Technology for integrating multiple identity clouds
A software platform integrates multiple identity clouds to automate user authentication and authorization, addressing the complexity of managing identities and access rights, enhancing security and performance for organizations with large user bases.
Patent Information
- Application Number
- JP2025525755
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-11-08
- Filing Date
- 2023-10-05
- Publication Date
- 2026-02-06
AI Technical Summary
Managing identities and access rights across multiple cloud platforms is complex and time-consuming, leading to security vulnerabilities and increased burden for organizations, especially those with a large number of users.
A software platform that integrates multiple identity clouds by automating the registration and authorization process, using a directory to manage user authentication and authorization based on authorization models, and supporting features like single sign-on and identity governance.
Enhances security and reduces complexity in managing identities and access rights across multiple cloud platforms, improving performance and reducing the risk of phishing attacks and credential theft.
Smart Images

Figure 2026504628000001_ABST
Abstract
Description
[Technical Field]
[0001] cross reference
[0001] This patent application claims the benefit of commonly assigned U.S. patent application Ser. No. 18 / 053,721, filed Nov. 8, 2022, by McGuinness et al., entitled "TECHNIQUES FOR UNIFYING MULTIPLE IDENTITY CLOUDS."
[0002] Technology field
[0002] The present disclosure relates generally to database systems and data processing, and specifically to techniques for integrating multiple identity clouds. [Background technology]
[0003] background
[0003] An organization may provide its users with access to resources (such as software applications) that may be scrutinized for security purposes, compliance, or license management, among other examples. Thus, an organization that includes several users must manage several different access rights. The need to manage identities and access rights for several users can impose a significant burden on an organization.
[0004] In some cases, organizations may use tools such as identity governance and administration (IGA) tools to help manage user identities and access rights. However, for some use cases, traditional IGA tools may be inadequate or suboptimal in some current configurations. Summary of the Invention [Means for solving the problem]
[0005] overview The described technology relates to improved methods, systems, devices, and apparatuses that support technology for integrating multiple identity clouds. For example, a software platform may receive a first request from a first user to establish an authorization model for a resource by using a first cloud platform, which may be associated with the software platform. The authorization model may identify one or more parameters associated with accessing the resource by using the first cloud platform. In some examples, the software platform may receive a second request from the first user to integrate the resource with a second cloud platform according to the authorization model. The software platform may authorize the first request and the second request by using a directory associated with the software platform. For example, the software platform may authorize the first request and the second request based on first authentication information associated with the first user. In some examples, the software platform may receive a third request from a second user to access the resource by using a second cloud platform, which may be associated with the software platform. The software platform may authorize the third request by using a directory associated with the software platform. In some examples, authorization of the third request may be performed in the software platform according to an authorization model and based on second authentication information associated with the second user.
[0006] A method for managing resources in a software platform of a device is described. The method may include receiving a first request from a first user to establish an authorization model for the resource by using a first cloud platform associated with the software platform, the authorization model identifying one or more parameters associated with accessing the resource by using a second cloud platform associated with the software platform; receiving a second request from the first user to integrate the resource with the second cloud platform according to the authorization model; authorizing the first request and the second request by using a directory associated with the software platform, the authorization of the first request and the second request being based on first authentication information associated with the first user; receiving a third request from the second user to access the resource by using the second cloud platform associated with the software platform; and authorizing the third request by using the directory associated with the software platform, the authorization of the third request being according to the authorization model and based on second authentication information associated with the second user.
[0007]
[0007] An apparatus for managing resources in a software platform of a device is described. The apparatus may include a processor, a memory coupled to the processor, and instructions stored in the memory. The instructions may be executable by the processor to cause the apparatus to: receive a first request from a first user to establish an authorization model for a resource by using a first cloud platform associated with the software platform, the authorization model identifying one or more parameters associated with accessing the resource by using a second cloud platform associated with the software platform; receive a second request from the first user to integrate the resource with the second cloud platform according to the authorization model; authorize the first request and the second request by using a directory associated with the software platform, the authorization of the first request and the second request being based on first authentication information associated with the first user; receive a third request from a second user to access the resource by using a second cloud platform associated with the software platform; and authorize the third request by using a directory associated with the software platform, the authorization of the third request being according to the authorization model and based on second authentication information associated with the second user.
[0008] Another apparatus for managing resources in a software platform of a device is described. The apparatus may include means for receiving a first request from a first user to establish an authorization model for a resource by using a first cloud platform associated with the software platform, the authorization model identifying one or more parameters associated with accessing the resource by using a second cloud platform associated with the software platform; means for receiving a second request from the first user to integrate the resource with the second cloud platform according to the authorization model; means for authorizing the first request and the second request by using a directory associated with the software platform, the authorization of the first request and the second request being based on first authentication information associated with the first user; means for receiving a third request from a second user to access the resource by using a second cloud platform associated with the software platform; and means for authorizing the third request by using a directory associated with the software platform, the authorization of the third request being according to the authorization model and based on second authentication information associated with the second user.
[0009] A non-transitory computer-readable medium storing code for managing resources in a software platform of a device is described. The code may include instructions executable by a processor to: receive a first request from a first user to establish an authorization model for a resource by using a first cloud platform associated with the software platform, the authorization model identifying one or more parameters associated with accessing the resource by using a second cloud platform associated with the software platform; receive a second request from the first user to integrate the resource with the second cloud platform according to the authorization model; authorize the first request and the second request by using a directory associated with the software platform, the authorization of the first request and the second request being based on first authentication information associated with the first user; receive a third request from a second user to access the resource by using a second cloud platform associated with the software platform; and authorize the third request by using a directory associated with the software platform, the authorization of the third request being according to the authorization model and based on second authentication information associated with the second user.
[0010]
[0010] Some examples of the methods, apparatuses, and non-transitory computer-readable media described in this specification may further include operations, features, means, or instructions for establishing a connection between a second cloud platform and a resource in response to authorizing the third request.
[0011]
[0011] Some examples of the methods, apparatuses, and non-transitory computer-readable media described in this specification may further include operations, features, means, or instructions for establishing an authorization scheme by using a connection between a second cloud platform and a resource in accordance with an authorization model, wherein the authorization scheme includes single-sign-on authorization.
[0012]
[0012] Some examples of the methods, apparatuses and non-transitory computer-readable media described in this specification may further include operations, features, means or instructions for assigning privileges to a second user by using a connection between a second cloud platform and a resource, and the privileges may be based on an authorization model.
[0013]
[0013] Some examples of the methods, apparatuses, and non-transitory computer-readable media described in this specification may further include operations, features, means, or instructions for transmitting information corresponding to a security event associated with a resource to a first user and based on a connection between a second cloud platform and the resource.
[0014]
[0014] Some examples of the methods, apparatuses, and non-transitory computer-readable media described in this specification may further include operations, features, means, or instructions for receiving information corresponding to a security event related to a resource from a first user and based on a connection between a second cloud platform and the resource.
[0015]
[0015] Some examples of the methods, apparatus, and non-transitory computer-readable media described in this specification may further include operations, features, means, or instructions for transmitting information corresponding to a security event associated with a resource to a second user.
[0016] In some examples of the methods, apparatus, and non-transitory computer-readable media described herein, the resources may be included within a software application. [Brief explanation of the drawings]
[0017] BRIEF DESCRIPTION OF THE DRAWINGS [Figure 1]
[0017] An example system that supports techniques for integrating multiple identity clouds in accordance with some aspects of the present disclosure is illustrated. [Figure 2]
[0018] 1 illustrates an example block diagram supporting techniques for integrating multiple identity clouds in accordance with some aspects of the present disclosure. [Figure 3]
[0018] An example block diagram supporting a technique for integrating multiple identity clouds in accordance with some aspects of the present disclosure is shown. [Figure 4]
[0019] 1 illustrates an example process flow that supports techniques for integrating multiple identity clouds in accordance with some aspects of the present disclosure. [Figure 5]
[0020] 1 illustrates a block diagram of an apparatus facilitating techniques for integrating multiple identity clouds in accordance with some aspects of the present disclosure. [Figure 6]
[0021] 1 illustrates a block diagram of a software platform that supports techniques for integrating multiple identity clouds in accordance with some aspects of the present disclosure. [Figure 7]
[0022] 1 illustrates a diagram of a system including devices facilitating techniques for integrating multiple identity clouds in accordance with some aspects of the present disclosure. [Figure 8]
[0023] 1 illustrates a flowchart illustrating a method for facilitating techniques for integrating multiple identity clouds in accordance with some aspects of the present disclosure. [Figure 9]
[0023] A flowchart illustrating a method for supporting techniques for integrating multiple identity clouds in accordance with some aspects of the present disclosure is shown. DETAILED DESCRIPTION OF THE INVENTION
[0018] Detailed Description
[0024] In some examples, organizations may use cloud computing to improve organizational performance. However, in such examples, the use of cloud computing (e.g., applications accessed using cloud computing) may lead to security vulnerabilities. Accordingly, some applications may include security features, such as restricted access to the application, restricted access to resources contained within the application, or both. For example, an application may require a user (e.g., an employee of the organization) to log in to an account within the application by using credentials such as a username and password combination. The application may use the credentials to verify the user's identity. However, in some examples, an organization may use an increased amount of applications, but managing the identities and access rights of several users across several applications may impose a significant burden on the organization. For example, for an organization with an increased number of employees (e.g., users), managing credentials across multiple applications may impose a significant burden. In some examples, an organization may employ a first cloud platform to manage credentials across multiple applications. For example, the first cloud platform may provide the organization with access to multiple applications (e.g., and resources within multiple applications) while maintaining increased security. In some examples, the first cloud platform may include features such as single sign-on (SSO) across multiple applications, identity governance and administration (IGA), privileged access management (PAM), and identity access management (IAM).However, in some instances, integrating such features with multiple applications (e.g., each of multiple applications) can be relatively complex and time-consuming for the independent software vendor (ISV) that manages the application. Additionally or alternatively, configuring an application for SSO (or other features) can be relatively complex for users of the application and can lead to errors.
[0019]
[0025] In some examples, according to the techniques for integrating multiple identity platforms as described herein, a software platform may assist an ISV's framework in automating the registration of a user's application. For example, within the software platform, an ISV may build an application and use a second cloud platform to integrate the application into a first cloud platform. In such an example, a user may obtain the application and initiate the application registration process by using the software platform. For example, the software platform may receive a first request from a first user to establish an authorization model for a resource by using the first cloud platform. In such an example, the authorization model may identify one or more parameters associated with accessing the resource by using the second cloud platform. Additionally, the software platform may receive a second request from the first user. In some examples, the second request may be to integrate the resource with the second cloud platform according to the authorization model. The software platform may authorize the first request and the second request by using a directory associated with the software platform, and the authorization of the first request may be based on first authentication information associated with the first user. In some examples, the software platform may receive a third request from a second user. The third request may be to access a resource by using a second cloud platform. In some examples, the software platform may authorize the second request by using a directory associated with the software platform. For example, the software platform may authorize the second request according to an authorization model and based on second authentication information associated with the second user. In some examples, using the software platform to deploy and access resources may lead to improved performance for the first user and the second user, among other possible advantages.
