IP Library Patent Application 18825572
Patent Application
App. No. 18/825,572

DECOUPLING IDENTITY MANAGEMENT AND AUTHENTICATION FROM ATTRIBUTE PROVISIONING

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/825,572
Abstract

According to various embodiments, the system and method described herein provide techniques for decoupling identity management and authentication from identity attribute provisioning and additional extended management, thus allowing identity attribute-based authorization to be maintained inside a protected system while delegating authentication to a centralized identity provider (IDP). In at least one embodiment, a user lifecycle component (ULC) is situated between the IDP and an identity consumption platform. The IDP is delegated IDP responsibilities and provides identity authentication to the identity consumption platform, while the ULC provides provisioning and attribute management that is further used for authorization within the identity consumption platform. In at least one embodiment, the ULC may use APIs (such as Okta APIs) to read identity statuses from the IDP. An attribute mapping database may be provided, to maintain mappings between values of identity groups attributes and a set of groups.

Claims (58)

1 . A computer-implemented method for identity management, comprising:

automatically assigning identity management and authentication responsibilities to an identity provider;

automatically assigning attribute provisioning to a component that is separate from the identity provider;

establishing communication among the identity consumption platform, the identity provider, and the separate component, to enable identity management and authentication by the identity provider and to further enable attribute provisioning by the separate component; and

at the separate component, performing attribute provisioning for the identity consumption platform.

2 . The method of claim 1 , wherein automatically assigning attribute provisioning to the separate component comprises automatically assigning attribute mapping to the separate component.

3 . The method of claim 1 , wherein the identity provider comprises an Okta identity cloud.

4 . The method of claim 1 , wherein the identity consumption platform comprises an AWS IAM Identity Center.

5 . The method of claim 1 , wherein the separate component comprises a user lifecycle component.

6 . The method of claim 1 , further comprising:

at the separate component, obtaining, from the identity provider, a list of users to provision to the identity consumption platform;

at the separate component, obtaining, from the identity provider, attributes for the users;

storing the user attributes in a database; and

retrieving the stored user attributes to provision users and user attributes for the identity consumption platform.

7 . The method of claim 6 , further comprising assigning default attributes to the users based on group membership.

8 . The method of claim 6 , wherein obtaining the list of users to provision to the identity consumption platform comprises using API's associated with the identity provider.

9 . The method of claim 6 , wherein performing attribute provisioning for the identity consumption platform comprises using API's associated with the identity consumption platform.

10 . The method of claim 9 , wherein the APIs associated with the identity consumption platform comprise AWS SCIM APIs.

11 . A non-transitory computer-readable medium for identity management, comprising instructions stored thereon, that when performed by one or more hardware processing devices, perform the steps of:

automatically assigning identity management and authentication responsibilities to an identity provider;

automatically assigning attribute provisioning to a component that is separate from the identity provider;

establishing communication among the identity consumption platform, the identity provider, and the separate component, to enable identity management and authentication by the identity provider and to further enable attribute provisioning by the separate component; and

causing the separate component to perform attribute provisioning for the identity consumption platform.

12 . The non-transitory computer-readable medium of claim 11 , wherein automatically assigning attribute provisioning to the separate component comprises automatically assigning attribute mapping to the separate component.

13 . The non-transitory computer-readable medium of claim 11 , wherein the identity provider comprises an Okta identity cloud.

14 . The non-transitory computer-readable medium of claim 11 , wherein the identity consumption platform comprises an AWS IAM Identity Center.

15 . The non-transitory computer-readable medium of claim 11 , wherein the separate component comprises a user lifecycle component.

16 . The non-transitory computer-readable medium of claim 11 , further comprising instructions stored thereon, that when performed by one or more hardware processing devices, perform the steps of:

causing the separate component to obtain, from the identity provider, a list of users to provision to the identity consumption platform;

causing the separate component to obtain, from the identity provider, attributes for the users;

causing the user attributes to be stored in a database; and

retrieving the stored user attributes to provision users and user attributes for the identity consumption platform.

17 . The non-transitory computer-readable medium of claim 16 , further comprising instructions stored thereon, that when performed by one or more hardware processing devices, perform the step of assigning default attributes to the users based on group membership.

18 . The non-transitory computer-readable medium of claim 16 , wherein obtaining the list of users to provision to the identity consumption platform comprises using API's associated with the identity provider.

19 . The non-transitory computer-readable medium of claim 16 , wherein performing attribute provisioning for the identity consumption platform comprises using API's associated with the identity consumption platform.

20 . The non-transitory computer-readable medium of claim 19 , wherein the APIs associated with the identity consumption platform comprise AWS SCIM APIs.

21 . A system for identity management, comprising:

a processor configured to automatically assign identity management and authentication responsibilities to an identity provider; and

a component that is separate from the identity provider and is communicatively coupled to the processor;

wherein the processor is further configured to:

automatically assign attribute provisioning to the separate component; and

establish communication among the identity consumption platform, the identity provider, and the separate component, to enable identity management and authentication by the identity provider and to further enable attribute provisioning by the separate component; and

and wherein the separate component is configured to perform attribute provisioning for the identity consumption platform.

22 . The system of claim 21 , wherein automatically assigning attribute provisioning to the separate component comprises automatically assigning attribute mapping to the separate component.

23 . The system of claim 21 , wherein the identity provider comprises an Okta identity cloud.

24 . The system of claim 21 , wherein the identity consumption platform comprises an AWS IAM Identity Center.

25 . The system of claim 21 , wherein the separate component comprises a user lifecycle component.

26 . The system of claim 21 , further comprising:

a database;

wherein:

the separate component is further configured to obtain, from the identity provider, a list of users to provision to the identity consumption platform;

the separate component is further configured to obtain, from the identity provider, attributes for the users;

the database is configured to store the user attributes; and

the processor is further configured to retrieve the stored user attributes to provision users and user attributes for the identity consumption platform.

27 . The system of claim 26 , wherein the processor is further configured to assign default attributes to the users based on group membership.

28 . The system of claim 26 , wherein obtaining the list of users to provision to the identity consumption platform comprises using API's associated with the identity provider.

29 . The system of claim 26 , wherein performing attribute provisioning for the identity consumption platform comprises using API's associated with the identity consumption platform.

30 . The system of claim 29 , wherein the APIs associated with the identity consumption platform comprise AWS SCIM APIs.

Assignments (4)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT REEL/FRAME 070313/0123 Recorded Nov 3, 2025
From: VCP CAPITAL MARKETS, LLC
To: NAVAN, INC.
Reel/Frame 073511/0861 →
SECURITY INTEREST Recorded Mar 14, 2025
From: NAVAN, INC.
To: CITIBANK, N.A., AS AGENT
Reel/Frame 070519/0109 →
PATENT SECURITY AGREEMENT Recorded Feb 24, 2025
From: NAVAN, INC.
To: VCP CAPITAL MARKETS, LLC [AS ADMINISTRATIVE AGENT]
Reel/Frame 070313/0123 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 26, 2024
From: GUSAKOV, OLEG; IURCHENKO, IURII
To: NAVAN, INC.
Reel/Frame 068711/0268 →