IP Library Granted Patent US 11,526,587
Granted Patent B2
US 11,526,587 · App. 16/568,656 · Granted Dec 13, 2022

Privileged access management for applications

Inventors: András Pintér (Veszprém, HU); László Zana (Balatonfüred, HU)
Assignee: One Identity LLC
G06F21/31G06F9/451G06F16/954G06F16/986H04L63/0281H04L63/102
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,526,587
App. No.
16/568,656
Granted
Dec 13, 2022
Kind
B2
Abstract

A user of a client can access an application using privileged credentials without having direct access to or knowledge of the privileged credentials. The user's access to the application can also be monitored using a custom protocol including recording the user's interactions with the application while logged in with the privileged credentials.

Claims (56)

1. A method for implementing privileged access management comprising:

receiving, from a client, a request of a user to access an application, the request including or being associated with user credentials of the user;

evaluating the user credentials that are included in or associated with the request to determine that the user is authorized to access the application using privileged credentials that are different from the user credentials and that the user does not have access to;

in response to the request, executing the application on a container including logging in to the application using the privileged credentials;

creating, from a user interface of the application, protocol frames that define images of the user interface by accessing frames that the application generates to represent the user interface and comparing corresponding microblocks in the frames to identify changed microblocks, wherein each microblock encompasses multiple pixels of the frames, and wherein the protocol frames comprise a difference matrix that identifies microblocks that have changed and a payload that includes pixel values for each of the multiple pixels within each changed microblock;

sending, by the container and to the client, protocol communications containing the protocol frames to cause the images of the user interface to be displayed on the client;

receiving, by the container and from the client, additional protocol communications that define user input to the images that were displayed on the client; and

causing corresponding user input to be generated on the container and provided to the application.

2. The method of claim 1 , wherein the protocol communications containing the protocol frames are sent to the client via a proxy.

3. The method of claim 2 , further comprising:

forwarding, by the proxy, the protocol communications containing the protocol frames to a server.

4. The method of claim 3 , further comprising:

storing, by the server, the protocol frames in a session log.

5. The method of claim 1 , wherein the application comprises a web site and wherein executing the application includes navigating the browser to the website and then logging in to the website using the privileged credentials.

6. The method of claim 1 , further comprising:

receiving, at a website executing on the client, the protocol frames; and

for each received protocol frame, employing the protocol frame to update an image of the user interface that is currently stored on the client; and

causing the updated image to be displayed in an HTML5 canvas.

7. The method of claim 6 , further comprising:

detecting, by the website, user input to the HTML5 canvas;

wherein the website sends the additional protocol communications in response to the detected user input to the HTML5 canvas.

8. The method of claim 7 , wherein the user input defined in the additional protocol communications identifies a mouse position over the HTML5 canvas.

9. One or more computer storage media storing computer executable instructions which when executed implement a method for enabling a user to access an application using privileged credentials without having access to the privileged credentials, the method comprising:

receiving, from a user of a client, a request to access an application using privileged credentials that the user does not have access to;

creating a container that includes the application;

executing the application on the container including logging in to the application using the privileged credentials;

during a login process, modifying the application to prevent one or more user interface elements pertaining to input of the privileged credentials from being included in the user interface;

creating, on the container, a first protocol frame that defines an image of a user interface of the application during the login process such that the image of the user interface that the first protocol frame defines does not include the one or more user interface elements;

sending the protocol frame to the client; and

processing, on the client, the protocol frame to display the image of the user interface of the application.

10. The computer storage media of claim 9 , further comprising:

creating, on the container, a second protocol frame that defines the image of the user interface of the application;

sending the second protocol frame to a server; and

storing the second protocol frame in a session log.

11. The computer storage media of claim 10 , wherein creating the first protocol frame comprises excluding a mouse cursor while creating the second protocol frame comprises including the mouse cursor.

12. The computer storage media of claim 9 , wherein the application comprises a website and wherein executing the application includes navigating a browser to the website and then logging in to the website using the privileged credentials.