[0020]
[0026] Some aspects of the present disclosure are initially described in the context of distributed computing systems. Some aspects of the present disclosure are also described in the context of block diagrams and process flows. Some aspects of the present disclosure are further illustrated by and described with reference to device diagrams, system diagrams, and flowcharts related to techniques for integrating multiple identity clouds.
[0021]
[0027] FIG. 1 illustrates an example of a distributed computing (e.g., cloud computing) system 100 supporting techniques for integrating multiple identity clouds according to various aspects of the present disclosure. System 100 may include client devices 105, applications 110, an authentication platform 115, and data storage 120. Authentication platform 115 may be an example of a public or private cloud network. Client devices 105 may access authentication platform 115 over a network connection 135. The network may implement a transmission control protocol and internet protocol (TCP / IP), such as the Internet, or may implement other network protocols. Client devices 105 may be an example of a user device, such as a server (e.g., client device 105-a), a smartphone (e.g., client device 105-b), or a laptop (e.g., client device 105-c). In other examples, client devices 105 may be a desktop computer, a tablet, or another computing device or system capable of generating, analyzing, sending, and receiving communications. In some examples, client device 105 may be operated by a user that is part of a business, a corporation, a non-profit organization, a startup, or any other type of organization.
[0022]
[0028] A client device 105 may interact with multiple applications 110 through one or more interactions 130. The interactions 130 may include digital communications between the client device 105 and the applications 110, application programming interface (API) calls, hypertext transfer protocol (HTTP) messages, or any other interactions. Data may be associated with the interactions 130. The client device 105 may access an authentication platform 115 for storing, managing, and processing data related to the interactions 130. In some examples, the client device 105 may have an associated security or permission level. The client device 105 may be able to access some applications, data, and database information within the authentication platform 115, but not others, based on the associated security or permission level.
[0023]
[0029] The application 110 may interact with the client device 105 via email, web, text message, or any other suitable form of interaction. The interaction 130 may be a business-to-business (B2B) interaction or a business-to-consumer (B2C) interaction. The application 110 may also be referred to as a customer, client, website, or some other suitable technical term. In some examples, the application 110 may be an instance of a server, a node, a computing cluster, or any other type of computing system, component, or environment. In some examples, the application 110 may be operated by a user or a group of users.
[0024]
[0030] The authentication platform 115 may provide cloud-based services to the client devices 105, the applications 110, or both. In some examples, the authentication platform 115 may support a database system, such as a multi-tenant database system. In such cases, the authentication platform 115 may serve multiple client devices 105 with a single instance of software. However, other types of systems may be implemented, including but not limited to client-server systems, mobile device systems, and mobile network systems. The authentication platform 115 may receive data related to interactions 130 from the client devices 105 over a network connection 135 and may store and analyze this data. In some examples, the authentication platform 115 may receive data directly from interactions 130 between the applications 110 and the client devices 105. In some examples, the client devices 105 may develop applications to run on the authentication platform 115. The authentication platform 115 may be implemented using a remote server. In some examples, the remote server may be an example of data storage 120.
[0025]
[0031] Data storage 120 may include multiple servers. Multiple servers may be used for data storage, management, and processing. Data storage 120 may receive data from authentication platform 115 via connection 140, directly from client device 105, or from interactions 130 between applications 110 and client devices 105. Data storage 120 may utilize multiple redundancies for security purposes. In some examples, data stored in data storage 120 may be backed up by replicating the data in multiple locations.
[0026]
[0032] Subsystem 125 may include client device 105, authentication platform 115, and data storage 120. In some examples, data processing may occur in any of the components of subsystem 125 or in a combination of these components. In some examples, a server may perform the data processing. The server may be client device 105 or may be located in data storage 120.
[0027]
[0033] System 100 may be an example of a multi-tenant system. For example, system 100 may store data and simultaneously provide applications, solutions, or any other functionality for multiple tenants. A tenant may be an example of a group of users (e.g., an organization) associated with the same tenant identifier (ID) who share system 100 access, privileges, or both. System 100 may effectively isolate a first tenant's data and processing from other tenants' data and processing by using a system architecture, logic, or both that supports secure multi-tenancy. In some examples, system 100 may include or be an example of a multi-tenant database system. A multi-tenant database system may store data for different tenants in a single database or a single set of databases. For example, a multi-tenant database system may store data for multiple tenants in a single table (e.g., in different columns) of a database. To support multi-tenant security, a multi-tenant database system may prohibit (e.g., restrict) a first tenant from accessing, viewing, or in any way interacting with data or columns associated with different tenants. Thus, tenant data of a first tenant may be isolated (e.g., logically isolated) from tenant data of a second tenant, and the tenant data of the first tenant may be invisible (or otherwise transparent) to the second tenant. Multi-tenant database systems may additionally use encryption techniques to further protect tenant-specific data from unauthorized access (e.g., by another tenant).
[0028]
[0034] Additionally or alternatively, a multi-tenant system may support multi-tenancy of software applications and infrastructure. In some cases, a multi-tenant system may maintain a single instance of a software application and architecture that supports the software application to serve multiple different tenants (e.g., organizations, customers). For example, multiple tenants may share the same software application, the same underlying architecture, the same resources (e.g., computational resources, memory resources), the same database, the same server or cloud-based resources, or any combination thereof. For example, system 100 may run a single instance of software on a processing device (e.g., a server, server cluster, virtual machine) to serve multiple tenants. Such a multi-tenant system may provide efficient integration by applying integration to the same software application and underlying architecture that supports multiple tenants (e.g., by using APIs). In some cases, processing resources, memory resources, or both may be shared by multiple tenants.
[0029]
[0035] As described herein, system 100 may support any configuration for providing multi-tenant functionality. For example, system 100 may organize resources (e.g., processing resources, memory resources) to support tenant isolation (e.g., tenant-specific resources), tenant isolation within shared resources (e.g., within a single instance of a resource), tenant-specific resources within resource groups, tenant-specific resource groups corresponding to the same subscription, tenant-specific subscriptions, or any combination thereof. System 100 may support scaling of tenants within a multi-tenant system (e.g., by using scale triggers, automatic scaling procedures, scaling requests, or any combination thereof). In some cases, system 100 may implement one or more scaling rules to enable relatively fair sharing of resources across tenants. For example, a tenant may have a threshold amount of processing resources, memory resources, or both to use (which in some cases may be associated with a subscription by the tenant).
[0030]
[0036] In some examples, the subsystem 125 (e.g., a software platform) may support one or more techniques for integrating multiple identity platforms. For example, the software platform may receive a first request from a first user (e.g., via a client device 105) to create a resource. In some examples, as part of the first request, the first user may create (e.g., request to create) an authorization model for the resource using a first cloud platform, which may be associated with the software platform. The authorization model may identify one or more parameters associated with accessing the resource using the first cloud platform. In some examples, the software platform may receive a second request from the first user to integrate the resource with a second cloud platform according to the authorization model. For example, the first user may request to publish the resource on a marketplace included within the cloud platform. In some examples, the first user may use one-click configuration to synchronize metadata from the first cloud platform with the second cloud platform. The software platform may authorize the first request and the second request by using a directory associated with the software platform. For example, the software platform may authorize the first request based on first authentication information associated with the first user. In such an example, the software platform may authorize the second request based on the authorization of the first request.
[0031]
[0037] In some examples, the software platform may receive a third request from a second user (e.g., via another client device) to access a resource by using a second cloud platform that may be associated with the software platform. The software platform may authorize the third request by using a directory associated with the software platform. In some examples, authorization of the third request may be performed at the software platform according to an authorization model and based on second authentication information associated with the second user.
[0032]
[0038] It should be understood by those skilled in the art that one or more aspects of the present disclosure may be implemented in system 100 to additionally or alternatively solve other problems besides those discussed above. Furthermore, some aspects of the present disclosure may provide technical improvements to "conventional" systems or processes as described herein. However, this specification and the accompanying drawings include only exemplary technical improvements resulting from implementing some aspects of the present disclosure and therefore do not represent all of the technical improvements provided within the scope of the claims.
[0033]
[0039] 2 illustrates an example block diagram 200 supporting a technique for integrating multiple identity clouds according to some aspects of the present disclosure. In some examples, block diagram 200 may implement or be implemented by aspects of system 100. For example, block diagram 200 may be implemented in software platform 225, which may be an example of a corresponding entity as described with reference to FIG. 1, or in one or more cloud platforms 215 (e.g., cloud platform 215-a, cloud platform 215-b), or both.
[0034]
[0040] In some examples, organization 205 (e.g., organization 205-a, organization 205-b, organization 205c) may use cloud computing, such as cloud applications (e.g., application 210-a, application 210-b, application 210c), to improve the performance of organization 205 (e.g., a company, enterprise). However, in such examples, the use of cloud applications may lead to security vulnerabilities. Therefore, some cloud applications may include security features, such as restricted access to resources contained within the cloud application. For example, a cloud application may require a user (e.g., an employee of the organization) to log in to an account within the cloud application by using authentication information, such as a username and password combination. The cloud application may use the authentication information to verify the user's identity. However, in some examples, an organization may use an increased amount of cloud applications, and therefore, managing the identities and access rights of several users across several applications may impose a significant burden on the organization. That is, multiple cloud applications may include identity management features (e.g., IAM features) that users of the cloud applications (e.g., employees of the organization) comply with in order to use the cloud applications. For organizations with increased volumes of employees (e.g., users), managing credentials across multiple cloud applications can impose a significant burden.
[0035]
[0041] In some examples, organization 205 may employ cloud platform 215-a (e.g., a workforce identity cloud) to manage authentication information across multiple cloud applications (e.g., applications 210). For example, organization 205 may use a large number of technology vendors (e.g., ISVs) for internet, collaboration (e.g., within the organization and external to the organization), email, and billing, among other possible examples. Additionally, as organization 205 increases in size, organization 205 may use more technologies and therefore an increased number of technology vendors. For example, organization 205 may utilize more resources, such as software applications (e.g., cloud applications), and may have multiple types of users of those resources (e.g., employees, contractors, and customers), among other examples. In some examples, organization 205 may implement one or more platforms (e.g., software platforms) for collaboration or infrastructure, but the features provided by such platforms may not include some services implemented within the organization. That is, the likelihood that a single platform will provide each service (e.g., all services, all applications) implemented within organization 205 may be relatively low, thus constraining the resources used by organization 205. For example, to reduce the amount of platforms used by the organization, the organization may decide to constrain the resources used by the organization to the resources (or features) provided by the platforms used by the organization for collaboration or infrastructure (e.g., the platforms may be silos).
[0036]
[0042] However, in some examples, organization 205 may utilize cloud platform 215-a to increase technology adoption within organization 205; for example, cloud platform 215-a may provide a zero-trust approach to a workforce (e.g., a borderless workforce) that may lead to improved performance. In some examples, a borderless workforce may refer to a workforce that includes employees, migrant workers, contractors, and business partners who may be associated with the organization (e.g., and may use multiple devices across multiple locations) and may use multiple resources associated with the organization (e.g., applications, infrastructure, APIs, cloud and on-premise servers). That is, an organization (e.g., one or more of organizations 205) may be associated with multiple types of users (e.g., employees, migrant workers, contractors, and business partners) who may access multiple types of resources managed (or utilized) by the organization. In such instances (e.g., where there is no clear boundary around resource access associated with the organization), the organization (e.g., a company) may extend its zero trust posture to each user (e.g., contractors, business partners, and employees (such as front office workers)) to improve organizational performance. That is, the trust boundary associated with the organization may include each entity (e.g., any human or other organization) associated with the organization.
