IP Library Granted Patent US 12,301,554
Granted Patent B2
US 12,301,554 · App. 17/821,598 · Granted May 13, 2025

Identity access management system and method

Inventors: Sylvan H. Morley, III (Thornton, CO); Jamie Lin (St. Louis, MO); Michael Benjamin (Broomfield, CO); John Knies (Evansville, IN)
Assignee: Level 3 Communications, LLC
H04L63/0807H04L63/102H04L63/105H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,301,554
App. No.
17/821,598
Granted
May 13, 2025
Kind
B2
Abstract

Authorization for a user may be dynamically tailored per application or per application function, rather than globally managed by an administrator. For example, in some embodiments, an identity access management system may generate a suitable authorization token (or authorization token information) to enable a user to login to an application or perform a particular function. The authorization token may be dynamically generated and tailored based on filtering various identity information otherwise available from an identity system, access boundaries of applicable application functions, or other factors.

Claims (64)

1. A method, comprising:

receiving an identity token for a user;

receiving user attributes associated with the identity token;

filtering the user attributes according to an application profile of an application to identify a user attribute set, wherein the user attribute set is a subset of the user attributes;

generating an application specific user profile including the user attribute set;

identifying an authorization policy associated with the application;

identifying an authorization tier associated with the user attribute set in the application specific user profile;

determining whether the application specific user profile is sufficient to satisfy the authorization policy, wherein determining whether the application specific user profile is sufficient to satisfy the authorization policy comprises comparing the application policy to the authorization tier;

generating, when the application specific user profile is sufficient to satisfy the authorization policy, an authorization token; and

providing the authorization token.

2. The method of claim 1 , further comprising:

querying a master data management store according to identity information of the user included in the identity token to retrieve the user attributes.

3. The method of claim 2 , wherein the user attributes of the user attribute set have one or more user attribute types, and wherein generating the application specific user profile comprises mapping the one or more user attribute types to the authorization policy.

4. The method of claim 1 ,

receiving the identity token for the user a second time;

receiving user attributes associated with the identity token;

filtering the user attributes according to a second application profile of a second application to identify a second user attribute set, wherein the second user attribute set is a second subset of the user attributes;

generating a second application specific user profile including the second user attribute set;

identifying a second authorization policy associated with the second application;

determining whether the second application specific user profile is sufficient to satisfy the second authorization policy;

generating, when the second application specific user profile is sufficient to satisfy the second authorization policy, a second authorization token; and

providing the second authorization token.

5. The method of claim 1 , wherein the application profile is specific to a first function of multiple functions of the application, the method further comprising:

receiving the identity token for the user a second time;

receiving user attributes associated with the identity token;

filtering the user attributes according to a second application profile of the application to identify a second user attribute set, wherein the second application profile is specific to a second function of the multiple functions of the application and the second user attribute set is a second subset of the user attributes;

generating a second application specific user profile including the second user attribute set;

identifying a second authorization policy associated with the application;

determining whether the second application specific user profile is sufficient to satisfy the second authorization policy;

generating, when the second application specific user profile is sufficient to satisfy the second authorization policy, a second authorization token; and

providing the second authorization token.

6. A system, comprising:

at least one processor; and

memory, operatively connected to the at least one processor and storing instructions that, when executed by the at least one processor, cause the system to perform a method, the method comprising:

receiving an identity token for a user;

receiving user attributes associated with the identity token;

filtering the user attributes according to an application profile of an application to identify a user attribute set, wherein the user attribute set is a subset of the user attributes;

generating an application specific user profile including the user attribute set;

identifying an authorization policy associated with the application;

identifying an authorization tier associated with the user attribute set in the application specific user profile;

determining whether the application specific user profile is sufficient to satisfy the authorization policy, wherein determining whether the application specific user profile is sufficient to satisfy the authorization policy comprises comparing the application policy to the authorization tier;

generating, when the application specific user profile is sufficient to satisfy the authorization policy, an authorization token; and

providing the authorization token.

7. The system of claim 6 , wherein the method further comprises:

querying a master data management store according to identity information of the user included in the identity token to retrieve the user attributes.

8. The system of claim 7 , wherein the user attributes of the user attribute set have one or more user attribute types, and wherein generating the application specific user profile comprises mapping the one or more user attribute types to the authorization policy.

9. The system of claim 6 , wherein the method further comprises:

receiving the identity token for the user a second time;

receiving user attributes associated with the identity token;

filtering the user attributes according to a second application profile of a second application to identify a second user attribute set, wherein the second user attribute set is a second subset of the user attributes;

generating a second application specific user profile including the second user attribute set;

identifying a second authorization policy associated with the second application;

determining whether the second application specific user profile is sufficient to satisfy the second authorization policy;

generating, when the second application specific user profile is sufficient to satisfy the second authorization policy, a second authorization token; and

providing the second authorization token.

10. The system of claim 6 , wherein the application profile is specific to a particular function of multiple functions of the application, the method further comprising:

receiving the identity token for the user a second time;

receiving user attributes associated with the identity token;

filtering the user attributes according to a second application profile of the application to identify a second user attribute set, wherein the second application profile is specific to a second function of the multiple functions of the application and the second user attribute set is a second subset of the user attributes;

generating a second application specific user profile including the second user attribute set;

identifying a second authorization policy associated with the application;

determining whether the second application specific user profile is sufficient to satisfy the second authorization policy;

generating, when the second application specific user profile is sufficient to satisfy the second authorization policy, a second authorization token; and

providing the second authorization token.

Assignments (3)
NOTICE OF GRANT OF SECURITY INTEREST IN INTELLECTUAL PROPERTY (SECOND LIEN) Recorded Nov 4, 2024
From: LEVEL 3 COMMUNICATIONS, LLC; GLOBAL CROSSING TELECOMMUNICATIONS, INC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 069295/0749 →
NOTICE OF GRANT OF SECURITY INTEREST IN INTELLECTUAL PROPERTY (FIRST LIEN) Recorded Nov 4, 2024
From: LEVEL 3 COMMUNICATIONS, LLC; GLOBAL CROSSING TELECOMMUNICATIONS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 069295/0858 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 15, 2022
From: MORLEY, SYLVAN H., III; LIN, JAMIE; BENJAMIN, MICHAEL; KNIES, JOHN
To: LEVEL 3 COMMUNICATIONS, LLC
Reel/Frame 061104/0648 →
Continuity (2)
Provisional Application 63241423 · Sep 7, 2021
Related Publication 20230075296A1 · Mar 9, 2023
References Cited (6)
US 8793509B1 · Nelson · 2014 [cited by examiner]
US 20150237074A1 · Mardikar · 2015 [cited by examiner]
US 20190327224A1 · Zhang · 2019 [cited by examiner]
US 20200145421A1 · Tin · 2020 [cited by examiner]
US 20220309177A1 · Mikhailov · 2022 [cited by examiner]
Sutterer, M., Droegehorn, O., & David, K. (Apr. 2007). User profile management on service platforms for ubiquitous computing environments. In 2007 IEEE 65th Vehicular Technology Conference—VTC2007—Spring (pp. 287-291). … [cited by examiner]