IP Library › Granted Patent US 12,549,538
Granted Patent B2
US 12,549,538 · App. 18/217,232 · Granted Feb 10, 2026

Native agentless efficient queries

Inventors: Tomer Dayan (Petach-Tikva, IL); Ofir Iluz (Petach-Tikva, IL); Yaron Nisimov (Petach-Tikva, IL)
Assignee: CyberArk Software Ltd.
H04L63/083H04L63/102H04L63/108
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,549,538
App. No.
18/217,232
Granted
Feb 10, 2026
Kind
B2
Abstract

Disclosed embodiments relate to systems and methods for providing agentless efficient queries for native network resource connections. Techniques include receiving a request from a network identity to access an original network resource; authenticating the network identity using a native client and communication protocol; authorizing the network identity based on one or more access policy; identifying an account having a secret, based on the one or more access policy; accessing the original network resource using the secret; enabling the network identity to access the original network resource using the account using the native client and communication protocol; creating at least one new entity associated with the original network resource; adapting the request to use the at least one new entity; and performing the request using the at least one new entity.

Claims (38)

1 . A non-transitory computer readable medium including instructions that, when executed by at least one processor, cause the at least one processor to perform operations for providing agentless efficient queries for native network resource connections, the operations comprising:

receiving a request from a network identity to access an original network resource;

authenticating the network identity using a native client and communication protocol, wherein the native client is configured for communicating transparently with the original network resource;

authorizing the network identity based on one or more access policy, the one or more access policy comprising rules for accessibility of the original network resource;

identifying an account having a secret, based on the one or more access policy;

accessing the original network resource using the secret;

enabling the network identity to access the original network resource using the account using the native client and communication protocol;

creating at least one new entity associated with the original network resource, the new entity being configured to replicate at least a portion of the original network resource;

adapting the request to use the at least one new entity, wherein adapting the request includes replacing a target associated with the original network resource with a corresponding target associated with the at least one new entity; and

performing the request using the at least one new entity.

2 . The non-transitory computer readable medium of claim 1 , wherein the at least one new entity is created based on the request from the network identity.

3 . The non-transitory computer readable medium of claim 1 , wherein the at least one new entity is created based on an action history of the original network resource.

4 . The non-transitory computer readable medium of claim 3 , wherein creating the at least one new entity includes profiling the action history on the original network resource to create the new entity.

5 . The non-transitory computer readable medium of claim 1 , wherein creating the at least one new entity includes creating a new resource in the original network resource.

6 . The non-transitory computer readable medium of claim 1 , wherein the at least one new entity is permanent.

7 . The non-transitory computer readable medium of claim 5 , wherein the at least one new entity is ephemeral.

8 . The non-transitory computer readable medium of claim 7 , wherein the operations further comprise decommissioning the at least one new entity.

9 . The non-transitory computer readable medium of claim 8 , wherein the at least one new entity is decommissioned based on an elapsed period of time.

10 . The non-transitory computer readable medium of claim 8 , wherein the at least one new entity is decommissioned based on the request being performed.

11 . The non-transitory computer readable medium of claim 1 , wherein the operations further comprise receiving a result of the request being performed on the at least one new entity, wherein the at least one new entity is configured such that the received result is the same as a result that would be received if the request was performed on the original network resource.

12 . The non-transitory computer readable medium of claim 1 , wherein the request from the network identity further comprises a request to perform one or more actions on the original network resource.

13 . The non-transitory computer readable medium of claim 1 , wherein adapting the request to use the at least one new entity includes altering at least one aspect of the request to generate an adapted request and wherein the request is performed using the adapted request.

14 . The non-transitory computer readable medium of claim 1 , wherein the request indicates the target associated with the original network resource.

15 . The non-transitory computer readable medium of claim 1 , wherein creating the at least one new entity associated with the original network resource includes generating at least one enhancement to the original network resource.

16 . The non-transitory computer readable medium of claim 14 , wherein the at least one enhancement includes at least one of an index of the original network resource, a tabulated form of at least a portion of the original network resource, a primary key for the original network resource, a foreign key for the original network resource, a modification to the original network resource, or metadata associated with the original network resource.

17 . A method for providing agentless efficient queries for native network resource connections, the method comprising:

receiving a request from a network identity to access an original network resource;

authenticating the network identity using a native client and communication protocol, wherein the native client is configured for communicating transparently with the original network resource;

authorizing the network identity based on one or more access policy, the one or more access policy comprising rules for accessibility of the original network resource;

identifying an account having a secret, based on the one or more access policy;

accessing the original network resource using the secret;

enabling the network identity to access the original network resource using the account using the native client and communication protocol;

creating at least one new entity associated with the original network resource, the new entity being configured to replicate at least a portion of the original network resource;

adapting the request to use the at least one new entity, wherein adapting the request includes replacing a target associated with the original network resource with a corresponding target associated with the at least one new entity; and

performing the request using the at least one new entity.

18 . The method of claim 17 , wherein the at least one new entity is created based on the request from the network identity.

19 . The method of claim 17 , wherein the at least one new entity is ephemeral.

20 . The method of claim 17 , wherein the at least one new entity is permanent.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2023
From: DAYAN, TOMER; ILUZ, OFIR; NISIMOV, YARON
To: CYBERARK SOFTWARE LTD.
Reel/Frame 064132/0582 →
Continuity (2)
Continuation In Part 18059780 · Nov 29, 2022
Related Publication 20240179143A1 · May 30, 2024
References Cited (11)
US 7346617B2 · Wong · 2008 [cited by examiner]
US 8099758B2 · Schaefer · 2012 [cited by examiner]
US 10116658B2 · Sade · 2018 [cited by examiner]
US 10681547B1 · Yang · 2020 [cited by applicant]
US 20160164878A1 · Nakano · 2016 [cited by applicant]
US 20170208055A1 · Golwalkar et al. · 2017 [cited by applicant]
US 20210119764A1 · Meghji · 2021 [cited by applicant]
US 20210250422A1 · Mladin et al. · 2021 [cited by applicant]
US 20220109675A1 · Williams et al. · 2022 [cited by applicant]
US 20220188448A1 · Levit et al. · 2022 [cited by applicant]
US 20220255931A1 · Avetisov et al. · 2022 [cited by applicant]