[0037]
[0043] For example, a device of an organization's employees (e.g., a computer of a support representative at the organization's call center) may be compromised. In such an instance, while the technical impact of the compromise may be relatively small (e.g., the compromise may occur on a single computer), the compromise may negatively impact trust boundaries within the organization's workforce and within other organizations associated with the organization (e.g., third parties). For example, such a compromise may lead to security vulnerabilities for the organization and third parties associated with the organization. Accordingly, the organization may implement cloud platform 215-a so that the technology environments of the organization's third parties and workforce may have increased security protection (e.g., from compromise). For example, organization 205 may implement cloud platform 215-a to reduce identity challenges and increase the security of organization 205.
[0038]
[0044] In some examples, cloud platform 215-a may enhance onboarding of an organization's 205 workforce (e.g., a borderless workforce). For example, identity governance features supported in cloud platform 215-a may enable an organization's (e.g., one or more of organizations 205) workforce to obtain appropriate entitlements to tools that the workforce may use for their work (e.g., tasks, jobs). In some examples, entitlements may change throughout the lifecycle of the workforce within the organization. For example, a user associated with the organization (e.g., a contractor) may complete a project and therefore refrain from utilizing access to organization-related applications that may be granted to employees on the project. In such an example, access authentication features supported in cloud platform 215-a may be used to notify another user associated with the organization (e.g., an employee on an information technology (IT) team) of a contract termination or extension associated with the contractor. That is, identity governance and access management features (e.g., IGA and LAM features) supported in cloud platform 215-a may enable cloud platform 215-a to increase security for multiple users across multiple stages of their respective lifecycles within an organization. For example, software platform 225 may include features for automating access policy enforcement through access authentication campaigns and automated reporting. In some examples, access requests may be used in accordance with one or more applications utilized by the organization. For example, access requests may be sent or received via a chat-based (e.g., message-based) application (e.g., between users associated with the organization or between cloud platform 215-a and a user associated with the organization). Additionally or alternatively, access requests may include the ability to orchestrate (e.g., by using workflows) access governance (e.g., relatively low-code or no-code provided by the organization) so that the organization can identify inactive users (e.g., automatically).In some examples, software platform 225 may support multiple types of resources, including business applications and infrastructure. Additionally or alternatively, each resource may include a scale (e.g., a sliding scale) of entitlements that may range from cloud application access to relatively highly privileged access (e.g., may be closely secured and time-bound). As discussed herein, entitlements may refer to resources (e.g., software applications or resources within software applications) that a user may be granted access to (e.g., may own) for use.
[0039]
[0045] In some examples, cloud platform 215-a (e.g., a workforce identity cloud) may enable improved performance for users (e.g., employees associated with respective IT or security teams within organization 205) across multiple stages of the identity lifecycle. For example, cloud platform 215-a may enable organization 205 to complete projects relatively quickly, remediate security threats (e.g., in real time), and provide information to stakeholders associated with organization 205.
[0040]
[0046] In some examples, cloud platform 215-a may correspond to technologies that organization 205 may use to connect to multiple (e.g., all) resources. For example, cloud platform 215-a may facilitate access to organization 205's applications 210 so that each user (e.g., employee) associated with organization 205 may obtain the appropriate technology for a suitable amount of time (e.g., in a zero-trust environment). For example, access to resources may lead to increased security risks for the workforce of an organization (e.g., one or more of organizations 205). In such examples, an organization may use cloud platform 215-a to enable multiple users (e.g., employees) associated with the organization access to multiple types of resources (e.g., technologies such as cloud applications) used to complete work (e.g., jobs, tasks). For example, cloud platform 215-a may correspond to an identity provider (e.g., a single identity provider, a single control plane, a single directory) for applications, systems, and tools utilized within the organization, among other examples. Additionally or alternatively, cloud platform 215-a may provide identity compliance and automation of business processes, including onboarding user applications, onboarding users (e.g., employees), compliance review of users, changing user roles within an organization, and leaving a user from an organization.
[0041]
[0047] In some examples, cloud platform 215-a may reduce the likelihood of a malicious cyberattack, such as a credential theft or phishing attack, being successful. As described herein, a phishing attack may refer to a type of malicious cyberattack in which an attacker may send a message (e.g., email) to a user in an attempt to obtain information related to the user (or other users) or to deploy malicious software on infrastructure (e.g., computers, servers) related to the user. For example, some attackers may use websites to conduct phishing attacks against obtained credentials related to an organization (e.g., one or more of organizations 205). In such examples, as the number of websites used for phishing attacks increases, the organization's vulnerability to phishing attacks (e.g., the likelihood that the organization will fall victim to a phishing attack) may also increase. Therefore, to reduce the likelihood of a malicious attack being successful, cloud platform 215-a may provide a framework for passwordless authentication. For example, cloud platform 215-a may provide passwordless authentication to an organization's workforce to access resources for work. In some examples, an organization's workforce (e.g., employees, contractors, and suppliers) may include hybrid and remote roles, which may lead to increased risk for the organization. However, in such examples, cloud platform 215-a may provide passwordless authentication across multiple types of resources (e.g., applications, actions, single sign-on interactions, social connections, log streams 210), multiple types of devices (e.g., smartphones, laptops, desktops, wearable devices), and multiple types of operating systems. For example, passwordless authentication features provided by using cloud platform 215-a may reduce phishing attacks that may target multiple types of users and multiple types of resources associated with organization 205. That is, cloud platform 215-a may provide one or more phishing-resistant identity solutions across user types and devices associated with organization 205.As discussed herein, phishing resistance may refer to the ability to reduce (eg, minimize) successful phishing attacks.
[0042]
[0048] In some examples, cloud platform 215-a may provide one or more enhancements for control of other authenticators (e.g., factors related to a web authentication API and fast identity online (FIDO) authentication credentials (e.g., passkeys)). For example, cloud platform 215-a may provide customizable authentication so that an organization (e.g., one or more of organizations 205) may select authentication factors consistent with the organization's security posture. As discussed herein, security posture may refer to the security state of a network (e.g., people, hardware, software, policies) associated with the organization. Additionally or alternatively, passwordless features provided by cloud platform 215-a extend the phishing-resistant identity solution beyond a few users (e.g., employees) of an organization to extend the organization's ecosystem. For example, the phishing-resistant identity solution may include employees, contractors, and customers, among other examples of users that may be associated with the organization. In such an example, by using cloud platform 215-a as an identity provider, an organization can allocate more resources (e.g., energy, time, finances) to the organization's customers and fewer resources to managing authentication certificates.
[0043]
[0049] In some examples (e.g., in addition to enabling phishing-resistant identity solutions for multiple types of users associated with organization 205), cloud platform 215-a may provide access that may be unrestricted at a single point in time and unrestricted to a single resource. That is, cloud platform 215-a may provide access across multiple resources for an extended period of time. For example, cloud platform 215-a may support principle of least privilege (POLP) access, where an organization (e.g., one or more of organizations 205) may customize authentication for users associated with the organization so that users may be granted permission to read, write, or execute resources to perform work. In some examples, cloud platform 215-a may support least privilege access and governance across the entire lifecycle associated with a user (e.g., across multiple roles a user may fill within an organization) and across multiple resources. In some examples, the LAM, IGA, and PAM components (e.g., each component) supported by cloud platform 215-a may provide increased control to an organization (e.g., a team within an organization) with reduced complexity, reduced resource overhead, and increased security. The identity governance (e.g., IGA) and privileged access (e.g., PAM) features supported by cloud platform 215-a may enable organization 205 to identify users (e.g., determine which users are provided access to one or more resources (e.g., which resources) with reduced (e.g., minimal) complexity.
[0044]
[0050] For example, identity governance features provided by cloud platform 215-a may enable customers of an organization (e.g., one or more of organizations 205) to automate multiple types of actions across access management and governance systems associated with the organization, while increasing the productivity of some users (e.g., IT teams) associated with the organization (e.g., without reducing workforce mobility). Additionally or alternatively, privileged access features provided by cloud platform 215-a may provide enhanced PAM, where privilege governance, secret management, and compliance audit capabilities that can be used by an organization (e.g., by IT and security teams within the organization) of PAM may be combined within cloud platform 215-a (e.g., in the same workforce identity solution). Thus, cloud platform 215-a may enable privileged user benefits and phishing-resistant passwordless access. For example, cloud platform 215-a may enable organizations 205 to operate without single-use (e.g., one-time) passwords, identity silos, and relatively bloated software.
[0045]
[0051] For example, organization 205-a may include a workforce of multiple users (e.g., tens of thousands of users (e.g., tens of thousands of employees, contractors, and suppliers)) across multiple locations (e.g., hundreds of thousands of locations) and multiple server instances. In such examples, cloud platform 215-a may provide a unified solution where a first user (e.g., a technician) at a first location may request access to a cloud server associated with cloud platform 215-a. In some examples, the first user may request access to a cloud server from another user (e.g., a manager) at a second location. In such examples, using cloud platform 215-a, the first user may be granted access to a cloud server relatively quickly (e.g., immediately), for example, without using static authentication or without sending a request to a second user (e.g., via a filled-out ticket). Additionally or alternatively, cloud platform 215-a may limit access granted to a first user (e.g., automatically) in response to cloud platform 215-a detecting a relatively high-risk login attempt (e.g., via an audit trail of multiple steps in the authentication process). That is, cloud platform 215-a may provide organization 205 with phishing-resistant access to multiple resources and centralized identity management of multiple resources, and enable automated compliance capabilities throughout the lifecycle of each user associated with organization 205. As discussed herein, centralized identity management may refer to the collection and storage of user verification data, allowing a user to access multiple resources (e.g., applications, websites, or other systems) with the same set of credentials.
[0046]
[0052] In some examples, it may be desirable for application 210 to support access management, scalability, login security, and user management, among other possible features. For example, users of application 210 (e.g., users associated with organization 205) may want to log in to application 210 using multiple types of passwordless or social login methods. Additionally or alternatively, an ISV (e.g., developer) of an application (e.g., one or more of applications 210) may want to determine whether users of the application may correspond to robot users or legitimate users. In some examples, developers and users of organization 205 may desire features related to preventing the use of compromised credentials (e.g., compromised credentials from application 210). That is, users may want to use, and developers may want to build, applications with enterprise-ready identity features. As discussed herein, enterprise-ready identity features may refer to identity features that may be suitable for organizations with constraints that may differ from those of consumer or relatively small business segments. However, in some examples, integrating enterprise-ready identity features into an application (e.g., one or more of applications 210) may be relatively complex. Accordingly, some developers (e.g., ISVs) may decide to integrate (e.g., deploy) their applications with cloud platform 215-b. For example, the developer of application 210 may use cloud platform 215-b (e.g., a customer identity cloud) to deploy, and in some instances build, application 210.
