Patents by Inventor Vadim Lander

Vadim Lander has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 9838376
    Abstract: A system provides cloud-based identity and access management. The system receives a request for performing an identity management service, where the request includes a call to an application programming interface (“API”) that identifies the identity management service and a microservice configured to perform the identity management service. The system authenticates the request, accesses the microservice, and performs the identity management service by the microservice.
    Type: Grant
    Filed: March 6, 2017
    Date of Patent: December 5, 2017
    Assignee: Oracle International Corporation
    Inventors: Vadim Lander, Damien Carru, Gary P. Cole, Ajay Sondhi, Gregg Wilson
  • Publication number: 20170331832
    Abstract: A system for authorizing access to a resource receives a request for an access token that corresponds to the resource, where the request includes user information and application information. The user information includes a role of the user and the application information includes a role of the application. The system evaluates the request by computing scopes for the access token, including determining an intersection between the user information and the application information. The system then provides the access token that includes the computed scopes, the scopes being based at least on the role of the user and the role of the application.
    Type: Application
    Filed: March 30, 2017
    Publication date: November 16, 2017
    Inventors: VADIM LANDER, Hari SASTRY, Sreedhar KATTI, Sirish V. VEPA, Swathi Vinayak SHENOY
  • Publication number: 20170331829
    Abstract: A system provides cloud-based identity and access management. The system receives a request from a client for obtaining an access token for a user to access a resource. The system determines, based on the request, a tenancy of the client, a tenancy of the user, and a tenancy of the resource. The system accesses a microservice based on the request, and performs an identity management service by the microservice based on the request, where the identity management service includes generating the access token that identifies the tenancy of the resource and the tenancy of the user.
    Type: Application
    Filed: March 27, 2017
    Publication date: November 16, 2017
    Inventors: Vadim LANDER, Ajay SONDHI
  • Publication number: 20170331802
    Abstract: Key generation and roll over is provided for a cloud based identity management system. A key set is generated that includes a previous key and expiration time, a current key and expiration time, and a next key and expiration time, and stores the key set in a database table and a memory cache associated with the database table. At the current key expiration time, the key set is rolled over, including retrieving the key set from the database table, updating the previous key and expiration time with the current key and expiration time, updating the current key and expiration time with the next key and expiration time, generating a new key and expiration time, updating the next key and expiration time with the new key and expiration time, and updating the key set in the database table and the memory cache.
    Type: Application
    Filed: May 8, 2017
    Publication date: November 16, 2017
    Inventors: Rakesh Keshava, Sreedhar Katti, Sirish Vepa, Vadim Lander, Prateek Mishra
  • Publication number: 20170331812
    Abstract: A system provides cloud-based identity and access management. The system receives a request for performing an identity management service, where the request includes a call to an application programming interface (“API”) that identifies the identity management service and a microservice configured to perform the identity management service. The system authenticates the request, accesses the microservice, and performs the identity management service by the microservice.
    Type: Application
    Filed: March 6, 2017
    Publication date: November 16, 2017
    Inventors: Vadim LANDER, Damien CARRU, Gary P. COLE, Ajay SONDHI, Gregg WILSON
  • Publication number: 20170331813
    Abstract: A system provides cloud-based identity and access management. The system receives a request to perform an identity management service, and accesses a microservice based on the identity management service. The system determines one or more real-time tasks and one or more near-real-time tasks that are required to be executed to complete the identity management task. The system synchronously executes the one or more real-time tasks by the microservice, and sends the one or more near-real-time tasks to a queue to be asynchronously executed.
    Type: Application
    Filed: March 6, 2017
    Publication date: November 16, 2017
    Inventors: Vadim LANDER, Damien CARRU, Gary P. COLE, Ajay SONDHI, Gregg WILSON
  • Publication number: 20170329957
    Abstract: A system for authorizing access to a resource associated with a tenancy in an identity management system that includes a plurality of tenancies receives an access token request for an access token that corresponds to the resource, the request including user information and application information, the user information including roles of a user and the application information including roles of the application. The system evaluates the access token request by computing dynamic roles and corresponding dynamic scopes for the access token including a second intersection between the dynamic roles of the user and the dynamic roles of the application. The system then provides the access token that includes the computed static scopes, where the scopes are based at least on the roles of the user and the roles of the application, and further including the computed dynamic roles and corresponding dynamic scopes.
    Type: Application
    Filed: May 9, 2017
    Publication date: November 16, 2017
    Inventors: Sirish V. VEPA, Sreedhar KATTI, Maheshkumar Shivlal DHADUK, Vadim LANDER
  • Publication number: 20170331791
    Abstract: A system provides cloud-based identity and access management. The system receives a request by a web gate for an identity management service for reaching an application, and determines a tenancy from a header value of the request. The system looks up a policy configured to be applied for the tenancy, and applies the policy to the request. The system then sends the request to a microservice based on a result of the applying of the policy to the request, where the microservice performs the identity management service for reaching the application.
    Type: Application
    Filed: May 10, 2017
    Publication date: November 16, 2017
    Inventors: Stephan WARDELL, Andrew B. FOLKINS, Vadim LANDER, Prateek MISHRA, Rich LEVINSON, Cory WOMACKS, Dino E. CUTHBERT
  • Patent number: 7987495
    Abstract: The system and method described herein provides multi-context security policy management in a networked computing infrastructure. The system and method may generate a plurality of security contexts regarding different security characteristics of the communication between a computing device and the networked computing infrastructure. The computing device then requests access to at least one specific element of the computing infrastructure. The security policy definitions of the at least one specific element are compared with one or more of the security contexts to determine whether access to the specific elements should be granted.
    Type: Grant
    Filed: December 26, 2007
    Date of Patent: July 26, 2011
    Assignee: Computer Associates Think, Inc.
    Inventors: Sophia Maler, Vadim Lander, Andrew Rappaport
  • Publication number: 20080155649
    Abstract: The invention provides systems and methods for multi-context security policy management in a networked computing infrastructure. The invention includes generating a plurality of security contexts regarding different security characteristics of the communication between a computing device and the networked computing infrastructure. The computing device then requests access to at least one specific element of the computing infrastructure. The security policy definitions of the at least one specific element are compared with one or more of the security contexts to determine whether access to the specific elements should be granted.
    Type: Application
    Filed: December 26, 2007
    Publication date: June 26, 2008
    Inventors: SOPHIA MALER, VADIM LANDER, ANDREW RAPPAPORT
  • Patent number: 7350229
    Abstract: A method and apparatus for a network-wide authentication and authorization mapping system for a network is provided. The global authentication and authorization mapping system enables a seamless transition from one web-based application in the network configuration to another web-based application in the network configuration, including a single sign-on capability for users. There are no localized security enforcement processes required to further authenticate a user.
    Type: Grant
    Filed: October 4, 2001
    Date of Patent: March 25, 2008
    Assignee: Netegrity, Inc.
    Inventor: Vadim Lander