IP Library Granted Patent US 12,184,652
Granted Patent B2
US 12,184,652 · App. 18/340,988 · Granted Dec 31, 2024

Identity defined secure connect

Inventors: Cameron Williams (Denver, CO); Ryan Privette (Denver, CO); Christopher Chad Wheeler (Denver, CO); Andrew John Cer (Highlands Ranch, CO); Joseph Nathan Zendle (Centennial, CO)
Assignee: SAILPOINT TECHNOLOGIES, INC.
H04L63/0884H04L12/4633H04L12/4641H04L63/0272H04L63/062H04L63/0823H04L63/0846H04L63/0876
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,184,652
App. No.
18/340,988
Granted
Dec 31, 2024
Kind
B2
Abstract

Systems and methods for network security are provided. Various embodiments issue single use certificates for validating remote endpoints access to the private network. Some embodiments use a triage zone (or triage gateway) to which remote device can calls into using a static issued certificate. However, instead of granting complete access to the virtual private network, the use of this static certificate only grants access to the triage zone where further validation of the endpoint without any access to sensitive content on the private network. The endpoint can be connected to an ID manager within the triage zone. The endpoint can then send the username and password to the ID manager that can create a single use certificate (e.g., valid for a limited period of time). While valid, the single use certificate can be used by the remote device to gain access to the production zone using a VPN tunnel.

Claims (36)

1. A system for computer security, the system comprising:

a first processing zone and a second processing zone, the first processing zone separate from the second processing zone, wherein a set of resources cannot be accessed through the first processing zone, and wherein:

the first processing zone is adapted to:

upon successful authentication associated with a client device, issue an ephemeral token in association with a dynamic certificate, wherein the ephemeral token is adapted to be provided to the client device to allow access to the second processing zone, and not the first processing zone, based on the associated dynamic certificate;

the second processing zone adapted to:

establish a connection with the client device based on the dynamic certificate and ephemeral token; and

verify, by accessing the dynamic certificate based on the ephemeral token, that a request received from the client device is valid.

2. The system of claim 1 , wherein the request is verified using a name associated with the dynamic certificate.

3. The system of claim 1 , wherein successful authentication comprises validating a user specific data.

4. The system of claim 1 , wherein the client device establishes a connection to the first processing zone using the ephemeral token.

5. The system of claim 1 , wherein the first processing zone is adapted to generate the dynamic certificate.

6. The system of claim 5 , wherein the dynamic certificate is generated based on certificate details provided by from the client device.

7. A method, for network security, comprising:

providing a first processing zone and a second processing zone, the first processing zone separate from the second processing zone, wherein a set of resources cannot be accessed through the first processing zone, and wherein:

the first processing zone is adapted to:

upon successful authentication associated with a client device, issue an ephemeral token in association with a dynamic certificate, wherein the ephemeral token is adapted to be provided to the client device to allow access to the second processing zone, and not the first processing zone, based on the associated dynamic certificate;

the second processing zone adapted to:

establish a connection with the client device based on the dynamic certificate and ephemeral token; and

verify, by accessing the dynamic certificate based on the ephemeral token, that a request received from the client device is valid.

8. The method of claim 7 , wherein the request is verified using a name associated with the dynamic certificate.

9. The method of claim 7 , wherein successful authentication comprises validating a user specific data.

10. The method of claim 7 , wherein the client device establishes a connection to the first processing zone using the ephemeral token.

11. The method of claim 7 , wherein the first processing zone is adapted to generate the dynamic certificate.

12. The method of claim 11 , wherein the dynamic certificate is generated based on certificate details provided by from the client device.

13. A non-transitory computer readable medium, comprising instructions for:

providing a first processing zone and a second processing zone, the first processing zone separate from the second processing zone, wherein a set of resource cannot be accessed through the first processing zone, and wherein:

the first processing zone is adapted to:

upon successful authentication associated with a client device, issue an ephemeral token in association with a dynamic certificate, wherein the ephemeral token is adapted to be provided to the client device to allow access to the second processing zone, and not the first processing zone, based on the associated dynamic certificate;

the second processing zone adapted to:

establish a connection with the client device based on the dynamic certificate and ephemeral token; and

verify, by accessing the dynamic certificate based on the ephemeral token, that a request received from the client device is valid.

14. The non-transitory computer readable medium of claim 13 , wherein the request is verified using a name associated with the dynamic certificate.

15. The non-transitory computer readable medium of claim 13 , wherein successful authentication comprises validating a user specific data.

16. The non-transitory computer readable medium of claim 13 , wherein the client device establishes a connection to the first processing zone using the ephemeral token.

17. The non-transitory computer readable medium of claim 13 , wherein the first processing zone is adapted to generate the dynamic certificate.

18. The non-transitory computer readable medium of claim 17 , wherein the dynamic certificate is generated based on certificate details provided by from the client device.

Assignments (3)
PATENT SECURITY AGREEMENT Recorded Jun 25, 2025
From: SAILPOINT TECHNOLOGIES, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071724/0511 →
MERGER Recorded Aug 14, 2023
From: OVERWATCH.ID, INC.
To: SAILPOINT TECHNOLOGIES, INC.
Reel/Frame 064578/0620 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 14, 2023
From: ZENDLE, JOSEPH; WILLIAMS, CAMERON; PRIVETTE, RYAN; WHEELER, CHRISTOPHER CHAD; CER, ANDREW
To: OVERWATCH.ID, INC.
Reel/Frame 064578/0629 →
Continuity (4)
Continuation 17554942 · Dec 17, 2021
Continuation 16100068 · Aug 9, 2018
Provisional Application 62543118 · Aug 9, 2017
Related Publication 20230336549A1 · Oct 19, 2023