[0047]
[0053] For example, customer identity may affect how application developers can interact with users of the application. In such an example, using cloud platform 215-b to deploy an application may lead to growth opportunities and increased brand recognition for the developer (e.g., the business developing the application). For example, while it may be desirable for developers to build a differentiated product, maintaining and integrating the differentiated product (e.g., tools, passwordless standards, other types of features) into the application may be relatively complex and time-consuming, leading to reduced productivity and reduced innovation. For example, threat vectors, standards compliance, and evolving user experiences may compound and increase the complexity associated with integrating across the customer identity footprint associated with the application. That is, it may be desirable for developers to reduce the amount of time spent building and maintaining identities within an organization. Thus, developers may use cloud platform 215-b to deploy (e.g., build) applications 210 (e.g., consumer applications, SaaS applications), thereby reducing the burden associated with building and maintaining identities for applications 210. That is, cloud platform 215-b (e.g., a customer identity cloud) may enable application developers, digital leaders, and security teams to allocate more resources to innovation.
[0048]
[0054] In some examples, cloud platform 215-b may support customer identity solutions that can accelerate business without requiring users to navigate multiple features. For example, cloud platform 215-b may support flexible identity services. In some examples, cloud platform 215-b may provide security for application 210 and increase the convenience associated with using application 210. For example, application developers (e.g., digital teams associated with one or more ISVs of application 210) may increase revenue through application usage and reuse (e.g., by users of an organization, one or more of customers 205), while maintaining security protections. Thus, cloud platform 215-b (e.g., a customer identity cloud) may provide digital teams (e.g., developing consumer applications) with a framework for simplifying registration and login across multiple devices, stacks, and platforms for increased customer acquisition and retention, increased user experience, and a complete view of user data. For example, cloud platform 215-b may provide multiple features to assist digital teams in increasing the digital experience associated with applications. For example, cloud platform 215-b may provide a customizable user experience for application 210 that includes no-code or low-code universal login and multiple types of social login and passwordless login options. As discussed herein, no-code may refer to the development of a software application or feature where the developer (or administrator) of the feature or application may not be aware of how the associated coding for the development may work, and low-code may refer to the development of a software application of a feature where the developer (or administrator) of the feature or application may use some (e.g., a relatively low amount) of code to customize the feature or application.Additionally or alternatively, cloud platform 215-b may provide personalization through progressive profiling, which may enable application developers (e.g., marketers) to collect first-party data over time. In some examples, cloud platform 215-b may help prevent revenue loss (e.g., for developers of application 210) by providing security features that distinguish between normal user activity and activity that may be associated with an attacker. That is, cloud platform 215-b may provide an improved developer experience while maintaining security and privacy.
[0049]
[0055] In some examples, cloud platform 215-b may provide accelerated growth for developers who can develop applications for organizations (e.g., companies with business customers). For example, some software platforms may offer limited feature choices for companies with business customers (e.g., SaaS companies, companies that develop SaaS applications), and the product and engineering teams of such companies may rely on multiple software platforms to obtain a set of desired features (e.g., a certain combination of consumer and workforce identity solutions) for applications developed by the company (e.g., SaaS applications). Accordingly, cloud platform 215-b may provide multiple (e.g., various) tools for such companies to develop applications, such as SaaS applications or other types of applications (which may be enterprise-ready). For example, cloud platform 215-b may offer multiple tools for enterprise federation and other identity systems (which may offer relatively easy-to-implement functionality and reliable and dynamic scaling to meet the constraints of enterprise customers). That is, cloud platform 215-b may enable developers to obtain enterprise-level identity features relatively quickly and relatively easily. Cloud platform 215-b may evolve so that cloud platform 215-b can adapt to changes in standards (e.g., de facto enterprise standards such as service organization control 2 (SOC2) standards) and functionality. For example, cloud platform 215-b may provide several sets of identity capabilities (including several future sets of identity capabilities) for developers (e.g., SaaS developers) who can use SSO and passwordless access.
[0050]
[0056] For example, a developer (e.g., a company, ISV) of application 210-a may use cloud platform 215-b to integrate customer identity within application 210-a (e.g., a marketing stack or other infrastructure associated with application 210-a), enabling application 210-a to support open standards, pre-built integrations, multiple SDKs, multiple APIs, scalability, and deployment within public or private clouds. In some examples, by using cloud platform 215-b for customer identity associated with application 210-a, a developer of application 210-a may spend less time (e.g., a relatively short period of time) on identity management and more time (e.g., a relatively long period of time) on innovation. In some examples, to support the integration of customer identity within application 210, cloud platform 215-b may support passkeys as authenticators across applications 210. For example, passkeys may use biometric device support (e.g., facial recognition) to support credential sharing across devices. For example, enrolling a facial recognition on a device such as a smartphone may allow access to applications on the smartphone and another device (such as a laptop) to be authenticated by fingerprint. That is, Passkey may provide a customer with a passwordless experience across multiple devices. However, in some instances, Passkey may allow a third party to store authentication information associated with a user, leading to increased security risks. For example, some users (e.g., consumers) of applications that support Passkey may be associated with industries with increased regulatory and compliance constraints. Accordingly, cloud platform 215-b may support one or more capabilities, such as financial data exchange constraints, that may be adopted in some locations, enabling application developers to meet regulatory and compliance constraints.That is, cloud platform 215-b may enable developers to build features into applications for industries with increased regulatory and compliance constraints (such as financial services, healthcare, or utilities), among other examples, so that users of applications in such industries can meet their regulatory and compliance constraints. For example, cloud platform 215-b may support financial API and key management, allowing developers of financial services applications to allocate more resources to improving the digital experience associated with financial services applications and less time to managing identity compliance.
[0051]
[0057] In some examples, customer identity can encompass privacy, security, and experience. Thus, to support customer identity, cloud platform 215-b can enable developers to improve user experience and meet regulatory compliance while providing increased security. For example, cloud platform 215-b can include a security center that can provide increased visibility to developers. For example, the security center can enable monitoring (e.g., real-time monitoring), detection, and response to potential identity security events (e.g., directly (e.g., via a dashboard, or by integrating with one or more security stacks, or both)).
[0052]
[0058] In some examples, developers of organizations 205 and applications 210 may use software platform 225, which may integrate and provide interoperability between features (e.g., workforce identity features) provided by cloud platform 215-a (e.g., workforce cloud) and features (e.g., customer identity features) provided by cloud platform 215-b (e.g., customer identity cloud). For example, software platform 225 (e.g., a federated network) may be an example of an identity provider (e.g., a single identity provider) across organizations 205 and applications 210 (e.g., used by organizations 205) with the increased resiliency and uptime (e.g., approximately 99.99% uptime reliability) of cloud platform 215.
[0053]
[0059] In some examples, software platform 225 may provide infrastructure reliability and one or more opportunities for connecting features (e.g., products, technologies) across cloud platform 215. For example, software platform 225 (e.g., a unified identity platform) may correspond to a common integration layer where several technologies may be available to users (e.g., users associated with organization 205 and developers of application 210) across cloud platform 215. For example, software platform 225 may support no-code automation (e.g., workflow) across cloud platform 215. In some examples, providing workflows (e.g., automated proactive measures and responses) across cloud platform 215 may enable more extensibility and provide customizability for organization 205 and application 210. For example, in response to detecting a security incident related to a resource managed by software platform 225 (e.g., a resource included in one or more applications 210) or a device used to access a resource managed by software platform 225, or both, software platform 225 may trigger workflows for one or more users (e.g., teams, employees) associated with the organization (e.g., one or more of organizations 205), or for developers who may have built the resource, or both, to help protect the organization from security threats. Additionally or alternatively, software platform 225 may support risk signal sharing across cloud platform 215 (which may be implemented by using tools such as security centers and credential-based attack prevention techniques). In some examples, software platform 225 may aggregate logins across cloud platform 215, which may provide more robust authentication data and lead to improved access decisions and protections.
[0054]
[0060] In some examples, by supporting integration and interoperability across the cloud platform 215, the software platform 225 (e.g., an integrated network) may enable the organization 205 (e.g., workforce customers) to connect to improved cloud solutions and increase business while maintaining security protection through enterprise-grade capabilities. Additionally or alternatively, by supporting integration and interoperability across the cloud platform 215, the software platform 225 may provide the developer of the application 210 (e.g., a SaaS company) with faster enterprise readiness, exposure to multiple users (e.g., users associated with the organization 205, tens of thousands of workforce customers), and information regarding the usage of the application 210. For example, with multiple applications (e.g., thousands of SaaS applications) built using cloud platform 215-b and integrated with cloud platform 215-a that may be used by multiple organizations 205 (e.g., tens of thousands of organizations), software platform 225 may provide a hub for an increased amount of data and insights. Such data may provide benefits for the developers of applications 210 and for one or more of the organizations 205 that use (e.g., adopt) applications 210. For example, applications 210 may obtain insights (e.g., information, analytics, statistics) regarding which of applications 210 organizations 205 may use and which of applications 210 may be exposed to the developers of applications 210 (e.g., via APIs). Developers may use this insight to customize the experience of organizations 205 using software platform 225. For example, the software platform 225 (e.g., an integrated network) may provide the organization 205 with improved integration, enable increased development of applications 210 (e.g., SaaS applications), and lead to increased amounts of insight (e.g., data, analytics related to the use of the applications 210).
[0055]
[0061] In some examples, software platform 225 may provide a bridge between organization 205 (e.g., an enterprise) and application 210 (e.g., a SaaS application) that uses cloud platform 215-a. For example, organization 205-a may implement (e.g., adopt) application 210-a that uses cloud platform 215-a (e.g., to obtain SSO integration). That is, employees within organization 205-a may use a dashboard (e.g., via a client device) to request access to an application that uses SSO. In such an example, cloud platform 215-a may connect to cloud platform 215-b, which may be the identity provider used by application 210-a for authentication. That is, software platform 225 may manage both sides of the authentication path (e.g., the authentication process flow) used by organization 205-a to access application 210-a. In some examples, by managing both sides of the authentication path, software platform 225 may provide improved identity enforcement for multiple industries. Additionally or alternatively, by managing both sides of the authentication path, software platform 225 may lower the threshold associated with developing enterprise-ready applications and creating an ecosystem that enables flexible and reliable security. That is, software platform 225 may support independent identity providers, which may enable a connected and secure future across stacks or providers (e.g., beyond a single stack or single provider). In some examples, software platform 225 may support SSO adoption from protocols such as secure web authentication (SWA), security assertion markup language (SAML), and open identity connect (OIDC).Additionally or alternatively, through connecting cloud platforms 215 together, software platform 225 may facilitate the implementation of standards, SSO, provisioning, continuous authentication, and fine-grained authorization, among other features, to enhance zero trust and governance for organization 205.
[0056]
[0062] In some examples, software platform 225 may enable applications that can be built using cloud platform 215-b to be accessed using cloud platform 215-a. That is, a developer may build application 210 and use cloud platform 215-b to integrate application 210 with cloud platform 215-a so that users of cloud platform 215-a may access application 210. Additionally or alternatively, software platform 225 may enable developers of application 210 to satisfy enterprise identity constraints and provide developers with information and tools for building enterprise-ready applications. For example, software platform 225 may include content designed to help developers (e.g., SaaS builders) of application 210 implement identity solutions. As discussed herein, identity solutions may refer to features that can be used to solve problems related to managing authentication information or other identification information. The software platform 225 may provide organizations (e.g., businesses) with relative security and increased innovation for the SaaS ecosystem.
