IP Library Granted Patent US 12,598,188
Granted Patent B2
US 12,598,188 · App. 18/326,705 · Granted Apr 7, 2026

System and method for describing and visualizing allowed, denied, chained and effective access to a system

Inventors: Kristopher A. Keller (Cookeville, TN); Manoj K. Guglani (Los Gatos, CA)
Assignee: SailPoint Technologies, Inc.
H04L63/102H04L41/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,598,188
App. No.
18/326,705
Granted
Apr 7, 2026
Kind
B2
Abstract

Systems and methods are disclosed relating to identity governance and privileged access control in a distributed networked computing environment for cloud based computing services. Embodiments disclosed include a logical model developed to describe the effective access of multiple cloud service providers (CSPs), each of which may be based on different access systems. The resulting system can then provide a singular experience across all CSPs used by users, giving users a clear picture of how access is achieved.

Claims (37)

1 . An identity management system, comprising:

a processor;

a non-transitory, computer-readable storage medium, including computer instructions for:

obtaining identity management data from a plurality of different cloud service providers, the identity management data from each respective cloud service provider comprising data relating to rights and permissions associated with users of the respective cloud service provider, wherein the identity management data from a respective cloud service provider uses different terminology and a different data model than other of the different cloud service providers;

for each of the plurality of cloud service providers, normalizing the identity management data of the respective cloud service provider to match normalized terminology used by each of the plurality of cloud service providers;

for each of the plurality of cloud service providers, evaluating the respective normalized identity management data to determine rights of users and groups associated with the respective cloud service provider;

applying the determined rights of the plurality of cloud service providers to an access model to determine federated rights of users and groups across the plurality of different cloud service providers; and

presenting over a graphical user interface a graphical representation of the federated rights of a user across the plurality of cloud service providers.

2 . The identity management system of claim 1 , wherein at least one of the plurality of cloud service providers implements role-based access control.

3 . The identity management system of claim 1 , wherein at least one of the plurality of cloud service providers implements attribute-based access control.

4 . The identity management system of claim 1 , wherein the identity management data for a given cloud service provider specifies a collection of permissions and actions that a given user is allowed to take.

5 . The identity management system of claim 1 , wherein the identity management data for a given cloud service provider specifies a set of resources to which a given user has access.

6 . The identity management system of claim 1 , wherein the identity management data for a given cloud service provider specifies one or more groups to which a given user is associated.

7 . The identity management system of claim 1 , wherein the graphical representation illustrates when a given user is allowed to assume a role.

8 . A method, comprising:

obtaining identity management data from a plurality of different cloud service providers, the identity management data from each respective cloud service provider comprising data relating to rights and permissions associated with users of the respective cloud service provider, wherein the identity management data from a respective cloud service provider uses different terminology and a different data model than other of the different cloud service providers;

for each of the plurality of cloud service providers, normalizing the identity management data of the respective cloud service provider to match normalized terminology used by each of the plurality of cloud service providers;

for each of the plurality of cloud service providers, evaluating the respective normalized identity management data to determine rights of users and groups associated with the respective cloud service provider;

applying the determined rights of the plurality of cloud service providers to an access model to determine federated rights of users and groups across the plurality of different cloud service providers; and

presenting over a graphical user interface a graphical representation of the federated rights of a user across the plurality of cloud service providers.

9 . The method of claim 8 , wherein at least one of the plurality of cloud service providers implements role-based access control.

10 . The method of claim 8 , wherein at least one of the plurality of cloud service providers implements attribute-based access control.

11 . The method of claim 8 , wherein the identity management data for a given cloud service provider specifies a collection of permissions and actions that a given user is allowed to take.

12 . The method of claim 8 , wherein the identity management data for a given cloud service provider specifies a set of resources to which a given user has access.

13 . The method of claim 8 , wherein the identity management data for a given cloud service provider specifies one or more groups to which a given user is associated.

14 . The method of claim 8 , wherein the graphical representation illustrates when a given user is allowed to assume a role.

15 . A non-transitory computer readable medium, comprising instructions for:

obtaining identity management data from a plurality of different cloud service providers, the identity management data from each respective cloud service provider comprising data relating to rights and permissions associated with users of the respective cloud service provider, wherein the identity management data from a respective cloud service provider uses different terminology and a different data model than other of the different cloud service providers;

for each of the plurality of cloud service providers, normalizing the identity management data of the respective cloud service provider to match normalized terminology used by each of the plurality of cloud service providers;

for each of the plurality of cloud service providers, evaluating the respective normalized identity management data to determine rights of users and groups associated with the respective cloud service provider;

applying the determined rights of the plurality of cloud service providers to an access model to determine federated rights of users and groups across the plurality of different cloud service providers; and

presenting over a graphical user interface a graphical representation of the federated rights of a user across the plurality of cloud service providers.

