IP Library Granted Patent US 12,368,718
Granted Patent B2
US 12,368,718 · App. 17/958,208 · Granted Jul 22, 2025

Runtime configuration of authentication journeys

Inventors: Isaac Taylor (Bristol, GB); Volker Gunnar Scheuber Heinz (Georgetown, TX); Charles Bailey (Bath, GB); Abel Jay Bowers (Bristol, GB); Thomas James Dennis (Bristol, GB); Kajetan Hemzaczek (Bristol, GB)
Assignee: Ping Identity International, Inc.
H04L63/102H04L63/0884H04L63/105
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,368,718
App. No.
17/958,208
Granted
Jul 22, 2025
Kind
B2
Abstract

The disclosed technology teaches a method for customers of an organization to perform configuration at runtime for authentication journeys used by the customer's users, to simplify authentication trees, and to delegate configuration to the customer's administrators, wherein an authentication tree implements an authentication journey, the authentication tree including authentication nodes and edges connecting the authentication nodes. The method includes configuring an editable script and an authentication node used in the authentication tree in response to a user invocation of the authentication journey by executing a factory method that applies configuration parameters to the editable script and to parameters used to access an API.

Claims (35)

1. A computer-implemented method for a customer of an organization to perform configuration at runtime for authentication journeys used by users of the customer, to simplify authentication trees and to delegate configuration to administrators of the customer,

wherein an authentication tree implements an authentication journey, the authentication tree including authentication nodes and edges connecting the authentication nodes,

the computer-implemented method including:

configuring an editable script and an authentication node used in the authentication tree in response to a user invocation of the authentication journey by executing a factory method that applies configuration parameters to the editable script and to parameters used to access an API,

wherein the configuration parameters for the factory method are stored in a parameter data structure that stores a set of connection configurations for authentication nodes, and for the API accessed by at least one of the authentication nodes;

wherein the factory method configures the editable script to switch among alternative connections to authentication nodes in the authentication tree; and

wherein the factory method performs configuration at runtime of at least one parameter used by an authentication node in the authentication tree to access the API.

2. The computer-implemented method of claim 1 , further including applying the configuring to a customer instance of a legacy authentication node that, in a legacy implementation, was manually edited.

3. The computer-implemented method of claim 1 , further including delegating configuration of the parameter data structure to the administrators of the customer and the administrators of the customer configuring a customer instance of a legacy authentication node by modifying data stored in the parameter data structure for use by the factory method.

4. The computer-implemented method of claim 1 , wherein the authentication tree is a legacy workflow or a workflow compatible with legacy workflows.

5. The computer-implemented method of claim 1 , further including receiving edits to the parameters used to access the API from an administrator of the customer and persisting the edits for use in response to the user invocation of the authentication journey.

6. The computer-implemented method of claim 1 , wherein the alternative connections among authentication nodes in the authentication tree represent alternatives of authentication methods, alternative registration, or alternative branding.

7. The computer-implemented method of claim 1 , further including a user of the customer journeying across the authentication tree starting at a root authentication node of the authentication tree and traversing one or more downstream authentication nodes to a terminal authentication node.

8. The computer-implemented method of claim 7 , wherein the authentication tree comprises one or more direct traversals created during execution of the authentication journey and the one or more direct traversals created during execution of the authentication journey represent a nested authentication tree child wrapped by an authentication node parent within the authentication tree.

9. The computer-implemented method of claim 8 , wherein a connection configuration from the set of connection configurations is customized by the user of the customer through configuration data stored in a data model.

10. The computer-implemented method of claim 9 , wherein a designated connection configuration is unique to a nested authentication tree child within the authentication tree, and wherein the designated connection configuration is unique to the customer.

11. The computer-implemented method of claim 10 , wherein the designated connection configuration is loaded into the nested authentication tree child in response to the user invocation of an authentication node parent to the nested authentication tree child.

