IP Library Granted Patent US 12,041,046
Granted Patent B2
US 12,041,046 · App. 17/944,319 · Granted Jul 16, 2024

System and method for identity management of cloud based computing services in identity management artificial intelligence systems

Inventors: Brian Eric Rose (Austin, TX); Nicholas Ryan Wellinghoff (Austin, TX)
Assignee: SAILPOINT TECHNOLOGIES, INC.
H04L63/0815H04L63/102H04L63/20H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,041,046
App. No.
17/944,319
Granted
Jul 16, 2024
Kind
B2
Abstract

Systems and methods for embodiments of artificial intelligence systems for identity management are disclosed. Specifically, embodiments of an identity management system may provide identity management in association with cloud services used by an enterprise and, in particular, may provide identity management in association with cloud based services that may be accessed through federated access providers.

Claims (53)

1. An identity management system for identity management of cloud based computing services, comprising:

a processor device; and

a non-transitory, computer-readable storage medium, including computer instructions for:

providing an interface to obtain synthetic role information from a user;

determining a synthetic role definition based on the obtained synthetic role information, the synthetic role definition comprising a mapping between an Identity and Access Management (IAM) entity entitlement and a cloud access interface entitlement;

obtaining identity management data from one or more source systems, the identity management data comprising data on a set of identity management artifacts utilized in identity management for a distributed enterprise computing environment, wherein the source systems include a federated access provider and a cloud service provider;

determining, from the identity management data, the IAM entity entitlement representing a first access right associated with an IAM entity of the cloud service provider, the IAM entity associated with the enterprise;

determining, from the identity management data, the cloud access entitlement associated with the federated access provider, wherein the cloud access entitlement represents a second access right associated with the IAM entity of the cloud service provider, the second access right provided through the federated access provider;

generating a synthetic role at the identity management system based on the determined synthetic role definition, wherein the generated synthetic role associates the IAM entity entitlement and the cloud access entitlement;

assigning the generated synthetic role to a first identity and provisioning a native account of the first identity at the federated access provider;

obtaining an event log from the cloud service provider, wherein the event log includes events associated with the IAM entity of the cloud service provider;

determining one or more events of the event log associated with the first identity; and

associating the one or more events with the first identity based on the IAM entity entitlement representing the first access right for the IAM entity.

2. The system of claim 1 , wherein the interface is configured to present one or more artifacts associated with the cloud service provider to the user and to receive one or more selections from the user of one or more artifacts associated with the cloud service provider to be mapped to user selected artifacts associated with the federated access provider.

3. The system of claim 1 , wherein the interface is configured to receive input from the user to initialize searching by federated access artifacts, and to present, to the user, search results including one or more identity management artifacts associated with the federated access provider.

4. The system of claim 1 , wherein the interface is configured to obtain, from the user, a name for the synthetic role definition.

5. The system of claim 1 , wherein the synthetic role is defined as a role according to a model of the identity management system.

6. The system of claim 1 , wherein the instructions are further for initiating access to the federated access provider within the enterprise to configure the federated access provider to provide access to the user of one or more entitlements, in response to the user authenticating with the federated access provider.

7. The system of claim 1 , wherein the instructions are further for assigning the synthetic role to a first identity based on an access request submitted by the user for the synthetic role.

8. A method for identity management of cloud based computing services, comprising:

providing an interface to obtain synthetic role information from a user;

determining a synthetic role definition based on the obtained synthetic role information, the synthetic role definition comprising a mapping between an Identity and Access Management (IAM) entity entitlement and a cloud access interface entitlement;

obtaining identity management data from one or more source systems, the identity management data comprising data on a set of identity management artifacts utilized in identity management for a distributed enterprise computing environment, wherein the source systems include a federated access provider and a cloud service provider;

determining, from the identity management data, the IAM entity entitlement representing a first access right associated with an IAM entity of the cloud service provider, the IAM entity associated with the enterprise;

determining, from the identity management data, the cloud access entitlement associated with the federated access provider, wherein the cloud access entitlement represents a second access right associated with the IAM entity of the cloud service provider, the second access right provided through the federated access provider;

generating a synthetic role at the identity management system based on the determined synthetic role definition, wherein the generated synthetic role associates the IAM entity entitlement and the cloud access entitlement;

assigning the generated role to a first identity and provisioning a native account of the first identity at the federated access provider;

obtaining an event log from the cloud service provider, wherein the event log includes events associated with the IAM entity of the cloud service provider;

determining one or more events of the event log associated with the first identity; and

associating the one or more events with the first identity based on the IAM entity entitlement representing the first access right for the IAM entity.

