Patents Assigned to SailPoint Technologies, Inc.
  • Patent number: 12015675
    Abstract: Systems and methods for embodiments of artificial intelligence systems for identity management are disclosed. Embodiments of the identity management systems disclosed herein may support the creation, association, searching, or visualization of any relevant context to identity management assets for a variety of purposes, including for informing the identity management systems' manual or automated decisions, processes or workflows.
    Type: Grant
    Filed: June 23, 2022
    Date of Patent: June 18, 2024
    Assignee: SailPoint Technologies, Inc.
    Inventors: Norman Anderson, III, Jeffrey Foreman, Amar Rama
  • Patent number: 11811781
    Abstract: Systems and methods for embodiments of artificial intelligence systems for identity management are disclosed. Embodiments of the identity management systems disclosed herein may support the creation, association, searching, or visualization of any relevant context to identity management assets for a variety of purposes, including the creation of nested identity management artifacts in a search index and search syntaxes for querying such nested artifacts.
    Type: Grant
    Filed: May 26, 2022
    Date of Patent: November 7, 2023
    Assignee: SailPoint Technologies, Inc.
    Inventors: Jon-Michael Lees, Pamela Sharon Oren-Artzi, Jeffrey Allen Upton, Norman Anderson, III, Amarnath Ramakrishnan
  • Patent number: 11811833
    Abstract: Systems and methods for embodiments of a graph based artificial intelligence systems for identity management are disclosed. Embodiments of the identity management systems disclosed herein may utilize a network graph approach to analyzing identities, roles, entitlements or other identity management artifacts of a distributed networked enterprise computing environment. Specifically, embodiments of an artificial intelligence based identity management systems may perform predictive modeling for entitlement diffusion or role evolution or other aspects of identity management artifact using network identity graphs.
    Type: Grant
    Filed: October 14, 2021
    Date of Patent: November 7, 2023
    Assignee: Sailpoint Technologies, Inc.
    Inventors: Mohamed M. Badawy, Jostine Fei Ho
  • Patent number: 11740934
    Abstract: Systems and methods for embodiments for load attenuating thread pools (LATP) that may be associated with a service deployed in distributed computer environment, where that service utilizes a shared resource. A LATP includes a thread pool comprising a number of worker threads servicing requests handled by a service that includes such a LATP. The thread pool is managed by a thread pool manager of the LATP that can attenuate (herein used to mean add, remove or leave unchanged) the number of worker threads in the thread pool based on a resource utilization metric associated with the shared resource.
    Type: Grant
    Filed: September 29, 2021
    Date of Patent: August 29, 2023
    Assignee: SailPoint Technologies, Inc.
    Inventor: Adam Ethan Hampton
  • Patent number: 11729169
    Abstract: Systems and methods for network security are provided. Various embodiments issue single use certificates for validating remote endpoints access to the private network. Some embodiments use a triage zone (or triage gateway) to which remote device can calls into using a static issued certificate. However, instead of granting complete access to the virtual private network, the use of this static certificate only grants access to the triage zone where further validation of the endpoint without any access to sensitive content on the private network. The endpoint can be connected to an ID manager within the triage zone. The endpoint can then send the username and password to the ID manager that can create a single use certificate (e.g., valid for a limited period of time). While valid, the single use certificate can be used by the remote device to gain access to the production zone using a VPN tunnel.
    Type: Grant
    Filed: December 17, 2021
    Date of Patent: August 15, 2023
    Assignee: SailPoint Technologies, Inc.
    Inventors: Cameron Williams, Ryan Privette, Christopher Chad Wheeler, Andrew John Cer, Joseph Nathan Zendle
  • Patent number: 11516203
    Abstract: Systems and methods for embodiments of artificial intelligence systems for identity management are disclosed. Specifically, embodiments of an identity management system may provide identity management in association with cloud services used by an enterprise and, in particular, may provide identity management in association with cloud based services that may be accessed through federated access providers.
    Type: Grant
    Filed: July 29, 2020
    Date of Patent: November 29, 2022
    Assignee: SailPoint Technologies, Inc.
    Inventors: Brian Eric Rose, Nicholas Ryan Wellinghoff
  • Patent number: 11516219
    Abstract: Systems and methods for embodiments of a graph based artificial intelligence systems for identity management are disclosed. Embodiments of the identity management systems disclosed herein may utilize a network graph approach to analyzing identities or entitlements of a distributed networked enterprise computing environment. Specifically, in certain embodiments, an artificial intelligence based identity management systems may utilize the peer grouping of an identity graph (or peer grouping of portions or subgraphs thereof) to identify roles from peer groups or the like.
