IP Library Granted Patent US 12,445,446
Granted Patent B2
US 12,445,446 · App. 18/053,721 · Granted Oct 14, 2025

Techniques for unifying multiple identity clouds

Inventors: Karl McGuinness (Oakland, CA); Matias Woloski (Punta del Este, UY)
H04L63/102H04L63/0815
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,445,446
App. No.
18/053,721
Granted
Oct 14, 2025
Kind
B2
Abstract

Methods, systems, and devices for unifying multiple identity clouds are described. A software platform may receive a first request from a first user to build an authorization model for a resource using a first cloud platform. The authorization model may identify parameters associated with accessing the resource. The software platform may receive, from the first user, a second request to integrate the resource with a second cloud platform in accordance with the authorization model. The software platform may authorize the first request and the second request using a directory associated with the software platform. The software platform may receive a third request from a second user to access the resource using the second cloud platform. The software platform may authorize the third request using the directory. Authorization of the third request may be performed accordance to the authorization model and based on a second credential associated with the second user.

Claims (53)

1. A method for managing resources at a software platform of a device, comprising:

receiving, from a first user associated with an application, a first request to build an authorization model for a resource of the application using a first cloud platform associated with the software platform, the first cloud platform including one or more features associated with authentication management across a plurality of applications comprising the application, wherein the authorization model identifies one or more parameters associated with accessing the resource via a second cloud platform associated with the software platform, the second cloud platform used by a plurality of organizations;

receiving, from the first user, a second request to integrate the resource with the second cloud platform in accordance with the authorization model, wherein the resource is accessible via the second cloud platform in accordance with integration of the resource with the second cloud platform;

authorizing the first request and the second request using a directory associated with the software platform, wherein authorization of the first request and the second request is based at least in part on a first credential associated with the first user;

receiving, from a second user of an organization of the plurality of organizations, a third request to access the resource of the application via the second cloud platform associated with the software platform; and

authorizing the third request using the directory associated with the software platform, wherein the authorization of the third request is in accordance with the authorization model and based at least in part on a second credential associated with the second user.

2. The method of claim 1 , further comprising:

establishing a connection between the second cloud platform and the resource in response to authorizing the third request.

3. The method of claim 2 , further comprising:

establishing an authorization scheme using the connection between the second cloud platform and the resource in accordance with the authorization model, wherein the authorization scheme comprises single-sign-on authorization.

4. The method of claim 2 , further comprising:

assigning privileges to the second user using the connection between the second cloud platform and the resource, wherein the privileges are based at least in part on the authorization model.

5. The method of claim 2 , further comprising:

transmitting, to the first user and based at least in part on the connection between the second cloud platform and the resource, information corresponding to a security event associated with the resource.

6. The method of claim 2 , further comprising:

receiving, from the first user and based at least in part on the connection between the second cloud platform and the resource, information corresponding to a security event associated with the resource.

7. The method of claim 6 , further comprising:

transmitting, to the second user, the information corresponding to the security event associated with the resource.

8. The method of claim 1 , wherein the resource is included within a software application.

9. An apparatus for managing resources at a software platform of a device, comprising:

a processor;

memory coupled with the processor; and

instructions stored in the memory and executable by the processor to cause the apparatus to:

receive, from a first user associated with an application, a first request to build an authorization model for a resource of the application using a first cloud platform associated with the software platform, the first cloud platform including one or more features associated with authentication management across a plurality of applications comprising the application, wherein the authorization model identifies one or more parameters associated with accessing the resource via a second cloud platform associated with the software platform, the second cloud platform used by a plurality of organizations;

receive, from the first user, a second request to integrate the resource with the second cloud platform in accordance with the authorization model, wherein the resource is accessible via the second cloud platform in accordance with integration of the resource with the second cloud platform;

authorize the first request and the second request using a directory associated with the software platform, wherein authorization of the first request and the second request is based at least in part on a first credential associated with the first user;

receive, from a second user of an organization of the plurality of organizations, a third request to access the resource of the application via the second cloud platform associated with the software platform; and

authorize the third request using the directory associated with the software platform, wherein the authorization of the third request is in accordance with the authorization model and based at least in part on a second credential associated with the second user.

10. The apparatus of claim 9 , wherein the instructions are further executable by the processor to cause the apparatus to:

establish a connection between the second cloud platform and the resource in response to authorizing the third request.

11. The apparatus of claim 10 , wherein the instructions are further executable by the processor to cause the apparatus to:

establish an authorization scheme using the connection between the second cloud platform and the resource in accordance with the authorization model, wherein the authorization scheme comprises single-sign-on authorization.

12. The apparatus of claim 10 , wherein the instructions are further executable by the processor to cause the apparatus to:

assign privileges to the second user using the connection between the second cloud platform and the resource, wherein the privileges are based at least in part on the authorization model.

