IP Library Granted Patent US 12,368,702
Granted Patent B2
US 12,368,702 · App. 18/324,301 · Granted Jul 22, 2025

Intent-based identity access management systems and methods

Inventors: Jamie Lin (St. Louis, MO); Vishal Vallabha (Mount Juliet, TN); John T. Pugaczewski (Hugo, MN); Christopher Buzzetta (Highlands Ranch, CO); Glenn Balanoff (Arvada, CO); John Knies (Evansville, IN); Sylvan H. Morley, III (Thornton, CO); Jason Lish (Phoenix, AZ)
Assignee: Level 3 Communications, LLC
H04L63/0807H04L63/102H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,368,702
App. No.
18/324,301
Granted
Jul 22, 2025
Kind
B2
Abstract

An identity and access management system including: a processor; and memory including instructions that, when executed by the processor, cause the processor to: receive an API token request for an authorization token to authorize an application function associated with a target API of an application; determine identity information from the API token request; retrieve attributes associated with the identity information; identify the target API and an API function profile associated with the target API for the application function; filter the attributes associated with the identity information based on the API function profile; generate the authorization token according to the filtered attributes; and transmit the authorization token in response to the API token request.

Claims (57)

1. An identity and access management system comprising:

at least one processor; and

memory comprising instructions that, when executed by the at least one processor, cause the processor to:

receive an application programming interface (API) token request for an authorization token to authorize an application function associated with a target API of an application;

determine identity information from the API token request;

retrieve attributes associated with the identity information;

identify the target API and an API function profile associated with the target API for the application function;

filter the attributes associated with the identity information based on the API function profile;

generate the authorization token according to the filtered attributes;

transmit the authorization token in response to the API token request;

identify one or more API authorization policies based on the API function profile, wherein the API authorization policies enable only the application function associated with the target API from among a plurality of application functions associated with the application of the target API;

execute the one or more API authorization policies based on the filtered attributes to generate the authorization token;

receive API requirements registered in an API marketplace for the target API, the API requirements including at least the application function associated with the target API and application requirements for the authorization token to enable the application function by the target API;

generate the API authorization policies based on the application function and the application requirements;

generate the API function profile for the target API based on the API authorization polices; and

associate the API function profile with the target API.

2. The system of claim 1 , wherein the attributes are retrieved from a master data management store configured to store various attributes of various applications and users.

3. The system of claim 1 , wherein the API function profile includes a plurality of attribute types to be included in the authorization token generated for the target API.

4. The system of claim 1 , wherein the authorization token enables only the application function associated with the target API from among a plurality of application functions associated with the application of the target API.

5. A method, comprising:

receiving an application programming interface (API) token request for an authorization token to authorize an application function associated with a target API of an application;

determining identity information from the API token request;

retrieving attributes associated with the identity information;

identifying the target API and an API function profile associated with the target API for the application function;

filtering the attributes associated with the identity information based on the API function profile;

generating the authorization token according to the filtered attributes;

transmitting the authorization token in response to the API token request;

identifying one or more API authorization policies based on the API function profile, wherein the API authorization policies enable only the application function associated with the target API from among a plurality of application functions associated with the application of the target API;

executing the one or more API authorization policies based on the filtered attributes to generate the authorization token;

receiving API requirements registered in an API marketplace for the target API, the API requirements including at least the application function associated with the target API and application requirements for the authorization token to enable the application function by the target API;

generating the API authorization policies based on the application function and the application requirements;

generating the API function profile for the target API based on the API authorization polices; and

associating the API function profile with the target API.

6. The method of claim 5 , wherein the attributes are retrieved from a master data management store configured to store various attributes of various applications and users.

7. The method of claim 5 , wherein the API function profile includes a plurality of attribute types to be included in the authorization token generated for the target API.

8. The method of claim 5 , wherein the authorization token enables only the application function associated with the target API from among a plurality of application functions associated with the application of the target API.

9. An identity and access management system comprising:

at least one processor; and

memory comprising instructions that, when executed by the at least one processor, cause the processor to:

receive an application programming interface (API) token request for an authorization token to authorize an application function associated with a target API of an application;

receive API requirements registered in an API marketplace for the target API, the API requirements including at least the application function associated with the target API and application requirements for the authorization token to enable the application function by the target API;

determine identity information from the API token request;

retrieve attributes associated with the identity information;

identify the target API and an API function profile associated with the target API for the application function;

filter the attributes associated with the identity information based on the API function profile;

generate the authorization token according to the filtered attributes; and

transmit the authorization token in response to the API token request.

10. The system of claim 9 , wherein the attributes are retrieved from a master data management store configured to store various attributes of various applications and users.

11. The system of claim 9 , wherein the instructions further cause the at least one processor to:

identify one or more API authorization policies based on the API function profile; and

execute the one or more API authorization policies based on the filtered attributes to generate the authorization token.

12. The system of claim 11 , wherein the API authorization policies enable only the application function associated with the target API from among a plurality of application functions associated with the application of the target API.

13. The system of claim 12 , wherein the instructions further cause the at least one processor to:

generate the API authorization policies based on the application function and the application requirements;

generate the API function profile for the target API based on the API authorization polices; and

associate the API function profile with the target API.

14. The system of claim 13 , wherein the API function profile includes a plurality of attribute types to be included in the authorization token generated for the target API.

Assignments (2)
NOTICE OF GRANT OF SECURITY INTEREST IN INTELLECTUAL PROPERTY (SECOND LIEN) Recorded Nov 4, 2024
From: LEVEL 3 COMMUNICATIONS, LLC; GLOBAL CROSSING TELECOMMUNICATIONS, INC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 069295/0749 →
NOTICE OF GRANT OF SECURITY INTEREST IN INTELLECTUAL PROPERTY (FIRST LIEN) Recorded Nov 4, 2024
From: LEVEL 3 COMMUNICATIONS, LLC; GLOBAL CROSSING TELECOMMUNICATIONS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 069295/0858 →
Continuity (2)
Provisional Application 63365374 · May 26, 2022
Related Publication 20230388282A1 · Nov 30, 2023
References Cited (7)
US 20190098055A1 · Pitre · 2019 [cited by applicant]
US 20190327224A1 · Zhang · 2019 [cited by examiner]
US 20200026871A1 · Mikhailov · 2020 [cited by applicant]
US 20200145421A1 · Tin · 2020 [cited by examiner]
US 20220309177A1 · Mikhailov · 2022 [cited by examiner]
US 20230075296A1 · Morley, III · 2023 [cited by examiner]
International Search Report and Written Opinion of the International Searching Authority, dated Sep. 27, 2023, Int'l Appl. No. PCT/US2023/067526, Int'l Filing Date May 26, 2023; 10 pgs. [cited by applicant]