    Type: Grant
    Filed: August 20, 2020
    Date of Patent: November 29, 2022
    Assignee: SailPoint Technologies, Inc.
    Inventors: Mohamed M. Badawy, Jostine Fei Ho
  • Patent number: 11283882
    Abstract: Embodiments of a software services platform with a services infrastructure that allows standalone service to be run in association with other services deployed on a deployment platform. The service infrastructure and services may cooperate to ensure that that communications (associated with the standalone service are routed to that standalone service while communications for other services deployed in the software services may also continue communicating to receive and servicing requests for those services.
    Type: Grant
    Filed: September 8, 2020
    Date of Patent: March 22, 2022
    Assignee: SailPoint Technologies, Inc.
    Inventors: Jeffrey Allen Upton, Vasil Shlapkou
  • Patent number: 10523682
    Abstract: Systems and methods for embodiments of a graph based artificial intelligence systems for identity management are disclosed. Embodiments of the identity management systems disclosed herein may utilize a network graph approach to analyzing identities or entitlements of a distributed networked enterprise computing environment. Specifically, in certain embodiments, an artificial intelligence based identity governance systems may include an intelligent decision support agent to provide an approval or denial recommendation for an access request. To provide an approval or denial recommendation, the intelligent agent may utilize a classifier trained on historical certification data. The intelligent agent may utilize features which represent relevant signals to the approval or denial decision including features that may be associated with a network graph of the identities and entitlements of the enterprise computing environment.
    Type: Grant
    Filed: February 26, 2019
    Date of Patent: December 31, 2019
    Assignee: SailPoint Technologies, Inc.
    Inventors: Mohamed M. Badawy, Jostine Fei Ho, Rajat Kabra
  • Patent number: 10476953
    Abstract: Systems and methods for graph based artificial intelligence systems for identity management systems are disclosed. Embodiments of the identity management systems disclosed herein may utilize a network graph approach to peer grouping of identities of distributed networked enterprise computing environment. Specifically, in certain embodiments, data on the identities and the respective entitlements assigned to each identity as utilized in an enterprise computer environment may be obtained by an identity management system. A network identity graph may be constructed using the identity and entitlement data. The identity graph can then be clustered into peer groups of identities. The peer groups of identities may be used by the identity management system and users thereof in risk assessment or other identity management tasks.
    Type: Grant
    Filed: July 1, 2019
    Date of Patent: November 12, 2019
    Assignee: SailPoint Technologies, Inc.
    Inventors: Mohamed M. Badawy, Jostine Fei Ho
  • Patent number: 10476952
    Abstract: Systems and methods for graph based artificial intelligence systems for identity management systems are disclosed. Embodiments of the identity management systems disclosed herein may utilize a network graph approach to peer grouping of identities of distributed networked enterprise computing environment. Specifically, in certain embodiments, data on the identities and the respective entitlements assigned to each identity as utilized in an enterprise computer environment may be obtained by an identity management system. A network identity graph may be constructed using the identity and entitlement data. The identity graph can then be clustered into peer groups of identities. The peer groups of identities may be used by the identity management system and users thereof in risk assessment or other identity management tasks.
    Type: Grant
    Filed: May 21, 2019
    Date of Patent: November 12, 2019
    Assignee: SailPoint Technologies, Inc.
    Inventors: Mohamed M. Badawy, Jostine Fei Ho
  • Patent number: 10341430
    Abstract: Systems and methods for graph based artificial intelligence systems for identity management systems are disclosed. Embodiments of the identity management systems disclosed herein may utilize a network graph approach to peer grouping of identities of distributed networked enterprise computing environment. Specifically, in certain embodiments, data on the identities and the respective entitlements assigned to each identity as utilized in an enterprise computer environment may be obtained by an identity management system. A network identity graph may be constructed using the identity and entitlement data. The identity graph can then be clustered into peer groups of identities. The peer groups of identities may be used by the identity management system and users thereof in risk assessment or other identity management tasks.
    Type: Grant
    Filed: November 27, 2018
    Date of Patent: July 2, 2019
    Assignee: SailPoint Technologies, Inc.
