IP Library Granted Patent US 12,413,594
Granted Patent B2
US 12,413,594 · App. 18/600,282 · Granted Sep 9, 2025

System and method for outlier and anomaly detection in identity management artificial intelligence systems using cluster based analysis of network identity graphs

Inventors: Mohamed M. Badawy (Round Rock, TX); Jostine Fei Ho (Austin, TX)
Assignee: SAILPOINT TECHNOLOGIES, INC.
H04L63/102G06F16/9024H04L63/104
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,413,594
App. No.
18/600,282
Granted
Sep 9, 2025
Kind
B2
Abstract

Systems and methods for artificial intelligence systems for identity management systems are disclosed. Embodiments may perform outlier detection and risk assessment based on identity management data, including one or more property graphs or peer groups determined from those property graphs, to determine identity management artifacts with ‘abnormal’ patterns when compared to other related identity management artifacts.

Claims (42)

1. An identity management system for risk assessment using graphs, comprising:

a memory;

a processor device;

a non-transitory, computer-readable storage medium including instructions executable by the processor device for:

accessing identity management data obtained from one or more source systems;

evaluating the accessed identity management data to determine a set of identity management artifacts associated with a set of identities and at least one entitlement in association with the one or more source systems;

generating a first identity management graph from the identity management data, the first identity management graph comprising nodes for identity management artifacts edges between those nodes, and weights for the edges based on data associated with nodes joined by those edges in accordance with the associated set of identifies or at least one entitlement;

analyzing the first identity management graph or the identity management data to identify an anomaly;

identifying an identity management artifact associated with the identified anomaly as a high risk identity management artifact;

presenting the identified high risk identity management artifact through a user interface of the identity management system to manage vulnerabilities associated with the set of identities or at least one entitlement.

2. The system of claim 1 , wherein the analysis of the first identity graph is based on a second identity graph associated with the set of identity management artifacts.

3. The system of claim 2 , wherein the first identity graph is associated with a first time and the second identity graph is associated with a second time.

4. The system of claim 3 , wherein the second time is previous to the first time or subsequent to the first time.

5. The system of claim 1 , wherein the anomaly is identified based on a degree of connectivity or in-betweenness of a node in the first identity management graph associated with the identified identity management artifact.

6. The system of claim 1 , wherein the identified identity management artifact is an identity, entitlement, or role.

7. The system of claim 1 , wherein the anomaly is an outlier with respect to the first identity management graph.

8. A method for risk at assessment using graphs, comprising:

accessing identity management data obtained from one or more source systems;

evaluating the accessed identity management data to determine a set of identity management artifacts associated with a set of identities and at least one entitlement in association with the one or more source systems;

generating a first identity management graph from the identity management data, the first identity management graph comprising nodes for identity management artifacts edges between those nodes, and weights for the edges based on data associated with nodes joined by those edges in accordance with the associated set of identities or at least one entitlement;

analyzing the first identity management graph or the identity management data to identify an anomaly;

identifying an identity management artifact associated with the identified anomaly as a high risk identity management artifact;

presenting the identified high risk identity management artifact through a user interface of the identity management system to manage vulnerability associated with the set of identities or at least one entitlement.

9. The method of claim 8 , wherein the analysis of the first identity graph is based on a second identity graph associated with the set of identity management artifacts.

10. The method of claim 9 , wherein the first identity graph is associated with a first time and the second identity graph is associated with a second time.

11. The method of claim 10 , wherein the second time is previous to the first time or subsequent to the first time.

12. The method of claim 8 , wherein the anomaly is identified based on a degree of connectivity or in-betweenness of a node in the first identity management graph associated with the identified identity management artifact.

13. The method of claim 8 , wherein the identified identity management artifact is an identity, entitlement, or role.

14. The method of claim 8 , wherein the anomaly is an outlier with respect to the first identity management graph.

15. A non-transitory computer storage readable medium, comprising instructions of risk assessment using graphs for:

accessing identity management data obtained form one or more source systems;

evaluating the accessed identity management data to determine a set of identity management artifacts associated with a set of identities and at least one entitlement in association with the one or more source systems;

generating a first identity management graph from the identity management data, the first identity management graph comprising nodes for identity management artifacts edges between those nodes, and weights for the edges based on data associated with nodes joined by those edges in accordance with the associated set of identities or at least one entitlement;

analyzing the first identity management graph or the identity management data to identify an anomaly;

identifying an identity management artifact associated with the identified anomaly as a high risk identity management artifact;

presenting the identified high risk identity management artifact through a user interface of the identity management system to manage vulnerabilities associated with the set of identities or at least one entitlement.

16. The non-transitory computer readable medium of claim 15 , wherein the analysis of the first identity graph is based on a second identity graph associated with the set of identity management artifacts.

17. The non-transitory computer readable medium of claim 16 , wherein the first identity graph is associated with a first time and the second identity graph is associated with a second time.

18. The non-transitory computer readable medium of claim 17 , wherein the second time is previous to the first time or subsequent to the first time.

19. The non-transitory computer readable medium of claim 15 , wherein the anomaly is identified based on a degree of connectivity or in-betweenness of a node in the first identity management graph associated with the identified identity management artifact.

20. The non-transitory computer readable medium of claim 15 , wherein the identified identity management artifact is an identity, entitlement, or role.

21. The non-transitory computer readable medium of claim 15 , wherein the anomaly is an outlier with respect to the first identity management graph.

Assignments (2)
PATENT SECURITY AGREEMENT Recorded Jun 25, 2025
From: SAILPOINT TECHNOLOGIES, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 071724/0511 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 9, 2024
From: BADAWY, MOHAMED M.; HO, JOSTINE FEI
To: SAILPOINT TECHNOLOGIES, INC.
Reel/Frame 067046/0526 →
Continuity (5)
Continuation 17825545 · May 26, 2022
Continuation 16861335 · Apr 29, 2020
Continuation 16691998 · Nov 22, 2019
Provisional Application 62771889 · Nov 27, 2018
Related Publication 20240214383A1 · Jun 27, 2024
References Cited (19)
US 9679125B2 · Bailor · 2017 [cited by examiner]
US 11610205B1 · Fain · 2023 [cited by applicant]
US 11962597B2 · Badawy · 2024 [cited by applicant]
US 11966858B2 · Badawy · 2024 [cited by applicant]
US 12041056B2 · Badawy · 2024 [cited by applicant]
US 12056588B2 · Badawy · 2024 [cited by applicant]
US 12254422B2 · Badawy · 2025 [cited by applicant]
US 12294584B2 · Badawy · 2025 [cited by applicant]
US 20190114342A1 · Orun · 2019 [cited by examiner]
US 20240211782A1 · Badawy · 2024 [cited by applicant]
US 20240267384A1 · Badawy · 2024 [cited by applicant]
US 20240356925A1 · Badawy · 2024 [cited by applicant]
US 20250094628A1 · McDonnell · 2025 [cited by applicant]
US 20250173591A1 · Badawy · 2025 [cited by applicant]
Office Action for U.S. Appl. No. 18/534,067, mailed Sep. 5, 2024, 12 pgs. [cited by applicant]
Office Action for U.S. Appl. No. 18/600,241, mailed Sep. 19, 2024, 11 pgs. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 17/948,635, mailed Mar. 27, 2024, 8 pgs. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 18/600,241, mailed Oct. 30, 2024, 6 pgs. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 18/534,067, mailed Jan. 23, 2025, 6 pgs. [cited by applicant]