[0057]
[0063] For example, an organization 205 may use a software platform 225 to integrate applications 210 (e.g., cloud applications) used in the organization 205 and to centralize identities within the software platform 225 (e.g., rather than individually managing identities within each application 210). That is, the software platform 225 may be connected to each application 210 used in the organization 205. In some examples, connecting multiple applications used in the organization 205 allows the organization 205 to select the appropriate application 210 (e.g., technology) for the organization's business while maintaining security, availability, and productivity, among other examples. That is, the software platform 225 may provide relatively independent identity and neutrality among one or more applications 210. The software platform 225 may connect and integrate applications 210 such that identities may be independent (e.g., separate) from the applications 210. That is, by using software platform 225, users of application 210 may forgo managing multiple (e.g., separate) credentials for each application in application 210. In some examples, software platform 225 may provide one or more alternatives to a monolithic technology stack. That is, software platform 225 may provide an identity solution across multiple stacks and multiple sets of cloud applications. For example, software platform 225 may provide a framework for customizable technology within an organization so that the technology utilized within the organization can be suitable for the organization's business. That is, software platform 225 may enable organization 205 to utilize multiple (e.g., different) ISVs of multiple (e.g., different) types of technology.
[0058]
[0064] In some examples, software platform 225 may be referred to as an integration network. For example, software platform 225 may provide cloud access ecosystem mapping (such that identities may be integrated across the entire cloud access ecosystem). That is, software platform 225 (e.g., an integration network) may connect organization 205 (e.g., users associated with the organization) to multiple applications 210 within software platform 225 (e.g., the cloud access ecosystem). In some examples, connecting an organization to multiple cloud applications through a centralized identity provider (e.g., software platform 225) may reduce the burden associated with managing identities within the organization. Additionally or alternatively, the centralized identity provider may provide automated identity compliance and business processes, including onboarding (e.g., of employees within the organization), compliance review, role change management, or resignation, among other possible examples. In some examples, centralized identities may lead to identities being synchronized across multiple cloud applications (e.g., applications 210) and systems used in an organization (e.g., one or more of organizations 205). Additionally or alternatively, centralized identity may reduce vulnerability to malicious security attacks (e.g., phishing attacks) for example, centralized identity may reduce vulnerability to malicious security attacks not only to users associated with an organization (e.g., employees associated with a digital content team, a development team), but also to infrastructure and contractors associated with the organization.
[0059]
[0065] Additionally or alternatively, software platform 225 providing centralized identity may be able to identify whether a user of an application is a robot or a legitimate user. In some examples, software platform 225 may be able to provide multiple types of login methods, such as passwordless methods or social login methods. Additionally or alternatively, software platform 225 may be able to prevent the use of multiple (e.g., tens of millions) compromised credentials. In some examples, identity may be central to the technology landscape because use of cloud applications, such as application 210, may depend on identity and users may rely on cloud applications to achieve their goals. Thus, by providing centralized identity across users of application 210 and organization 205, software platform 225 may improve the performance of application 210 and organization 205.
[0060]
[0066] In some examples, as an organization evolves (e.g., acquires business, adds resources), managing identities (e.g., of the organization's IT team and digital management team) can become relatively complex and may require managing identities across multiple cloud applications, systems, and devices, among other examples. For example, to be relatively agile and agile, the organization's employees (e.g., workforce) may use multiple types of technology (e.g., securely) to improve performance (e.g., drive better business results), and developers of technology (e.g., applications) may want to build relatively long-term relationships with the organization (e.g., customers). In some examples, building such relationships may begin at the login boxes used by the organization's employees to access applications.
[0061]
[0067] In some examples, software platform 225 may provide a framework for connecting identities across multiple aspects of an organization and may enable management of security parameters associated with an organization (e.g., employees, contractors, and vendors) across a range of endpoints and devices. That is, by using software platform 225, an organization's workforce may securely and seamlessly access resources regardless of whether the workforce accesses the resources by using on-premise or cloud applications, cloud servers, databases, or containers, among other examples. Such security may include visibility across resources and may provide a relatively simple, secure, and user-friendly experience for customers.
[0062]
[0068] Additionally or alternatively, such security may provide increased efficiency and productivity for developers, digital management teams, and security teams while maintaining visibility into how responsibilities relate to the customer experience. That is, software platform 225 may provide increased access to an increased amount of resources while providing control and customizable identity solutions for organizations that utilize software platform 225. Thus, software platform 225 may provide a catalyst for growth within an organization while protecting the organization's workforce and customer base.
[0063]
[0069] For example, by using cloud platform 215-b, software platform 225 may enable increased innovation by developers of application 210. For example, software platform 225 may enable developers to customize the identity (e.g., authorization model) of application 210 (e.g., based on the stack used by the developer). Additionally or alternatively, software platform 225 may provide customizability and extensibility to developers so that developers can tailor the features of application 210 to consumers (e.g., organizations 205) of application 210. Cloud platform 215-b may enhance digital experiences across users (e.g., consumers) and applications (e.g., SaaS applications). Software platform 225 (e.g., an identity platform) may support an interoperability layer across cloud platform 215, which may include an integration network. That is, software platform 225 may include an integration hub between cloud platforms 215 so that developers can create improved digital experiences for customers and organizations can increase workforce productivity.
[0064]
[0070] For example, software platform 225 may facilitate use by organization 205 of cloud platform 215-a (e.g., a workforce identity platform), which may include one or more features. In some examples, employees (or other users, such as contractors) of organization 205 may use cloud platform 215-a (e.g., via one or more client devices) to accelerate business (e.g., as a growth engine) and enable organization 305 to become an identity-first (or identity-powered) organization. That is, cloud platform 215-a may enable an agile workforce, high-performance IT, and identity-driven security for organization 205.
[0065]
[0071] Additionally or alternatively, developers of applications 210 (or other users, such as contractors) may use cloud platform 215-b to improve digital experiences and improve innovation. That is, cloud platform 215-b may provide organizations 205 and developers of applications 210 with access to customizable and scalable technology and increased security reliability. In some examples, by using cloud platform 215, software platform 225 may provide increased security reliability through automation and features for phishing resistance. Additionally or alternatively, software platform 225 (e.g., an identity platform) may provide increased IT productivity and workforce mobility (including enhanced governance and privileged access capabilities) through integrated solutions. For example, software platform 225 may provide unified access governance across cloud platform 215 and access to multiple applications and systems (such as open source systems (e.g., cloud-native k8 infrastructure such as Kubernetes)). For example, software platform 225 may provide password-less access (which may be utilized for PAM) to a cloud-native k8 infrastructure. In some examples, software platform 225 may include cloud-native features for secure access to privileged resources through the use of a privileged credentials vault and privilege governance. As described herein, a credential vault may refer to a repository that stores credentials (e.g., user IDs, passwords) for shared accounts and resources.
[0066]
[0072] In some examples, software platform 225 may provide features for identity management, including anything-as-a-source (XaaS), where software platform 225 may connect to multiple trusted sources (e.g., any trusted source, including a trusted source without integration) and may leverage existing resources (e.g., an existing human resources system) as a source capability. As described herein, a trusted source may refer to the aggregation of data from multiple systems within an organization into a single location. That is, users of application 210 (e.g., one or more of organizations 205) that have an unsupported human resources system may use software platform 225 to realize one or more benefits of XaaS. For example, XaaS may enable organization 205 to integrate multiple (e.g., any) trusted sources with software platform 225, leading to one or more benefits of human resource-driven provisioning from multiple trusted sources. In some examples, the XaaS features provided by the software platform 225 may provide the organization 205 with the flexibility to determine (e.g., define, identify, select) the period of synchronization between the software platform 225 and one or more trusted sources.
[0067]
[0073] For example, software platform 225 (e.g., a unified identity platform) may enable organization 205 with an extended business ecosystem by combining identity and access management features, identity and access governance features, and privileged access management features via a cloud-native control plane, leading to enterprise agility and increased IT productivity. In some examples, software platform 225 may be scalable, flexible, and support multiple users, sources, and resources (including future users, future sources, and future resources). Additionally or alternatively, software platform 225 may be relatively easy to use and improve governance and privileged access by providing features for administrators and users (e.g., of organization 205) and aligning multiple workstreams. In some examples, software platform 225 may provide integrated features of reliability, scalability, and security.
[0068]
[0074] Additionally or alternatively, software platform 225 may include one or more automation features and access technologies to assist organization 205 (e.g., an enterprise) in securing its extended workforce and supply chain. For example, software platform 225 may provide improved organizational security and identity threat response through ecosystem extension and biometric authentication automation, among other examples. For example, software platform 225 may provide enhanced phishing resistance (e.g., end-to-end phishing resistance features), passkey management, enhanced controls for APIs (e.g., web authentication APIs), and passwordless access management capabilities. Additionally or alternatively, software platform 225 may provide enhanced security features for the extended business ecosystem (including biometric login for external business partners), enhanced security checks for unmanaged devices (e.g., devices associated with but not managed by organization 205), and zero trust features across the workforce and supply chain (e.g., business-to-business supply chain) associated with organization 205.
[0069]
[0075] In some examples, software platform 225 may provide multiple security templates and may detect and respond to security incidents by identifying changes in user behavior that may lead to increased security risks for the organization. Additionally or alternatively, software platform 225 may provide automated IT and security operations and one or more connector builders (e.g., an independent software vendor (ISV) no-code flow designer).
[0070]
[0076] For example, software platform 225 (e.g., cloud platform 215-b within software platform 225) may provide one or more Shared Signals and Events (SSE) publish / subscribe messaging sender-receiver connectors (e.g., SSE connectors). In some examples, software platform 225 may provide one or more SSE connectors as an SDK (e.g., used for building applications). For example, software platform 225 may support implementation of an SSE-compatible, scalable, multi-tenant receiver. Additionally or alternatively, software platform 225 may support implementation of an SSE stream composition protocol and may support multiple types of events, such as session invalidation events, IP change events, and risk level change events. In some examples, software platform 225 may provide a means for mapping incoming events to user accounts associated with cloud platform 215-a. Additionally or alternatively, software platform 225 may implement heuristics for actions that may be taken by software platform 225 in response to one or more events being processed. In some examples, software platform 225 may send (e.g., fire) first-party events to a system log, which may be generated by a risk engine based on native user context, first-party risk events, and received third-party events. Additionally or alternatively, software platform 225 may provide a web user interface (UI) for administrators (users of organization 205, which may have administrator privileges) to enable streams from supported vendors (e.g., supported ISVs, ISVs associated with applications used within organization 205). In some examples, software platform 225 may provide a mechanism (e.g., a v1 mechanism) for partners (e.g., other organizations, which may be related to one or more of organization 205) to integrate with cloud platform 215-a.In such examples, software platform 225 may correspond to an ecosystem where developers may use not only an SDK (e.g., relatively few lines of code) but also a receiver connector provided by cloud platform 215-b to integrate with cloud platform 215-a, which may provide a risk engine that can be used with a sender connector provided by cloud platform 215-b in the ecosystem. That is, a connector provided by cloud platform 215-b (e.g., an SDK with relatively few lines of code) may be used as an interface between cloud platform 215-b and cloud platform 215-a. In some examples, by providing such connectors, the software platform may provide increased internal security and zero trust products.