16 . The non-transitory computer readable medium of claim 15 , wherein at least one of the plurality of cloud service providers implements role-based access control.

17 . The non-transitory computer readable medium of claim 15 , wherein at least one of the plurality of cloud service providers implements attribute-based access control.

18 . The non-transitory computer readable medium of claim 15 , wherein the identity management data for a given cloud service provider specifies a collection of permissions and actions that a given user is allowed to take.

19 . The non-transitory computer readable medium of claim 15 , wherein the identity management data for a given cloud service provider specifies a set of resources to which a given user has access.

20 . The non-transitory computer readable medium of claim 15 , wherein the identity management data for a given cloud service provider specifies one or more groups to which a given user is associated.

Assignments (2)
PATENT SECURITY AGREEMENT Recorded Jun 25, 2025
From: SAILPOINT TECHNOLOGIES, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071724/0511 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 21, 2023
From: KELLER, KRISTOPHER A.; GUGLANI, MANOJ K.
To: SAILPOINT TECHNOLOGIES, INC.
Reel/Frame 064341/0783 →
Continuity (1)
Related Publication 20240406180A1 · Dec 5, 2024
References Cited (39)
US 9276942B2 · Srinivasan · 2016 [cited by applicant]
US 9692748B2 · Maheshwari · 2017 [cited by applicant]
US 9761119B1 · Trundle · 2017 [cited by examiner]
US 10291638B1 · Chandana · 2019 [cited by examiner]
US 10310745B2 · Wu · 2019 [cited by examiner]
US 10798084B1 · Rose · 2020 [cited by applicant]
US 10878483B1 · Felbinger · 2020 [cited by examiner]
US 11178182B2 · Saxena · 2021 [cited by applicant]
US 11223559B2 · Rahman · 2022 [cited by examiner]
US 11516203B2 · Rose · 2022 [cited by applicant]
US 11711401B2 · Solari · 2023 [cited by examiner]
US 12010120B2 · Parks · 2024 [cited by examiner]
US 12041046B2 · Rose · 2024 [cited by applicant]
US 20130007845A1 · Chang · 2013 [cited by examiner]
US 20150269383A1 · Lang · 2015 [cited by applicant]
US 20170099344A1 · Hadfield · 2017 [cited by examiner]
US 20180069899A1 · Lang · 2018 [cited by applicant]
US 20180234480A1 · Rezvani · 2018 [cited by examiner]
US 20180367526A1 · Huang · 2018 [cited by examiner]
US 20190068612A1 · Eads · 2019 [cited by examiner]
US 20190327271A1 · Saxena · 2019 [cited by applicant]
US 20190373006A1 · Chandana · 2019 [cited by examiner]
US 20200019414A1 · Byard · 2020 [cited by examiner]
US 20200358756A1 · Rose · 2020 [cited by applicant]
US 20210075727A1 · Chen · 2021 [cited by examiner]
US 20220271958A1 · Bassili · 2022 [cited by examiner]
US 20220311777A1 · Makenzi · 2022 [cited by examiner]
US 20230021041A1 · Rose · 2023 [cited by applicant]
US 20230153426A1 · Grobelny · 2023 [cited by examiner]
CA 2907301C · 2023 [cited by examiner]
CN 102571821A · 2012 [cited by examiner]
CN 114385367A · 2022 [cited by examiner]
Notice of Allowance for U.S. Appl. No. 17/944,319, mailed Mar. 6, 2024, 9 pgs. [cited by applicant]
CIS Benchmarks, CIS Amazon Web Services Foundations, v1.2.0, May 23, 2018, 158 pages. [cited by applicant]
International Search Report and Written Opinion issued in PCT Application No. PCT/US19/28390, mailed Jul. 18, 2019, 9 pages. [cited by applicant]
Office Action issued in U.S. Appl. No. 16/389,755, mailed Apr. 21, 2021, 12 pages. [cited by applicant]
International Preliminary Report on Patentability mailed Oct. 20, 2020, and Written Opinion mailed Jul. 18, 2019, issued in International Patent Application No. PCT/US19/28390, 7 pages. [cited by applicant]
Notice of Allowance issued in U.S. Appl. No. 16/389,755, mailed Aug. 2, 2021, 15 pages. [cited by applicant]
Notice of Allowance issued in U.S. Appl. No. 16/942,416, mailed Jul. 11, 2022, 13 pages. [cited by applicant]