13. The computer storage media of claim 9 , wherein the image of the user interface that the first protocol frame defines includes a user interface element for receiving input required to log in using the privileged credentials.

14. The computer storage media of claim 9 , wherein processing the protocol frame to display the image of the user interface of the application comprises displaying the image in an HTML5 canvas.

15. The computer storage media of claim 9 , wherein the first protocol frame defines the image as differences relative to a previous image.

16. A method for enabling a user to access an application using privileged credentials without having access to the privileged credentials, the method comprising:

receiving, from a user of a client, a request to access an application using privileged credentials that the user does not have access to, the request including or being associated with user credentials of the user;

evaluating the user credentials that are included in or associated with the request to determine that the user is authorized to access the application using privileged credentials that are different from the user credentials and that the user does not have access to;

creating a container that includes the application;

executing the application on the container including logging in to the application using the privileged credentials;

while the application is executing on the container, creating and sending protocol frames to the client which define images of the application's user interface;

employing the protocol frames to display the images of the application's user interface on the client;

routing the protocol frames to a server for storage in a session log;

receiving a request to replay the user's access to the application; and

employing the protocol frames stored in the session log to sequentially display the images of the application's user interface to thereby replay the user's access to the application;

wherein the protocol frames sent to the server include a cursor of the container's mouse while the protocol frames sent to the client do not.

17. The method of claim 16 , further comprising:

sending, to the server, one or more events that occurred during the user's access to the application; and

storing the one or more events in the session log.

18. The method of claim 16 , wherein the protocol frames are sent to the client via a proxy.

19. The method of claim 16 , wherein creating the protocol frames comprises accessing frames that the application generates to represent the user interface and comparing corresponding microblocks in the frames to identify changed microblocks.

20. The method of claim 19 , wherein each microblock encompasses multiple pixels of the frames, and wherein the protocol frames comprise a difference matrix that identifies microblocks that have changed and a payload that includes pixel values for each of the multiple pixels within each changed microblock.

Assignments (12)
RELEASE OF SECURITY INTEREST Recorded Nov 19, 2025
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073606/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 18, 2025
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.
Reel/Frame 073613/0326 →
RELEASE OF SECURITY INTEREST Recorded Jun 6, 2025
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: ONE IDENTITY LLC (N/K/A OI HOLDINGS LLC); ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
Reel/Frame 071350/0897 →
RELEASE OF SECURITY INTEREST Recorded Jun 6, 2025
From: GOLDMAN SACHS BANK USA
To: ONE IDENTITY LLC (N/K/A OI HOLDINGS LLC); ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
Reel/Frame 071350/0827 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 2, 2025
From: ONE IDENTITY LLC
To: ONE IDENTITY II, LLC
Reel/Frame 071284/0085 →
CHANGE OF NAME Recorded Jun 2, 2025
From: ONE IDENTITY V, LLC
To: ONE IDENTITY LLC
Reel/Frame 071493/0775 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 2, 2025
From: ONE IDENTITY II, LLC
To: ONE IDENTITY III, LLC
Reel/Frame 071284/0175 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 2, 2025
From: ONE IDENTITY III, LLC
To: ONE IDENTITY IV, LLC
Reel/Frame 071284/0207 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 2, 2025
From: ONE IDENTITY IV, LLC
To: ONE IDENTITY V, LLC
Reel/Frame 071284/0268 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 058952/0279 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Feb 2, 2022
From: QUEST SOFTWARE INC.; ANALYTIX DATA SERVICES INC.; BINARYTREE.COM LLC; ERWIN, INC.; ONE IDENTITY LLC; ONELOGIN, INC.; ONE IDENTITY SOFTWARE INTERNATIONAL DESIGNATED ACTIVITY COMPANY
To: GOLDMAN SACHS BANK USA
Reel/Frame 058945/0778 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 12, 2019
From: PINTÉR, ANDRÁS; ZANA, LÁSZLÓ
To: ONE IDENTITY LLC
Reel/Frame 050356/0551 →
Continuity (2)
Provisional Application 62810847 · Feb 26, 2019
Related Publication 20200272712A1 · Aug 27, 2020