[0071]
[0077] Additionally or alternatively, some connectors may be provided to third parties, for example, to improve performance across a borderless workforce. For example, cloud platform 215-a, cloud platform 215-b, and a third party may use (e.g., consume) the same connector, which may serve as a connection point between a user (e.g., one or both of cloud platforms 215) to the third party. Additionally or alternatively, a connector may be implemented as an SDK (or open source code) so that a third party (e.g., an organizational partner, application 205) can be included within a zero trust ecosystem associated with software platform 225. In some examples, a connector may enable features provided by cloud platform 215-b (e.g., SaaS CLAM) to provide identity building blocks to developers building applications (e.g., SaaS applications) using cloud platform 215-b with zero trust and improved security. In such an example, cloud platform 215-b may offer SCIM directory synchronization (e.g., as part of a SaaS CIAM feature) to improve connectivity between cloud platform 215-b and cloud platform 215-a. Additionally or alternatively, several common SSE connectors may be built within the zero trust ecosystem. In some examples, the connectors help connect developers (e.g., using cloud platform 215-b) and organizations (e.g., businesses using cloud platform 215-a) and provide data ingestion integration between cloud platforms 215-a.
[0072]
[0078] In some examples, software platform 225 may provide identity-centric workforce security along with zero-trust access control and automation. For example, software platform 225 may provide anti-phishing, passwordless, and low-code capabilities that may enable end-to-end identity security for the workforce and supply chain associated with organization 205. For example, software platform 225 may enable extended workforce and supply chain security to protect and manage access for non-employee users (e.g., users associated with the organization who may not be employees of the organization). In some examples, software platform 225 may provide no-code automation and orchestration for identity management.
[0073]
[0079] In some examples, software platform 225 may provide features for increased security across multiple applications (e.g., applications 210), including video conferencing applications. For example, software platform 225 may provide increased security for video conferencing by verifying caller identities across video conferencing applications (e.g., video conferencing platforms). In some examples, software platform 225 may provide native integration for video conferencing applications, where users of organization 205 may securely log in to video conferences by using verification features provided by software platform 225. In such examples, software platform 225 may reduce the likelihood of identity-centric attacks against organization 205 (e.g., while users associated with organization 205 may be using the video conferencing application). In some examples, software platform 225 may provide authentication for end-to-end encrypted video conferencing so that users participating in a video conference can be verified. In such an example, software platform 225 may provide an improved sign-in experience (e.g., login experience) for video conferencing applications, increased security, and password-less authentication, leading to fewer password policy updates and reduced password management for users. That is, software platform 225 may increase productivity by allowing users of video conferencing applications (or other types of applications) to collaborate by signing in (e.g., securely) to software platform 225 by using credentials associated with software platform 225, leading to a password-less or password-selectable experience. Additionally or alternatively, software platform 225 may improve identity-centric security by providing end-to-end encrypted video conferencing via verification features, reducing the administrative burden associated with managing password policies and complex integrations.
[0074]
[0080] In some examples, identity governance supported by software platform 225 (e.g., built into cloud platform 315-a (which includes software platform 225)) may include lifecycle management, which may correspond to the ability to connect to identity sources (e.g., human resources systems) and use these identity sources as a single source of truth. Additionally or alternatively, identity governance supported by software platform 225 may include access requests, which may correspond to a request and approval process that allows users associated with organization 205 to request and approve access to resources by using one or more applications (e.g., a common chat-based application). In some examples, identity governance supported by software platform 225 may include access authentication, which may provide governance policies and audit reports. Additionally or alternatively, identity governance supported by software platform 225 may include workflow, which may provide identity automation and orchestration capabilities with low-code or no-code.
[0075]
[0081] In some examples, cloud-native k8 infrastructure access management (e.g., Kubernetes access management) provided by software platform 225 may include one or more functionalities for deploying and troubleshooting applications running within cloud-native k8 infrastructure while complying with organizational security policies. Additionally or alternatively, cloud-native k8 infrastructure access management provided by software platform 225 may provide visibility into one or more (for example) cloud-native k8 infrastructure clusters that users of organization 205 may access, regardless of whether they previously had access to the cloud-native k8 infrastructure cluster (e.g., as part of onboarding or accessing a cluster deployed in the environment). In some examples, cloud-native k8 infrastructure access management provided by software platform 225 may include features to reduce the amount of time spent on technical assistance related to cloud-native k8 infrastructure access (e.g., assisting developers with setting up custom wrapper scripts or tools to access cloud-native k8 infrastructure clusters). Additionally or alternatively, the cloud-native k8 infrastructure access management provided by software platform 225 may provide an improved end-user experience for authentication to the cloud-native k8 infrastructure, regardless of whether the cluster may be deployed (e.g., on a cloud server, a hybrid server, or an on-premise server).In some examples, using the cloud-native k8 infrastructure software platform 225, access management may provide increased developer velocity by streamlining developer onboarding and offboarding processes, reduced code and systems that can be written and maintained by developers for access to the cloud-native k8 infrastructure, reduced downtime by allowing developers to access production Kubernetes infrastructure (e.g., relatively safely) without violating security policies, improved productivity by allowing developers to access the cloud-native k8 infrastructure with a single authentication, by satisfying internal and external security standards for applications hosted within the cloud-native k8 infrastructure, and by reducing operational overhead for site reliability engineers.
[0076]
[0082] In some examples, privileged access management features supported by software platform 225 may include privileged access services that may enable customers (e.g., organizations 205, developers of applications 210) to achieve compliance and business continuity by securing human, machine, and application access to resources. For example, a customer may be able to satisfy IAM, IGA, and PAM constraints (e.g., criteria) by using software platform 225 (e.g., a unified first-to-the-cloud platform for identity). That is, software platform 225 may support a single, unified IAM, IGA, and PAM platform for relatively secure access with multiple levels (e.g., any level) of privileges.
[0077]
[0083] In some examples, use of PAM software platform 225 may enable organization 205 to meet evolving compliance and security constraints with cloud-native PAM features that may be integrated with organization 205's respective infrastructure. For example, use of software platform 225 may enable organization 205 to implement a zero trust approach to security. In some examples, PAM capabilities supported in software platform 225 may provide credential vaulting and rotation for local user accounts and human-managed shared secrets, and may provide just-in-time (JIT) access request and approval workflows for humans, machines, and application users, etc., reducing unnecessary standing permissions to the attack surface associated with organization 205 (e.g., by using a least privilege model, POLP). Additionally or alternatively, PAM capabilities supported in software platform 225 may provide privileged access reporting and session management capabilities that may provide audit trails to detect and prevent unwanted behavior and to help verify (e.g., attest) compliance. In some examples, software platform 225 may provide passwordless access management by using ephemeral credential-based authorization across multiple infrastructures (e.g., multiple platforms, networks, or systems). In some examples, a least privilege model may correspond to a model of reduced privilege escalation, a model for reducing (e.g., minimizing) the amount of access to privileged resources at a given time. For example, a relatively high percentage (e.g., about 80%) of breaches may target servers. Thus, software platform 225 may contain access to servers by server administrators. For example, software platform 225 may withhold some privileges from server administrators.
[0078]
[0084] In some examples, PAM capabilities (e.g., features) supported in software platform 225 may include vaulting and rotation of privileged account credentials, private key management, single sign-on and zero trust access to infrastructure (e.g., managed resources including servers, k8s, and databases and applications), PAM compliance reporting, PAM access request and approval, PAM zero standing privilege and step-up of multi-factor authentication, PAM session recording, PAM session management, cloud infrastructure entitlement management, PAM audit and even logging, and PAM access certification, among other examples of PAM capabilities.
[0079]
[0085] In some examples, PAM capabilities (e.g., features) supported in software platform 225 may include use of ephemeral credential-based server access services that can be expanded to include a relatively broad range of infrastructure (such as cloud-native k8 infrastructure and one or more databases). Additionally or alternatively, PAM capabilities may include use of a cloud-native vault for shared account password management. In some examples, PAM capabilities of software platform 225 may assist both developers requesting access to a cloud-native k8 infrastructure cluster and operations managers requesting root access to make maintenance changes.
[0080]
[0086] In some examples, PAM capabilities may be integrated with identity governance capabilities that support a least privilege model. For example, by using software platform 225, organization 205 may implement (e.g., integrate) multiple tools, including IAM tools for access, IGA tools for governance, PAM tools for privileged resources, and cloud infrastructure entitlement management (CIEM) tools for cloud entitlements, and may reduce the burden associated with manually integrating such tools. That is, multiple tools supported in software platform 225 may enhance security, connectivity, and automation for workforce identity and access management within organization 205.
[0081]
[0087] In some examples, the XaaS capabilities supported in software platform 225 may include human resources as source functionality for automating IT processes related to users (e.g., individuals) joining, moving within, or leaving organization 205. For example, some human resources as a source system may constrain an organization to use a human resources system with an existing integrated network or on-premise deployment. In other examples, the XaaS capabilities supported in software platform 225 may provide human resources as a source capability (or multiple source capabilities) to multiple trusted sources (e.g., any trusted source). For example, software platform 225 may provide an API that organization 205 can use to send data from a source (e.g., to software platform 225) and use a human resources system as a source capability (e.g., user validation, user matching and linking, profile mapping, and import monitoring, among other examples) included within software platform 225. In some examples, the human resources services software platform 225 may allow users to write custom connectors or leverage workflows to identify from multiple sources.
[0082]
[0088] In some examples, phishing-resistant features supported in software platform 225 can determine whether an authentication request is from an authentic (e.g., correct, preferred) server, thereby providing phishing resistance for multiple (e.g., all) managed devices and platforms used on devices managed by organization 205 and devices not managed by organization 205 (e.g., using channel binding). For example, an attacker may send a message (e.g., email) to a user associated with organization 205-a, which may include a malicious link to an inauthentic server (e.g., a spoofed site). In such an example, the user may use software platform 225 to attempt to log on to the inauthentic server in response to receiving the message. In response, the software platform may stamp a key associated with the inauthentic server, which the attacker may obtain (e.g., intercept). In some examples, the attacker may attempt to use a key provided by software platform 225 from the inauthentic server on the corresponding authentic server. In such an example, the key may fail. That is, in response to detecting that the server associated with the link is not authentic, software platform 225 may take one or more actions to ensure that a key obtained by an attacker cannot be used to access resources associated with software platform 225 (e.g., protected websites and applications).
[0083]
[0089] In some examples, a passkey (e.g., multi-device web authentication certificate) management feature supported in software platform 225 may allow an administrator of organization 205 to decide to block passkeys for some groups or users. For example, a multi-device web authentication certificate, which may be referred to as a passkey, may provide one or more benefits to end users (including reducing the frequency with which a user may register or re-register an account), for example, if the user uses multiple (e.g., various) devices. In such examples, multiple devices may store authentication information as a passkey. In such examples, a user may use (e.g., regenerate) authentication information via the passkey. Additionally or alternatively, a passkey may allow a user to use some devices (e.g., a smartphone) as a roaming authenticator. However, in such examples, using a passkey may lead to increased security risks for organization 205 because, for example, authentication information may be stored on (e.g., backed up to) other servers associated with the user (e.g., a personal server, a personal cloud, a server not associated with software platform 225). Thus, software platform 225 may provide a feature to prevent users from using passkeys that may be backed up to a server not associated with software platform 225 (eg, a personal cloud).