    Inventors: Mohamed M. Badawy, Jostine Fei Ho
  • Patent number: 10277566
    Abstract: This disclosure is directed to systems and methods for securely communicating authentication information in a networked environment such as one involving a client device, a cloud based computing platform, and an enterprise computing environment. Some embodiments may include encrypting, by a client device using a public key, authentication information provided by a user. The encrypted authentication information is sent to a cloud based service which then sends it to an on-premises component residing behind a firewall of an enterprise. The on-premises component decrypts the authentication information using a private key, validates the authentication information, and returns the result to the cloud based service over a network. If validated, the cloud based service establishes a secure connection between the client device and the on-premises component such that the user can access the enterprise's content without the enterprise having to share the authentication information with the cloud based service.
    Type: Grant
    Filed: June 14, 2017
    Date of Patent: April 30, 2019
    Assignee: SailPoint Technologies, Inc.
    Inventors: Craig Robert William Forster, Daniel Thomas Greff, Crandall B. T. Chow, Phillip Goldenburg
  • Patent number: 9722980
    Abstract: This disclosure is directed to systems and methods for securely communicating authentication information in a networked environment such as one involving a client device, a cloud based computing platform, and an enterprise computing environment. Some embodiments may include encrypting, by a client device using a public key, authentication information provided by a user. The encrypted authentication information is sent to a cloud based service which then sends it to an on-premises component residing behind a firewall of an enterprise. The on-premises component decrypts the authentication information using a private key, validates the authentication information, and returns the result to the cloud based service over a network. If validated, the cloud based service establishes a secure connection between the client device and the on-premises component such that the user can access the enterprise's content without the enterprise having to share the authentication information with the cloud based service.
    Type: Grant
    Filed: March 15, 2016
    Date of Patent: August 1, 2017
    Assignee: Sailpoint Technologies, Inc.
    Inventors: Craig Robert William Forster, Daniel Thomas Greff, Crandall B. T. Chow, Phillip Goldenburg
  • Patent number: 9600656
    Abstract: Embodiments of systems and method as presented herein allow a user's locally stored authentication credentials to be reset without needing either to contact the domain controller over a network or authenticating a user at the device. Credentials being reset by the user are obtained at the device and encrypted in the same manner as the original locally stored domain credentials such that the new credentials can be used to overwrite the previously stored authentication credentials for the user at the device without contacting the domain controller over the network. The user can then access his device without contacting the domain controller using these new locally stored authentication credentials. Additionally, the user's credentials may be independently reset with respect to the domain controller.
    Type: Grant
    Filed: March 9, 2016
    Date of Patent: March 21, 2017
    Assignee: Sailpoint Technologies, Inc.
    Inventor: Nicholas Ryan Wellinghoff
  • Patent number: 9319395
    Abstract: This disclosure is directed to systems and methods for securely communicating authentication information in a networked environment such as one involving a client device, a cloud based computing platform, and an enterprise computing environment. Some embodiments may include encrypting, by a client device using a public key, authentication information provided by a user. The encrypted authentication information is sent to a cloud based service which then sends it to an on-premises component residing behind a firewall of an enterprise. The on-premises component decrypts the authentication information using a private key, validates the authentication information, and returns the result to the cloud based service over a network. If validated, the cloud based service establishes a secure connection between the client device and the on-premises component such that the user can access the enterprise's content without the enterprise having to share the authentication information with the cloud based service.
    Type: Grant
    Filed: June 27, 2014
    Date of Patent: April 19, 2016
    Assignee: Sailpoint Technologies, Inc.
    Inventors: Craig Robert William Forster, Daniel Thomas Greff, Crandall B. T. Chow, Phillip Goldenburg
  • Publication number: 20080288330
    Abstract: Systems and methods for measuring access risk associated with an enterprise having at least one resource accessible by at least one user with at least one entitlement to access the resource. Some embodiments implement a method of identifying the resources, users, and entitlements and associating access risk scores with the entitlements. The method can include combining the access risk scores associated with each user to form composite access risks scores and outputting the composite access risk scores. In some embodiments, the user with the highest composite access risk score can be identified and remedial action taken. The highest access risk user of some embodiments may be a department, a division, a subsidiary, or an organization. The method can occur in real time and an administrator can be alerted to changes in entitlements. Access risk scores can be adjusted for compensating controls and personal factors and attributes of the users.
    Type: Application
    Filed: May 14, 2008
    Publication date: November 20, 2008
    Applicant: SailPoint Technologies, Inc.
    Inventors: David Hildebrand, Darran Rolls