising account data on accounts of the source system and identity data on identities of the enterprise computing environment;

determining uncorrelated accounts of the accounts from the source system and correlated accounts from the accounts from the source system, wherein each of the correlated accounts is associated with an identity of the identities from the source system;

determining a similarity measure based on an uncorrelated account of the set of uncorrelated accounts and the set of correlated accounts;

clustering the accounts to determine account clusters, the clustering based on the similarity measure based on the uncorrelated account and the set of correlated accounts, wherein an account cluster of the account clusters comprises the uncorrelated account and one or more correlated accounts;

managing network security of the distributed enterprise computing environment by:

for the uncorrelated account of the uncorrelated accounts, determining the account cluster including the uncorrelated account;

determining a peer correlated account in the account cluster, wherein the peer correlated account is one of the correlated accounts included in the account cluster;

determining a crowdsourcing target based on the peer correlated account, wherein the crowdsourcing target is a first identity associated with the peer correlated account;

sending a crowdsourcing communication associated with the uncorrelated account to the crowdsourcing target;

determining a response to the crowdsourcing communication associated with the uncorrelated account; and

managing network security of the enterprise computing environment by managing access of the uncorrelated account within the enterprise computing environment based on the response.

16. The non-transitory computer readable medium of claim 15 , wherein determining a crowdsourcing target comprises: determining a second identity that is correlated with the peer correlated accounts and determining that the first identity that is related to the second identity.

17. The non-transitory computer readable medium of claim 16 , wherein determining that the first identity that is related to the second identity is based on the identity management data.

18. The non-transitory computer readable medium of claim 15 , wherein the first identity is associated with the source system associated with the peer correlated account.

19. The non-transitory computer readable medium of claim 15 , wherein the source system includes a non-authoritative source system and an authoritative source system.

20. The non-transitory computer readable medium of claim 19 , wherein the uncorrelated accounts are from the non-authoritative source system and the correlated are from the non-authoritative source systems, wherein each of the set of correlated accounts is associated with at least one of the identities from the authoritative source system.

21. The non-transitory computer readable medium of claim 15 , wherein the similarity measure is determined between each uncorrelated account and each of the set of correlated accounts.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded Jun 27, 2025
From: GOLUB CAPITAL MARKETS LLC
To: SAILPOINT TECHNOLOGIES, INC.; SAILPOINT TECHNOLOGIES HOLDINGS, INC.
Reel/Frame 071776/0411 →
PATENT SECURITY AGREEMENT Recorded Jun 25, 2025
From: SAILPOINT TECHNOLOGIES, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071724/0511 →
SECURITY INTEREST Recorded Aug 17, 2022
From: SAILPOINT TECHNOLOGIES, INC.
To: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 061202/0540 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 22, 2022
From: DOMSCH, MATTHEW LEE; GUPTA, ROHIT
To: SAILPOINT TECHNOLOGIES, INC.
Reel/Frame 059340/0545 →
Continuity (2)
Continuation 17206424 · Mar 19, 2021
Related Publication 20220300586A1 · Sep 22, 2022
Cited By (1)
US 12,254,422