12. The computer-implemented method of claim 1 , further including a delegated administration structure, wherein the delegated administration structure is associated with a database that supports configuring alternative connections between the authentication nodes and APIs accessed by the authentication nodes in response to a user invocation of the authentication journey.

13. The computer-implemented method of claim 1 , wherein the alternative connections can use or customize a GUI or an API in a library that supports alternative authentication methods and alternative registration journeys.

14. The computer-implemented method of claim 1 , wherein external services provide a cookie, and wherein the authentication node assigns data from the cookie for use in a downstream authentication node.

15. A tangible non-transitory computer readable storage media, including program instructions loaded into memory that, when executed on processors cause the processors to implement a method of performing configuration at runtime for authentication journeys used by users of a customer, to simplify authentication trees and to delegate configuration to administrators of the customer,

wherein an authentication tree implements an authentication journey, the authentication tree including authentication nodes and edges connecting the authentication nodes,

the method including:

configuring an editable script and an authentication node used in the authentication tree in response to a user invocation of the authentication journey by executing a factory method that applies configuration parameters to the editable script and to parameters used to access an API,

wherein the configuration parameters for the factory method are stored in a parameter data structure that stores a set of connection configurations for authentication nodes, and for the API accessed by at least one of the authentication nodes;

wherein the factory method configures the editable script to switch among alternative connections to authentication nodes in the authentication tree; and

wherein the factory method performs configuration at runtime for at least one parameter used by an authentication node in the authentication tree to access the API.

16. The tangible non-transitory computer readable storage media of claim 15 , further including delegating configuration of the parameter data structure to the administrators of the customer and the administrators of the customer configuring a customer instance of a legacy authentication node by modifying data stored in the parameter data structure for use by the factory method.

17. The tangible non-transitory computer readable storage media of claim 15 , wherein the authentication tree is a legacy workflow or a workflow compatible with legacy workflows.

18. The tangible non-transitory computer readable storage media of claim 15 , further including receiving edits to the parameters used to access APIs or GUIs from an administrator of the customer and persisting the edits for use in response to the user invocation of the authentication journey.

19. The tangible non-transitory computer readable storage media of claim 15 , wherein a connection configuration from the set of connection configurations is customized by a user of the customer through configuration data stored in a data model.

20. A system for performing configuration at runtime for authentication journeys used by users of a customer, to simplify authentication trees and to delegate configuration to administrators of the customer, the system including a processor, memory coupled to the processor and program instructions from the tangible non-transitory computer readable storage media of claim 15 loaded into the memory.

21. The system of claim 20 , further including applying the configuring to a customer instance of a legacy authentication node that, in a legacy implementation, was manually edited.

22. The system of claim 20 , further including a delegated administration structure, wherein the delegated administration structure is associated with a database that supports configuring alternative connections between the authentication nodes and APIs accessed by the authentication nodes in response to a user invocation of the authentication journey.

23. The system of claim 20 , wherein the alternative connections among authentication nodes in the authentication tree represent alternatives of authentication methods, alternative registration, or alternative branding.