13. The apparatus of claim 10 , wherein the instructions are further executable by the processor to cause the apparatus to:

transmit, to the first user and based at least in part on the connection between the second cloud platform and the resource, information corresponding to a security event associated with the resource.

14. The apparatus of claim 10 , wherein the instructions are further executable by the processor to cause the apparatus to:

receive, from the first user and based at least in part on the connection between the second cloud platform and the resource, information corresponding to a security event associated with the resource.

15. The apparatus of claim 14 , wherein the instructions are further executable by the processor to cause the apparatus to:

transmit, to the second user, the information corresponding to the security event associated with the resource.

16. The apparatus of claim 9 , wherein the resource is included within a software application.

17. A non-transitory computer-readable medium storing code for managing resources at a software platform of a device, the code comprising instructions executable by a processor to:

receive, from a first user associated with an application, a first request to build an authorization model for a resource of the application using a first cloud platform associated with the software platform, the first cloud platform including one or more features associated with authentication management across a plurality of applications comprising the application, wherein the authorization model identifies one or more parameters associated with accessing the resource via a second cloud platform associated with the software platform, the second cloud platform used by a plurality of organizations;

receive, from the first user, a second request to integrate the resource with the second cloud platform in accordance with the authorization model, wherein the resource is accessible via the second cloud platform in accordance with integration of the resource with the second cloud platform;

authorize the first request and the second request using a directory associated with the software platform, wherein authorization of the first request and the second request is based at least in part on a first credential associated with the first user;

receive, from a second user of an organization of the plurality of organizations, a third request to access the resource of the application via the second cloud platform associated with the software platform; and

authorize the third request using the directory associated with the software platform, wherein the authorization of the third request is in accordance with the authorization model and based at least in part on a second credential associated with the second user.

18. The non-transitory computer-readable medium of claim 17 , wherein the instructions are further executable by the processor to:

establish a connection between the second cloud platform and the resource in response to authorizing the third request.

19. The non-transitory computer-readable medium of claim 18 , wherein the instructions are further executable by the processor to:

establish an authorization scheme using the connection between the second cloud platform and the resource in accordance with the authorization model, wherein the authorization scheme comprises single-sign-on authorization.

20. The non-transitory computer-readable medium of claim 18 , wherein the instructions are further executable by the processor to:

assign privileges to the second user using the connection between the second cloud platform and the resource, wherein the privileges are based at least in part on the authorization model.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 23, 2022
From: MCGUINNESS, KARL; WOLOSKI, MATIAS
To: OKTA, INC.
Reel/Frame 061863/0933 →
Continuity (1)
Related Publication 20240154967A1 · May 9, 2024
References Cited (26)
US 9087189B1 · Koeten et al. · 2015 [cited by applicant]
US 9774586B1 · Roche et al. · 2017 [cited by applicant]
US 10846390B2 · Subramanian et al. · 2020 [cited by applicant]
US 11930015B2 · Yang · 2024 [cited by examiner]
US 20100132019A1 · Hardt · 2010 [cited by examiner]
US 20130179573A1 · McCarty · 2013 [cited by examiner]
US 20170279793A1 · Trevathan et al. · 2017 [cited by applicant]
US 20180077143A1 · Sridharan · 2018 [cited by examiner]
US 20180083967A1 · Subramanian et al. · 2018 [cited by applicant]
US 20190306171A1 · Sisley · 2019 [cited by examiner]
US 20200125542A1 · Purushothaman et al. · 2020 [cited by applicant]
US 20210112065A1 · Yang · 2021 [cited by examiner]
US 20210281559A1 · Valecha · 2021 [cited by examiner]
US 20210390170A1 · Olden et al. · 2021 [cited by applicant]
US 20230036145A1 · Ramachandran et al. · 2023 [cited by applicant]
US 20230214514A1 · Levy · 2023 [cited by examiner]
US 20240146710A1 · Shah et al. · 2024 [cited by applicant]
US 20240154967A1 · McGuinness · 2024 [cited by examiner]
US 20240154968A1 · Kwon et al. · 2024 [cited by applicant]
US 20240364681A1 · Hu et al. · 2024 [cited by applicant]
US 20250111030A1 · Hamel et al. · 2025 [cited by applicant]
US 20250112906A1 · Kwon et al. · 2025 [cited by applicant]
CN 116471029A · 2023 [cited by applicant]
EP 3528454A1 · 2019 [cited by applicant]
“International Search Report and Written Opinion of the International Searching Authority,” issued in connection with Int'l Appl. No. PCT/US2023/034593, dated Feb. 15, 2024 (10 pages). [cited by applicant]
“International Search Report and Written Opinion of the International Searching Authority,” issued in connection with Int'l Appl. No. PCT/US2024/049480, dated Dec. 9, 2024 (12 pages). [cited by applicant]