[0084]
[0090] In some examples, web authentication authenticator features supported in software platform 225 may include finer-grained control of web authentication authenticators (e.g., passkeys). For example, using software platform 225 for web authentication may enable a respective administrator of organization 205 to block (e.g., restrict access to) one or more authenticators (e.g., one or more FIDO authenticators). Additionally or alternatively, such features may enable an administrator of organization 205 to initiate web authentication registration for each user (e.g., employee) associated with organization 205. For example, software platform 225 may enable organization 205 to limit web authentication registration to hardware keys issued by one or more organizations (e.g., specific organizations) to prevent hardware-based phishing attempts. In some examples, control of web authentication authenticators supported in software platform 225 may include the ability to allow or block a list of web authentication authenticators and administrator-initiated web authentication registration. In some examples, using the software platform 225 for web authentication may allow the organization 205 to obtain a set of FIDO authenticators (e.g., hardware authenticators) that may automatically enroll users (e.g., employees, including new hires) and trigger the software platform 225 to send a message containing a key, thereby increasing phishing resistance.
[0085]
[0091] In some examples, the Borderless Workforce passwordless authenticator can increase phishing resistance on multiple devices and operating systems. Additionally or alternatively, the passwordless authenticator can be used in conjunction with unified access management, identity governance, and privileged access capabilities tools supported in software platform 225 to provide a passwordless experience for multiple users and multiple resources (including privileged resources).
[0086]
[0092] In some examples, multi-factor authentication features supported in software platform 225 may include biometric web login. For example, software platform 225 may support expanded options for the use of biometric authentication (e.g., facial recognition, contact recognition, fingerprint recognition) for an improved passwordless experience for users. Additionally or alternatively, multi-factor authentication features supported in software platform 225 may include enhanced security checks for unmanaged devices (which may support the ability to perform security posture checks on unmanaged devices and define appropriate access policies to enforce security posture). For example, the multi-factor authentication feature may cause software platform 225 to perform one or more verification processes when an application is installed on a device (e.g., phone, tablet) of a user associated with organization 205 so that organization 205 can obtain information related to the device's security posture. In some examples, the validation process may include detecting one or more signals that may indicate whether the device may be jailbroken (e.g., modified to remove restrictions imposed by the manufacturer or operator to allow the installation of unauthorized software); the OS version of the device; whether the device may have a code (e.g., a PIN code) to unlock the device's lock screen; and whether disk encryption may be enabled on the device. The software platform 225 may support such validation processes for multiple types of devices and multiple operating systems to understand whether devices used for organization-related activities may have updated operating systems and use PIN codes, among other examples, to enable each administrator of the organization 205 to build customizable security policies.
[0087]
[0093] In some examples, workflows supported in the software platform 225 may include workflow solution packs that may assist the organization 205 (e.g., a customer) with identity-based automation by using a collection of customizable (e.g., pre-built) templates used to perform tasks. For example, a workflow solution pack may include templates for capturing contract signatures, account provisioning, device activation, and sending notifications across multiple devices associated with the organization 205. In some examples, a workflow solution pack may include security templates that may enable automation across security operations center processes used within the organization 205. For example, security templates may enable the software platform 225 to detect and respond to security incidents (e.g., risks that may pose a risk to the organization 205) by identifying changes in user behavior. Additionally or alternatively, security templates may enable the organization 205 to continuously monitor and improve the respective security posture associated with the organization 205. That is, security templates may provide assistance to respective security operations teams associated with organization 205 by providing customizable (e.g., and pre-built) workflows for security awareness, identity automation and response, incident investigation and response, threat intelligence, and user behavior analysis. In some examples, security templates may provide automation for security policy enforcement at the identity layer by identifying changes in user behavior (e.g., changes that may create risk to the organization), detecting and responding to suspicious user or entity activity, and monitoring (e.g., continuous monitoring) the security posture associated with the organization.
[0088]
[0094] In some examples, one or more connector builders supported in the software platform 225 may provide for building workflow connectors within a no-code flow designer (e.g., supported in the software platform 225). For example, using the connector builder, an ISV (e.g., a developer) may build a connector for the organization 205 (e.g., a customer), and each administrator of the organization 205 may build a connector to connect custom tools (e.g., to the application 210). That is, the connector builder may provide no-code development of workflow connectors, where, among other examples, organizations, ISVs, and developers may use workflows to build connectors (e.g., by using a drag-and-drop interface), leading to on-demand productized connectors to third-party or internal systems with APIs available on the public internet. In some examples, connectors and templates may be used to automate prevention and response use cases to support enhanced security.
[0089]
[0095] In some examples, the use of workflows may reduce the time period used to deploy applications and may enable relatively smooth and secure provisioning for privileged accounts, such as system administrators. For example, some users may rely on standard accounts for computer login, email, and other user tasks (which may require logging into a separate privileged account to perform high-level administrative tasks). In other examples, no-code workflow platform services supported in software platform 225 may enable users to perform such tasks (e.g., via software platform 225) by using SSO.
[0090]
[0096] In some examples, verification features supported in the software platform 225 may include features that can prove and verify a user's identity in an end-to-end encrypted video conference (e.g., without involving the back-end infrastructure used for communication between the software platform 225 and the application through which the video conference is taking place). In some examples, use of such verification features may enable the organization 205 to create a password-optional or password-less sign-in experience for end users, and may reduce the amount of time associated with enrollment and increase security associated with the sign-in experience because users may obtain relatively strong authenticators, such as possession-based authenticators or biometric authenticators. In some examples, use of such authenticators may reduce end-user password management (e.g., including remembering or maintaining passwords via one or more other tools).
[0091]
[0097] In some examples of passwordless onboarding using software platform 225, a first user (e.g., an IT operations administrator associated with organization 205-a) may set policies for users to ensure end-to-end passwordless and phishing-resistant access. In such examples, organization 205-a may use the software platform to register and onboard a second user (e.g., an employee of organization 205-a) with a null password. Additionally or alternatively, a third user (e.g., a contractor of organization 205-a) may use software platform 225 to gain secure access to resources associated with organization 205-a. In some examples, the third user may log in to application 210-a and initiate downloading a file (e.g., a media file) from a resource associated with application 210-a. In such examples, application 210 may detect the activity and use a workflow (e.g., set up by organization 205-a using software platform 225) to notify software platform 225. In such an example, software platform 225 may suspend the third user's access to the application and one or more other applications to which the third user may have access (e.g., may suspend the third user's session). Additionally or alternatively, software platform 225 may send an indication of the event to one or more users (e.g., a security operations team) associated with organization 205-a or one or more other organizations.
[0092]
[0098] In some examples, a second user (e.g., an employee who may be part of a security operations team) may receive an indication of the event from software platform 225 (e.g., via a client device). In such examples, the second user may perform forensics on an infrastructure to which a third user may have access. In some examples, the second user may request access to a server via software platform 225 to perform forensics. In such examples, software platform 225 may send a request to a fourth user associated with the organization (e.g., an administrator) to approve or deny the second user's request. In some examples, in response to the fourth user approving the second user's resources, software platform 225 may send the second user a link to a secure shell that the second user can use to perform forensics. In some examples, software platform 225 may record the session used by the first user to perform forensics via an audit trail. Additionally or alternatively, if application 210-a may use (e.g., may be deployed using, or may be integrated with) software platform 225, an event (e.g., a security incident) may trigger an access authentication campaign to scrutinize a third user's access to application 210-a. In such an example, a first user may scrutinize an event-driven authentication campaign that may identify details related to the third user's access (including the time when application 210-a may be accessible, the time when access to the application may be granted to the third user, the period during which the third user last used application 210-a, and other information related to the event). The techniques for integrating multiple identity clouds described herein may provide one or more capabilities to improve performance associated with ISVs, IT vendors, and employees, among other examples.
[0093] supplement:
[0094]
[0099] In some examples, software platform 225 may support a single-select configuration option (e.g., a push button), which may be referred to as one-click configuration within cloud platform 215-b. For example, after a developer may build a resource (e.g., a website, an application, an identity feature, a security feature) by using cloud platform 215-b, the developer may decide to integrate the resource into cloud platform 215-a (e.g., publish the application to cloud platform 215-a). In such an example, the developer may use one click to synchronize metadata from cloud platform 215-b (e.g., a process used to build the resource) with cloud platform 215-a (e.g., a marketplace with public applications) without providing information to cloud platform 215-a or cloud platform 215-b (e.g., without completing a form within cloud platform 215-a, such as by using an integration network administrator). In some examples, such a process may reduce complexity and increase the rate of development (e.g., and integration network operations) for ISVs. In some examples, Synchronization between cloud platform 215-b and cloud platform 215-b using one-click configuration may be performed for multiple types of applications, such as private applications that may be built from outside of cloud platform 215-b. In such an example, an ISV may share configured applications with automatic metadata synchronization between cloud platform 215-b and cloud platform 215-b using one-click configuration. In some examples, one-click configuration may be accessible through a dashboard (e.g., a managed dashboard) provided by software platform 225.
[0095]
[0100] For example, software platform 225 may support super federation, where software platform 225 may provide improved SAML with one-click configuration (e.g., one-click federation). For example, some techniques for implementing (e.g., onboarding) an application and enabling SSO for the application may be relatively challenging and error-prone. For example, some configuration screens in an application may be relatively complex and may use SAML, assertion customer service uniform resource locators (ACS URLs), signing certificates, name identifiers, and claims mappings, among other examples. In such an example, an administrator onboarding such an application may spend an increased amount of time copying and pasting information from multiple (e.g., various) documents to satisfy the application's constraints (e.g., signing certificates, name identifiers) in an attempt to configure SSO. Additionally or alternatively, such information may be updated in response to changing or updated integrations. In some instances, ISVs may provide guidance to their customers on how to integrate their applications with identity providers such as software platform 225.
[0096]
[0101] In some other examples, using one-click configuration supported in software platform 225, an ISV can automate the configuration of an identity provider with reduced (e.g., minimal) user input. For example, using software platform 225, an ISV can initiate the registration process based on an email address associated with a user (e.g., by using tools provided by software platform 225 for attaching information to an email address or other online resource) or by requiring the user to enter a FastFed Discovery Endpoint. In such examples, in response to initiating the registration process, an IT administrator (or other user associated with the organization) can be redirected to an associated identity provider (e.g., software platform 225) that the IT administrator can use to confirm the registration process. In some examples, after completing the registration process, resources can be created (e.g., an application can be integrated into software platform 225 and software platform 225 can be registered as an identity provider). In such examples, a connection (e.g., a communication channel) can be established for use in signing key rotation scenarios and other (e.g., future) scenarios. In some examples, software platform 225 may support more secure shadow IT. For example, configuring SSO may be performed by an IT administrator in some examples, which may lead to one or more issues if, for example, the application is not onboarded. In some examples, an IT administrator may use a free-tier or on a trial account to configure SSO, which may lead to one or more security risks. Additionally or alternatively, a company may lack visibility into applications used by employees.