Assignments (3)
SECURITY INTEREST Recorded Nov 13, 2025
From: PING IDENTITY CORPORATION; PING IDENTITY INTERNATIONAL, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 073557/0093 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 6, 2024
From: FORGEROCK, INC.
To: PING IDENTITY INTERNATIONAL, INC.
Reel/Frame 066358/0483 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 10, 2022
From: TAYLOR, ISAAC; SCHEUBER HEINZ, VOLKER GUNNAR; BAILEY, CHARLES; BOWERS, ABEL JAY; DENNIS, THOMAS JAMES; HEMZACZEK, KAJETAN
To: FORGEROCK, INC.
Reel/Frame 061362/0960 →
Continuity (1)
Related Publication 20240114031A1 · Apr 4, 2024
References Cited (105)
US 6633898B1 · Seguchi et al. · 2003 [cited by applicant]
US 7865931B1 · Stone et al. · 2011 [cited by applicant]
US 8751941B1 · Kaushik et al. · 2014 [cited by applicant]
US 8931055B2 · Shea et al. · 2015 [cited by applicant]
US 8978114B1 · Kaushik et al. · 2015 [cited by applicant]
US 9720750B1 · Abrams et al. · 2017 [cited by applicant]
US 10265694B2 · Aizenberg et al. · 2019 [cited by applicant]
US 10303576B1 · Seymour et al. · 2019 [cited by applicant]
US 10333918B2 · Kruse · 2019 [cited by applicant]
US 10630501B2 · Ansari et al. · 2020 [cited by applicant]
US 10681055B2 · Thexton et al. · 2020 [cited by applicant]
US 10686795B2 · Thexton et al. · 2020 [cited by applicant]
US 10686885B2 · Goyal et al. · 2020 [cited by applicant]
US 10705808B2 · Chiosi et al. · 2020 [cited by applicant]
US 10817346B1 · Culp et al. · 2020 [cited by applicant]
US 10922284B1 · Venkatasubramanian et al. · 2021 [cited by applicant]
US 10938940B2 · Alla · 2021 [cited by applicant]
US 11075791B2 · Prathipati et al. · 2021 [cited by applicant]
US 11347560B2 · Culp et al. · 2022 [cited by applicant]
US 11777992B1 · Cross et al. · 2023 [cited by applicant]
US 20070214497A1 · Montgomery · 2007 [cited by applicant]
US 20100199346A1 · Ling et al. · 2010 [cited by applicant]
US 20130047229A1 · Hoefel · 2013 [cited by applicant]
US 20130212387A1 · Oberheide · 2013 [cited by examiner]
US 20140165193A1 · El-Rafei et al. · 2014 [cited by applicant]
US 20140316797A1 · Biernacki et al. · 2014 [cited by applicant]
US 20150033292A1 · Nguyen et al. · 2015 [cited by applicant]
US 20150067889A1 · Baikalov et al. · 2015 [cited by applicant]
US 20150135305A1 · Cabrera et al. · 2015 [cited by applicant]
US 20150205708A1 · Michelsen · 2015 [cited by applicant]
US 20170093871A1 · Abuelsaad et al. · 2017 [cited by applicant]
US 20170295062A1 · Tang · 2017 [cited by applicant]
US 20180088982A1 · Abrams et al. · 2018 [cited by applicant]
US 20180197128A1 · Carstens et al. · 2018 [cited by applicant]
US 20190356693A1 · Cahana et al. · 2019 [cited by applicant]
US 20190384662A1 · Bonnell · 2019 [cited by applicant]
US 20190391897A1 · Vijendra et al. · 2019 [cited by applicant]
US 20200034254A1 · Natanzon · 2020 [cited by applicant]
US 20200073655A1 · Park et al. · 2020 [cited by applicant]
US 20200136987A1 · Nakfour · 2020 [cited by applicant]
US 20200280517A1 · Kwon et al. · 2020 [cited by applicant]
US 20210004253A1 · Barnes et al. · 2021 [cited by applicant]
US 20210072966A1 · Zong et al. · 2021 [cited by applicant]
US 20210082575A1 · Ji et al. · 2021 [cited by applicant]
US 20210173940A1 · Mylrea et al. · 2021 [cited by applicant]
