IP Library Granted Patent US 12,423,402
Granted Patent B2
US 12,423,402 · App. 17/814,315 · Granted Sep 23, 2025

Techniques for credential and identity synchronization

Inventor: Jonathan Roman Todd (Boulder, CO)
G06F21/44H04L63/08H04W12/068
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,423,402
App. No.
17/814,315
Granted
Sep 23, 2025
Kind
B2
Abstract

Methods, systems, and devices for managing identifying information are described. A software platform (e.g., a wallet) may access an application to update a credential based on an integration parameter for the software platform, which may correspond to how the software platform may access the application. For example, the software platform may receive a request (e.g., from a user) to update the credential. The software platform may identify an association between the software platform and the application. Based on the association between the software platform and the application, the software platform may determine an integration parameter available to the software platform for communicating with the application. The software platform may access the application based on the integration parameter, for example using authentication information stored at the software platform, and update the credential associated with the application.

Claims (58)

1. A method for managing identifying information, comprising:

receiving, at a software platform, a request to update a credential associated with an application, wherein:

the software platform comprises a plurality of associations with a plurality of applications including the application, and

the plurality of associations correspond to a plurality of access types by which the software platform accesses respective applications of the plurality of applications;

determining an integration parameter for the software platform to communicate with the application based at least in part on an association of the plurality of associations between the software platform and the application, wherein the integration parameter indicates instructions to access the application in accordance with an access type of the plurality of access types corresponding to the association between the software platform and the application;

accessing the application via the software platform based at least in part on the instructions indicated by the determined integration parameter and authentication information stored at the software platform; and

updating the credential based at least in part on accessing the application.

2. The method of claim 1 , further comprising:

identifying a prior access of the application, wherein the request to update the credential is received based at least in part on identifying the prior access.

3. The method of claim 1 , further comprising:

identifying the credential in a database, wherein the request to update the credential is received based at least in part on identifying the credential in the database.

4. The method of claim 1 , wherein updating the credential comprises:

deactivating an account at the application, the account associated with a user of the software platform.

5. The method of claim 4 , wherein the account is deactivated based at least in part on a duration since a prior access of the application.

6. The method of claim 1 , wherein the credential comprises personal information associated with a user of the software platform, a password associated with accessing the application, an authentication factor associated with accessing the application, or any combination thereof.

7. The method of claim 1 , wherein:

the association between the software platform and the application is based at least in part on a software development kit (SDK) of the software platform that is included with the application; and

the integration parameter is determined based at least in part on identifying the SDK, wherein inclusion of the SDK with the application is indicative of the access type.

8. The method of claim 1 , wherein:

the association between the software platform and the application is based at least in part on an application programming interface (API) of the software platform that is configured to communicate with the application; and

the integration parameter is determined based at least in part on identifying the API, wherein configuration of the API is indicative of the access type.

9. The method of claim 1 , wherein:

the association between the software platform and the application is based at least in part on a plugin of the software platform that is configured to communicate with the application; and

the integration parameter is determined based at least in part on identifying the plugin, wherein configuration of the plugin is indicative of the access type.

10. The method of claim 1 , wherein:

the association between the software platform and the application is based at least in part on a customer identity and access management (CIAM) relationship between the software platform and the application; and

the integration parameter is determined based at least in part on identifying the CIAM relationship, wherein the CIAM relationship is indicative of the access type.

11. An apparatus for managing identifying information, comprising:

a processor;

memory coupled with the processor; and

instructions stored in the memory and executable by the processor to cause the apparatus to:

receive, at a software platform, a request to update a credential associated with an application, wherein:

the software platform comprises a plurality of associations with a plurality of applications including the application, and

the plurality of associations correspond to a plurality of access types by which the software platform accesses respective applications of the plurality of applications;

determine an integration parameter for the software platform to communicate with the application based at least in part on an association of the plurality of associations between the software platform and the application, wherein the integration parameter indicates instructions to access the application in accordance with an access type of the plurality of access types corresponding to the association between the software platform and the application;

access the application via the software platform based at least in part on the instructions indicated by the determined integration parameter and authentication information stored at the software platform; and

update the credential based at least in part on accessing the application.

12. The apparatus of claim 11 , wherein the instructions are further executable by the processor to cause the apparatus to:

identify a prior access of the application, wherein the request to update the credential is received based at least in part on identifying the prior access.

13. The apparatus of claim 11 , wherein the instructions are further executable by the processor to cause the apparatus to:

identify the credential in a database, wherein the request to update the credential is received based at least in part on identifying the credential in the database.

14. The apparatus of claim 11 , wherein the instructions to update the credential are executable by the processor to cause the apparatus to:

deactivate an account at the application, the account associated with a user of the software platform.

15. The apparatus of claim 14 , wherein the account is deactivated based at least in part on a duration since a prior access of the application.

