IP Library › Granted Patent US 12,592,943
Granted Patent B2
US 12,592,943 · App. 18/887,397 · Granted Mar 31, 2026

Session analysis for identity posture management and security

Inventors: Kartik Kumar Chatnalli Deshpande Sridhar (Saratoga, CA); Abhay Sudhakar Kulkarni (Saratoga, CA); Deepak Swaminathan (Fremont, CA)
Assignee: WideField Security Inc.
H04L63/1416H04L63/1441H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,592,943
App. No.
18/887,397
Granted
Mar 31, 2026
Kind
B2
Abstract

Methods, systems, and computer programs are presented for stitching a meta session with an underlying trail fragmented across multiple distributed sessions. One method includes receiving telemetry signals from entities in a session environment that includes at least one identity of a user engaged with applications via respective meta sessions. An underlying trail for each meta session is determined, where the underlying trail is fragmented across two or more sessions with two or more entities. For a first meta session with a first application for the identity of the user, several operations are performed, including correlating a signal hierarchy based on the telemetry signals; constructing, based on the correlated signal hierarchy, a session hierarchy underlying the first meta session distributed across the one or more entities; determining a posture of the first meta session based on the constructed session hierarchy; and enforcing a security policy based on the determined posture.

Claims (49)

1 . A method, for stitching together a meta session with an underlying trail fragmented across multiple distributed sessions, comprising:

receiving telemetry signals from a plurality of entities in a session environment, wherein the session environment includes at least one identity of a user engaged with respective applications via respective meta sessions;

determining an underlying trail for each meta session, the underlying trail being fragmented across two or more sessions with two or more entities in the plurality of entities; and

for a first meta session with a first application associated with the identity of the user, perform operations comprising:

correlating a signal hierarchy based on the telemetry signals;

constructing, based on the correlated signal hierarchy, a session hierarchy underlying the first meta session distributed across the plurality of entities;

determining a posture of the first meta session based on the constructed session hierarchy; and

enforcing a security policy based on the determined posture.

2 . The method as recited in claim 1 , wherein the telemetry signals specify risky third-party applications, wherein the risky third-party applications are identified based on evaluating third-party applications on different application stores, the method further comprising:

classifying as the risky third-party applications the third-party applications that lack enterprise-grade compliance, do not provide data residency, or use customer data to train artificial intelligence models.

3 . The method as recited in claim 1 , further comprising:

detecting, based on audit logs, events during sessions in the session hierarchy underlying the first meta session.

4 . The method as recited in claim 3 , wherein the audit logs specify activities detected during the sessions in the session hierarchy underlying the first meta session.

5 . The method as recited in claim 1 , wherein telemetry signal categories include timestamp, user, groups, roles, application, internet protocol (IP), device, activity, and session.

6 . The method as recited in claim 5 , wherein an application telemetry signal category includes “app name” telemetry signals, “app identifier (ID)” telemetry signals, and “app instance identifier (ID)” telemetry signals.

7 . The method as recited in claim 1 , wherein the plurality of entities includes the applications, and wherein the plurality of entities includes one or more endpoints used by the identity of the user to engage with the applications.

8 . The method as recited in claim 1 , wherein the plurality of entities includes one or more identity and access management (IAM) services.

9 . The method as recited in claim 1 , wherein the plurality of entities includes one or more enterprise mobility management (EMM) services.

10 . The method as recited in claim 1 , wherein the plurality of entities includes one or more mobile device management (VIDM) services, secure access service edge (SASE) services, or one or more cloud access security broker (CASB) services.

11 . A system comprising:

a memory comprising instructions; and

one or more computer processors, the instructions, when executed by the one or more computer processors, causing the system to perform operations comprising:

receiving telemetry signals from a plurality of entities in a session environment, wherein the session environment includes at least one identity of a user engaged with respective applications via respective meta sessions;

determining an underlying trail for each meta session, the underlying trail being fragmented across two or more sessions with two or more entities in the plurality of entities; and

for a first meta session with a first application associated with the identity of the user, perform operations comprising:

correlating a signal hierarchy based on the telemetry signals;

constructing, based on the correlated signal hierarchy, a session hierarchy underlying the first meta session distributed across the plurality of entities;

determining a posture of the first meta session based on the constructed session hierarchy; and

enforcing a security policy based on the determined posture.

12 . The system as recited in claim 11 , wherein the telemetry signals specify risky third-party applications, wherein the risky third-party applications are identified based on evaluating third-party applications on different application stores, wherein the instructions further cause the one or more computer processors to perform operations comprising:

classifying as the risky third-party applications the third-party applications that lack enterprise-grade compliance, do not provide data residency, or use customer data to train artificial intelligence models.

13 . The system as recited in claim 11 , wherein the instructions further cause the one or more computer processors to perform operations comprising:

detecting, based on audit logs, events during sessions in the session hierarchy underlying the first meta session.

14 . The system as recited in claim 13 , wherein the audit logs specify activities detected during the sessions in the session hierarchy underlying the first meta session.

15 . The system as recited in claim 11 , wherein telemetry signal categories include timestamp, user, groups, roles, application, internet protocol (IP), device, activity, and session.

16 . A non-transitory machine-readable storage medium including instructions that, when executed by a machine, cause the machine to perform operations comprising:

receiving telemetry signals from a plurality of entities in a session environment, wherein the session environment includes at least one identity of a user engaged with respective applications via respective meta sessions;

determining an underlying trail for each meta session, the underlying trail being fragmented across two or more sessions with two or more entities in the plurality of entities; and

for a first meta session with a first application associated with the identity of the user, perform operations comprising:

correlating a signal hierarchy based on the telemetry signals;

constructing, based on the correlated signal hierarchy, a session hierarchy underlying the first meta session distributed across the plurality of entities;

determining a posture of the first meta session based on the constructed session hierarchy; and

enforcing a security policy based on the determined posture.

17 . The non-transitory machine-readable storage medium as recited in claim 16 , wherein the telemetry signals specify risky third-party applications, wherein the risky third-party applications are identified based on evaluating third-party applications on different application stores, wherein the machine further performs operations comprising:

classifying as the risky third-party applications the third-party applications that lack enterprise-grade compliance, do not provide data residency, that use unnecessarily broad scopes and permissions, that have unsafe sub-processors, or use customer data to train artificial intelligence models.

18 . The non-transitory machine-readable storage medium as recited in claim 16 , wherein the machine further performs operations comprising:

detecting, based on audit logs, events during sessions in the session hierarchy underlying the first meta session.

19 . The non-transitory machine-readable storage medium as recited in claim 18 , wherein the audit logs specify activities detected during the sessions in the session hierarchy underlying the first meta session.

20 . The non-transitory machine-readable storage medium as recited in claim 16 , wherein telemetry signal categories include timestamp, user, groups, roles, application, internet protocol (IP), device, activity, and session.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 14, 2024
From: SRIDHAR, KARTIK KUMAR CHATNALLI DESHPANDE; KULKARNI, ABHAY SUDHAKAR; SWAMINATHAN, DEEPAK
To: WIDEFIELD SECURITY INC.
Reel/Frame 068889/0377 →
Continuity (3)
Provisional Application 63539673 · Sep 21, 2023
Provisional Application 63539677 · Sep 21, 2023
Related Publication 20250106261A1 · Mar 27, 2025
References Cited (4)
US 20210105291A1 · Ryan · 2021 [cited by examiner]
US 20240106855A1 · Sundararajan · 2024 [cited by examiner]
US 20240356957A1 · Bajer · 2024 [cited by examiner]
US 20250106227A1 · Sridhar et al. · 2025 [cited by applicant]