US 20210400075A1 · Stergioudis et al. · 2021 [cited by applicant]
US 20220030036A1 · Cirelli et al. · 2022 [cited by applicant]
US 20220070201A1 · Almaz et al. · 2022 [cited by applicant]
US 20220191247A1 · Dhoble et al. · 2022 [cited by applicant]
CN 101951375A · 2011 [cited by applicant]
JP H1049443A · 1998 [cited by applicant]
JP 2003162612A · 2003 [cited by applicant]
JP 2003216497A · 2003 [cited by applicant]
JP 2004054732A · 2004 [cited by applicant]
JP 2006073003A · 2006 [cited by applicant]
JP 2012073812A · 2012 [cited by applicant]
JP 2016051460A · 2016 [cited by applicant]
JP 2016181158A · 2016 [cited by applicant]
Behavioral Biometrics for Mobile, BioCatch, 2021, 3 pages (retrieved Dec. 14, 2021 from https://www.biocatch.com/hubfs/New%20Boilerplate/BC%20SB%20Mobile%20Data%20v6%20NBP.pdf). [cited by applicant]
Innovating the Customer Experience Without Opening Fraud Floodgates, BioCatch, 10 pages (retrieved Dec. 14, 2021 from https://www.biocatch.com/hubfs/WP-Innovate-Customer-Experience-Without-Fraud.pdf). [cited by applicant]
Threat Matrix Guide, ID Dataweb, 7 pages (retrieved Dec. 14, 2021 from https://docs.iddataweb.com/docs/threatmetrix-1). [cited by applicant]
Cichonski et al., “Computer Security Incident Handling Guide”, National Institute of Standards and Technology, U.S. Department of Commerce, Special Publication 800-61, Revision 2, http://dx.doi.org/10.6028/NIST.SP.800-6… [cited by applicant]
“Hardening your cluster's security”, Kubernetes Engine, (https://cloud.google.com/kubernetes-engine/docs/concepts/security-overview), Jul. 2019, 10 pages. [cited by applicant]
Dempsey, et al., “Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations”, NIST National Institute of Standards and Technology, U.S. Dept. of Commerce, NIST Special Publicati… [cited by applicant]
“Configuring Vertical Pod Autoscaling”, Kubernetes Engine, Google Cloud (https://cloud.google.com/kubernetes-engine/), Aug. 14, 2019, 8 pages. [cited by applicant]
Wilkin, “Kubernetes Deployment Dependencies”, https://medium.com/google-cloud/kubernetes-deployment-dependencies-ef703e563956, Jul. 2, 2018, 21 pages. [cited by applicant]
“Vertical Pod Autoscaling”, Kubernetes Engine, https://cloud.google.com/kubernetes-engine/docs/concepts/verticalpodautoscaler), Aug. 29, 2019, 8 pages. [cited by applicant]
Sakimura et al, “OpenID Connect Dynamic Client Registration 1.0 incorporating errata set 1”, https://openid.net/specs/openid-connect-registration-1_0.html, Oct. 1, 2019, 19 pages. [cited by applicant]
Jayanandana, “Enable Rolling updates in Kubernetes with Zero downtime”, https://medium.com/platformer-blog/enable-rolling-updates-in-kubernetes-with-zero-downtime-31d7ec.388c81, Sep. 27, 2018, 6 pages. [cited by applicant]
“FAQ: IDM/OpenIDM performance and tuning”, https://backstage.forgerock.com/knowledge/kb/article/a32504603, Jun. 26, 2019, 7 pages. [cited by applicant]
Amazon; AWS Elastic Beanstalk Developer Guide; Aug. 2019; 924 pgs (https://web.archive.org/web/20190805110626/https:// docs.aws.amazon.com/elasticbeanstalk/latest/dg/awseb-dg.pdf). [cited by applicant]
Amazon; AWS Elastic Beanstalk Developer Guide API version Dec. 1, 2012 dated Nov. 14, 2016, 965 pgs. [downloaded Aug. 9, 2023 from https://web.archive.org/web/20161114152137/https://docs.aws.amazon.com/elasticbeanstalk/… [cited by applicant]