16. The apparatus of claim 11 , wherein the credential comprises personal information associated with a user of the software platform, a password associated with accessing the application, an authentication factor associated with accessing the application, or any combination thereof.

17. A non-transitory computer-readable medium storing code for managing identifying information, the code comprising instructions executable by a processor to:

receive, at a software platform, a request to update a credential associated with an application, wherein:

the software platform comprises a plurality of associations with a plurality of applications including the application, and

the plurality of associations correspond to a plurality of access types by which the software platform accesses respective applications of the plurality of applications;

determine an integration parameter for the software platform to communicate with the application based at least in part on an association of the plurality of associations between the software platform and the application, wherein the integration parameter indicates instructions to access the application in accordance with an access type of the plurality of access types corresponding to the association between the software platform and the application;

access the application via the software platform based at least in part on the instructions indicated by the determined integration parameter and authentication information stored at the software platform; and

update the credential based at least in part on accessing the application.

18. The non-transitory computer-readable medium of claim 17 , wherein the instructions are further executable by the processor to:

identify a prior access of the application, wherein the request to update the credential is received based at least in part on identifying the prior access.

19. The non-transitory computer-readable medium of claim 17 , wherein the instructions are further executable by the processor to:

identify the credential in a database, wherein the request to update the credential is received based at least in part on identifying the credential in the database.

20. The non-transitory computer-readable medium of claim 17 , wherein the instructions to update the credential are executable by the processor to:

deactivate an account at the application, the account associated with a user of the software platform.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2022
From: TODD, JONATHAN ROMAN
To: OKTA, INC.
Reel/Frame 060593/0756 →
Continuity (2)
Provisional Application 63363909 · Apr 29, 2022
Related Publication 20230351004A1 · Nov 2, 2023
References Cited (37)
US 9424419B1 · Kruse · 2016 [cited by examiner]
US 9558341B1 · Allababidi · 2017 [cited by examiner]
US 10475273B2 · Campero · 2019 [cited by examiner]
US 10825001B2 · Purves · 2020 [cited by examiner]
US 11183294B2 · Sargent · 2021 [cited by examiner]
US 11258875B2 · Kouru · 2022 [cited by examiner]
US 11438764B2 · Avetisov · 2022 [cited by examiner]
US 11836241B1 · Unnikrishnan · 2023 [cited by examiner]
US 20020027713A1 · Turnbull · 2002 [cited by examiner]
US 20050027713A1 · Cameron · 2005 [cited by examiner]
US 20070130463A1 · Law · 2007 [cited by examiner]
US 20080126145A1 · Rackley, III · 2008 [cited by examiner]
US 20100095372A1 · Hodgkinson · 2010 [cited by examiner]
US 20110093937A1 · Mantle · 2011 [cited by examiner]
US 20130086658A1 · Kottahachchi · 2013 [cited by examiner]
US 20130086669A1 · Sondhi · 2013 [cited by examiner]
US 20140250006A1 · Makhotin · 2014 [cited by examiner]
US 20150286816A1 · Adler · 2015 [cited by examiner]
US 20170011214A1 · Cavanagh · 2017 [cited by examiner]
US 20170061427A1 · Sharma · 2017 [cited by examiner]
US 20170200151A1 · Bruno · 2017 [cited by examiner]
US 20180108008A1 · Chumbley · 2018 [cited by examiner]
US 20180176195A1 · Pangam · 2018 [cited by examiner]
US 20190019179A1 · Mtaza · 2019 [cited by examiner]
US 20190028447A9 · Pangam · 2019 [cited by examiner]
US 20190050557A1 · Martin · 2019 [cited by examiner]
US 20200265417A1 · Bruno · 2020 [cited by examiner]
US 20210194884A1 · Xie · 2021 [cited by examiner]
US 20210209205A1 · Baldwin · 2021 [cited by examiner]
US 20210377252A1 · Monro · 2021 [cited by examiner]
US 20220070000A1 · Gondza · 2022 [cited by examiner]
US 20230015523A1 · Mani · 2023 [cited by examiner]
US 20230179590A1 · Kim · 2023 [cited by examiner]
WO WO2014210227A1 · 2014 [cited by examiner]
AlSharqawi et al.; “Challenges on Identity Management Iot Environment—Survey”, 2020, International Conference on Computing and Information Technology, vol. 02, Issue: ICCIT—1441, pp. 123-127. (Year: 2020). [cited by examiner]
Buecker et al.; “Integrated Identity and Access Management Architectural Patterns”, 2008, IBM.com/redbooks, pp. 1-44. (Year: 2008). [cited by examiner]
Buecker et al.; “Integrated Identity and Access Management Architectural Patterns” 2008, IBM Redbooks, pp. 1-44. (Year: 2008). [cited by examiner]