9. The method of claim 8 , wherein the interface is configured to present one or more artifacts associated with the cloud service provider to the user and to receive one or more selections from the user of one or more artifacts associated with the cloud service provider to be mapped to user selected artifacts associated with the federated access provider.

10. The method of claim 8 , wherein the interface is configured to receive input from the user to initialize searching by federated access artifacts, and to present, to the user, search results including one or more identity management artifacts associated with the federated access provider.

11. The method of claim 8 , wherein the interface is configured to obtain, from the user, a name for the synthetic role definition.

12. The method of claim 8 , wherein the synthetic role is defined as a role according to a model of the identity management system.

13. The method of claim 8 , further comprising initiating access to the federated access provider within the enterprise to configure the federated access provider to provide access to the user of one or more entitlements, in response to the user authenticating with the federated access provider.

14. The method of claim 8 , further comprising assigning the synthetic role to a first identity based on an access request submitted by the user for the synthetic role.

15. A non-transitory computer readable storage medium, comprising instructions when executed for identity management of cloud based computing services to perform the steps of:

providing an interface to obtain synthetic role information from a user;

determining a synthetic role definition based on the obtained synthetic role information, the synthetic role definition comprising a mapping between an Identity and Access Management (IAM) entity entitlement and a cloud access interface entitlement;

obtaining identity management data from one or more source systems, the identity management data comprising data on a set of identity management artifacts utilized in identity management for a distributed enterprise computing environment, wherein the source systems include a federated access provider and a cloud service provider;

determining, from the identity management data, the IAM entity entitlement representing a first access right associated with an IAM entity of the cloud service provider, the IAM entity associated with the enterprise;

determining, from the identity management data, the cloud access entitlement associated with the federated access provider, wherein the cloud access entitlement represents a second access right associated with the IAM entity of the cloud service provider, the second access right provided through the federated access provider;

generating a synthetic role at the identity management system based on the determined synthetic role definition, wherein the generated synthetic role associates the IAM entity entitlement and the cloud access entitlement;

assigning the generated synthetic role to a first identity and provisioning a native account of the first identity at the federated access provider;

obtaining an event log from the cloud service provider, wherein the event log includes events associated with the IAM entity of the cloud service provider;

determining one or more events of the event log associated with the first identity; and

associating the one or more events with the first identity based on the IAM entity entitlement representing the first access right for the IAM entity.

16. The non-transitory computer readable medium of claim 15 , wherein the interface is configured to present one or more artifacts associated with the cloud service provider to the user and to receive one or more selections from the user of one or more artifacts associated with the cloud service provider to be mapped to user selected artifacts associated with the federated access provider.

17. The non-transitory computer readable medium of claim 15 , wherein the interface is configured to receive input from the user to initialize searching by federated access artifacts, and to present, to the user, search results including one or more identity management artifacts associated with the federated access provider.

18. The non-transitory computer readable medium of claim 15 , wherein the interface is configured to obtain, from the user, a name for the synthetic role definition.

19. The non-transitory computer readable medium of claim 15 , wherein the synthetic role is defined as a role according to a model of the identity management system.

20. The non-transitory computer readable medium of claim 15 , wherein the instructions are further for initiating access to the federated access provider within the enterprise to configure the federated access provider to provide access to the user of one or more entitlements, in response to the user authenticating with the federated access provider.

21. The non-transitory computer readable medium of claim 15 , wherein the instructions are further for assigning the synthetic role to a first identity based on an access request submitted by the user for the synthetic role.

Assignments (3)
PATENT SECURITY AGREEMENT Recorded Jun 25, 2025
From: SAILPOINT TECHNOLOGIES, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071724/0511 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 19, 2022
From: ROSE, BRIAN ERIC
To: SAILPOINT TECHNOLOGIES, INC.
Reel/Frame 061140/0861 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 19, 2022
From: WELLINGHOFF, NICHOLAS RYAN
To: SAILPOINT TECHNOLOGIES, INC.
Reel/Frame 061140/0890 →
Continuity (4)
Continuation 16942416 · Jul 29, 2020
Continuation 16858026 · Apr 24, 2020
Provisional Application 62840469 · Apr 30, 2019
Related Publication 20230021041A1 · Jan 19, 2023
Cited By (1)
US 12,598,188