AU 2019201186—Examination Report No. 1, dated Oct. 15, 2019, 8 pages. [cited by applicant]
AU 2019201186—Examination Report No. 2, dated May 5, 2020, 4 pages. [cited by applicant]
AU 2019201186—Examination Report No. 3, dated Oct. 6, 2020, 4 pages. [cited by applicant]
JP 2019-027807—Search Report dated Feb. 27, 2020, 63 pages. [cited by applicant]
JP 2019-027807—Notice of Reasons for Refusal dated Mar. 24, 2020, 8 pages. [cited by applicant]
JP 2019-027807—Response to Notice of Reasons for Refusal dated Sep. 24, 2020, 13 pages. [cited by applicant]
JP 2019-027807—Written Opinion dated Sep. 24, 2020, 9 pages. [cited by applicant]
JP 2019-027807—Notice of Reasons for Refusal dated Mar. 9, 2021, 6 pages. [cited by applicant]
JP 2019-027807—Response to Notice of Reasons for Refusal dated Sep. 7, 2021, 13 pages. [cited by applicant]
JP 2019-027807—Written Opinion dated Sep. 7, 2021, 4 pages. [cited by applicant]
JP 2019-027807—Decision to Grant a Patent dated Nov. 2, 2021, 6 pages. [cited by applicant]
JP 2021-194612—Decision to Grant a Patent dated Jan. 10, 2023, 5 pages. [cited by applicant]
AU 2019201186—Response to Examination Report No. 1, dated Apr. 9, 2020, 10 pages. [cited by applicant]
AU 2019201186—Response to Examination Report No. 2, dated Sep. 14, 2020, 8 pages. [cited by applicant]
AU 2020256320—Examination Report No. 1, dated Nov. 8, 2021, 6 pages. [cited by applicant]
AU 2020256320—Response to Examination Report No. 1, dated Jun. 29, 2022, 62 pages. [cited by applicant]
AU 2020256320—Examination Report No. 2, dated Jul. 20, 2022, 4 pages. [cited by applicant]
AU 2022268298—Examination Report No. 1, dated Sep. 12, 2023, 4 pages. [cited by applicant]
“Authentication nodes configuration reference”, ForgeRock Identity Cloud Docs, accessed on May 12, 2022, 133 pages. [cited by applicant]
U.S. Appl. No. 16/579,740, filed Sep. 23, 2019, U.S. Pat. No. 10,817,346, Oct. 27, 2020, Issued. [cited by applicant]
U.S. Appl. No. 17/068,653, filed Oct. 12, 2020, U.S. Pat. No. 11,347,560, May 31, 2022, Issued. [cited by applicant]
U.S. Appl. No. 17/550,916, filed Dec. 14, 2021, U.S. Pat. No. 11,720,410, Aug. 8, 2023, Issued. [cited by applicant]
U.S. Appl. No. 18/231,160, filed Aug. 7, 2023, Abandoned. [cited by applicant]
U.S. Appl. No. 15/900,475, filed Feb. 20, 2018, U.S. Pat. No. 10,708,274, Jul. 7, 2020, Issued. [cited by applicant]
U.S. Appl. No. 16/016,154, filed Jun. 22, 2018, U.S. Pat. No. 10,676,795, Jun. 16, 2020, Issued. [cited by applicant]
U.S. Appl. No. 16/581,087, filed Sep. 24, 2019, U.S. Pat. No. 10,681,055, Jun. 9, 2020, Issued. [cited by applicant]
U.S. Appl. No. 16/906,953, filed Jun. 19, 2020, U.S. Pat. No. 11,128,635, Sep. 21, 2021, Issued. [cited by applicant]
U.S. Appl. No. 17/673,692, filed Feb. 16, 2022, U.S. Pat. No. 12,015,614, Jun. 18, 2024, Issued. [cited by applicant]
2019201186, Feb. 20, 2019, AU 2019201186 A1, Sep. 5, 2019, Published. [cited by applicant]
201927807, Feb. 19, 2019, JP 6,987,087 B2, Dec. 2, 2021, Issued. [cited by applicant]
2020256320, Feb. 20, 2019, AU 2020256320 A1, Nov. 12, 2020, Published. [cited by applicant]
2021194612, Nov. 30, 2021, JP 7,219,325 B2, Feb. 7, 2023, Issued. [cited by applicant]
2022268298, Nov. 8, 2022, AU 2022268298 A1, Dec. 15, 2022, Published. [cited by applicant]