[0097]
[0102] In some other examples, an IT administrator may use software platform 225, which may serve as an identity provider that may integrate with ISVs. For example, by using software platform 225, company employees may use corporate credentials to sign applications for use. Additionally or alternatively, by using software platform 225, an IT administrator may track the applications used by employees and select applications to onboard. In some examples, software platform 225 may generate and output reports to the IT administrator. In some examples, the reports may provide insight into the applications used by employees. Additionally or alternatively, an IT administrator may use software platform 225 to codify some of the company policies to govern the types of applications that may be used (e.g., in a self-service context). For example, an IT administrator may use software platform 225 to restrict access to applications that may comply with one or more standards (e.g., applications that may be SOC2 compliant). That is, in some examples, the software platform 225 may accommodate a single global identity provider and IT administrator that may provide one or more enhancements for ISVs, among other examples.
[0098]
[0103] Additionally or alternatively, software platform 225 may support a system for SAML and cross-domain identity management (SCIM) using one-click configuration and provisioning. For example, software platform 225 may provide a one-click SAML extension, which may enable software platform 225 to provision users and groups to applications (e.g., SaaS applications). In some examples, the SAML extension may also provide SCIM for provisioning (which may be part of one or more specifications, such as the FastFed specification). In some examples, one-click configuration and provisioning may allow IT administrators (e.g., or other users associated with an organization) to enable SSO for users and automate the provisioning and deprovisioning (e.g., of applications or resources within an application) to users (e.g., single users or groups of users). In some examples, software platform 225 may be used as an identity graph. For example, some ISVs may forego (or may not be able to use) the use of an identity provider to add users and groups to applications. For example, the ISV may use a synchronization process or may choose to query the identity provider (e.g., in real time) to avoid using a local copy of the data (e.g., and managing synchronization and conflicts). In such an example, the ISV may use software platform 225 (e.g., one-click configuration supported by software platform 225) that may allow the ISV to request read access to the organization's directory. In such an example, the ISV may query users and groups (e.g., via software platform 225) by using a graph API. Additionally or alternatively, software platform 225 may include an endpoint that may provide the ISV with a set of changes that may be used during the synchronization process.For example, an ISV may use a stream (eg, data) of features (eg, a people picker).
[0099]
[0104] In some examples, software platform 225 may support a marketplace where ISVs using software platform 225 can offer cutting-edge capabilities (e.g., as part of an application) to users (e.g., within the marketplace). For example, a user may use an application (e.g., a SaaS application) from the marketplace. In such an example, an IT administrator may be able to install an application from within the marketplace. In some examples, this installation may establish a connection (e.g., a channel) to the application. For example, this connection may occur between an account within the application and a directory associated with an organization. In some examples, software platform 225 may offer subscription and license management features that may integrate with one or more IGA capabilities (including future IGA capabilities). In some examples, upon installing an application, an IT administrator may be provided with an option to connect to software platform 225 (e.g., which may include one-click configuration).
[0100]
[0105] In some examples, to use one or more features supported by software platform 225, an ISV may be constrained to support and maintain standards (e.g., the FastFed standard), SAML, and SCIM. Additionally or alternatively, as FastFed adoption increases, the ISV may create and maintain an increased amount (or variety) of integrations with multiple identity providers. In such examples, the ISV may use cloud platform 215-b, which may enable FastFed, SAML, and SCIM to be transparent to the ISV. For example, the ISV may integrate its application with cloud platform 215-b and use one or more authentication and management SDKs (e.g., provided by cloud platform 215-b). In such examples, cloud platform 215-b may implement the FastFed standard, integrate with SAML, and support inbound SCIM provisioning. In some examples, software platform 225 may provide one or more resources for multi-tenant SaaS applications. For example, software platform 225 may combine with cloud platform 215 to provide capabilities such as a marketplace where users can install applications (e.g., trial or purchase) with SSO and / or provisioning. In some examples, the marketplace may provide a framework for ensuring enterprise-ready quality.
[0101]
[0106] In some examples, software platform 225 may support SAML and OIDC as well as standardize identity provider protocols. Additionally or alternatively, software platform 225 may reduce friction associated with onboarding (e.g., customer acquisition), reduce password management, or restore flow for organization 205, and enable organization 205 to delegate account management and multi-factor authentication to software platform 225. In some examples, software platform 225 may enable users (e.g., end users) to self-service SSO applications, reduce threads of account takeover, reduce credential reuse or leaks, enable enforcement of multi-factor authentication for non-IT-managed applications, reduce security incidents, and provide visibility into shadow IT by providing information related to applications used by employees. In some examples, software platform 225 may reduce the friction of enterprise adoption of SaaS applications (e.g., increased licenses), reduce the cost of supporting SSO, and increase the security (e.g., reduce liability) of SaaS applications (e.g., passwordless). Additionally or alternatively, software platform 225 may support relatively seamless (e.g., zero-downtime) upgrades of applications and may enable automated workflows for scalability. In some examples, software platform 225 may support mapping for enterprise-ready features, support competitive differentiation, and reduce barriers associated with application adoption by larger organizations. Additionally or alternatively, software platform 225 may support governance and security controls for self-service adoption, scalability of security controls, and enforcement, and reduce manual steps in security management.In some examples, the software platform may support increased adoption or engagement and "stickiness" by enabling employees to collaborate with teams and companies, and may enable ISVs to obtain information from organizations by using applications without identity provider push. Additionally or alternatively, the software platform 225 may support fine-grained delegation of enterprise directories to applications (which may be auditable, for example). In some examples, the software platform 225 may facilitate customer payments and funnel conversion to billing and procurement integrations.
[0102]
[0107] For example, software platform 225 may enable organizations to obtain SSO SaaS applications and provisioning from cloud platform 215-a, the ability to sign in through software platform 225, enterprise acquisition of self-service applications, enterprise policies, and marketplaces (e.g., try or buy). Additionally or alternatively, software platform 225 may support control plane APIs for identity providers and service providers (e.g., including SAML or OpenID Connect and SCIM) for SSO and provisioning configurations. In some examples, the software platform may enable configuration (e.g., traditional configuration) or trust setup between identity provider and service provider entities. Additionally or alternatively, the software platform may support an identity provider flow or a service provider flow for handshakes.
[0103]
[0108] 3 illustrates an example of a block diagram 300 that supports a technique for integrating multiple identity clouds according to some aspects of the present disclosure. In some examples, block diagram 300 may implement or be implemented by aspects of system 100 and block diagram 200. For example, block diagram 300 may be implemented in software platform 325, one or more cloud platforms 315 (e.g., cloud platform 315-a, cloud platform 315-b), one or more client devices 320 (e.g., client device 320-a, client device 320-b), client device 320c, client device 320-d, or any combination thereof, which may be examples of corresponding entities as described with reference to FIGS.
[0104]
[0109] In some examples, organization 305 may use software platform 325 to manage resources across multiple identity clouds. For example, software platform 325 may provide a framework through which an organization may request access to resources across an increasing number of software applications with reduced complexity while maintaining security and compliance. For example, software platform 325 may provide one or more services for developers to build (e.g., and deploy (via cloud platform 315-b)) software applications and may provide services for organizations (e.g., organization 305) that consume those applications (e.g., via cloud platform 315-b), thereby providing an improved experience for interaction between developers and organizations. That is, a user (e.g., an employee of an organization, a developer 305 of application 310) may use software platform 325 to access cloud platform 315-a (e.g., a workforce identity platform) and cloud platform 315-b via a client device (e.g., client device 320-a, client device 320-b, client device 320c). For example, by using client device 320, a user may interact with a dashboard associated with software platform 325, which may include one or more features. The one or more features may include customer identity and workforce identity, a marketplace, a partner portal (e.g., a portal where ISVs may deploy (e.g., publish) extensions to the marketplace), an access gateway, server access, authorization, account management (e.g., a portal for managing access requests, inboxes), and an identity grid (e.g., an identity control plane for enabling developers and administrators of an organization to manage resources across cloud platform 315-a and cloud platform 315-b), among other possible features.
[0105]
[0110] As shown in the example of FIG. 3 , a developer may use cloud platform 315-b to build application 310 and publish application 310. In some examples, application 310 may be an example of an application (e.g., a super application) that may include multiple integrations (e.g., full-level integrations) including SSO provisioning of user accounts and fine-grained entitlements, among other examples of integrations. For example, the developer may send a request to access cloud platform 315-b to software platform 325 (e.g., via client device 320-d and using a first credential or credentials). Software platform 325 may grant access to cloud platform 315-b based on the first credential or credentials satisfying a threshold. In response to receiving access to cloud platform 315-b, the developer may use cloud platform 315-b to build code for application 310. In some examples, a developer may use predefined (e.g., predetermined) code provided by cloud platform 315-b. Additionally or alternatively, a developer may use software platform 325 to integrate application 310 into cloud platform 315-b for use within cloud platform 315-a. In some examples, a developer may use a dashboard associated with cloud platform 315-b to build (e.g., select, customize) an authorization model that software platform 325 can use to determine whether users of application 310 can gain access to application 310 (e.g., and resources (e.g., resource 311) within application 310). In some examples, the authorization model may include a uniform data model and configuration language for expressing a relatively wide range of access control policies from multiple client services (e.g., hundreds of client services). In some examples, the authorization model may include multiple (e.g., various) policies for multiple (e.g., various) resources within application 310.For example, a developer may assign access restrictions (e.g., per resource or per multiple resources) for a user, a set of users (e.g., a team), or an organization (e.g., a company). In some examples, an authorization model may identify whether one or more users can edit or view (or both) resources within application 310.
[0106]
[0111] In some examples, a developer may use software platform 325 to publish (e.g., deploy) application 310 to the marketplace. In some examples, a developer may publish one or more other types of actions to the marketplace. For example, a developer may publish social ties, SSO interactions, log streams, short messaging service (SMS) providers, among other types of actions. In some examples, as part of publishing application 310 to the marketplace (e.g., for use by users via cloud platform 315-a), a developer may select one or more resources associated with the application to which users may be able to request access. For example, a developer may enable users to request access to resource 311.
[0107]
[0112] In such examples, a user associated with organization 305 may use software platform 325 to request access to application 310 (e.g., and resources 311 within application 310) via cloud platform 315-a. For example, a first user may send a request to software platform 325 to access cloud platform 315-a (e.g., via client device 320-a and by using second one or more credentials). Software platform 325 may grant access to cloud platform 315-a based on the second one or more credentials satisfying a threshold. In some examples, in response to the first user obtaining access to cloud platform 315-a, the first user (e.g., an IT operations administrator) may install application 310 from cloud platform 315-b to a portal within cloud platform 315-a that may be associated with organization 305. In some examples, the portal may include resources (e.g., any resource) that may be accessed by users associated with organization 305.
[0108]
[0113] In some examples, a second user (e.g., a marketing leader associated with organization 305) may send a request to software platform 325 (e.g., via client device 320-b and by using the third one or more credentials) to access cloud platform 315-a. Software platform 325 may grant access to cloud platform 315-a based on the third one or more credentials satisfying a threshold. In response to the second user obtaining access to cloud platform 315-a, the second user may request access to application 310. For example, the second user may use a portal associated with organization 305 to determine whether application 310 may be available to the second user, such that the second user may request access to application 310. In some examples, access to application 310 by the second user may be based on an authorization model determined by the developer of application 310. In some examples, the request from the second user may trigger software platform 325 to send an indication of the request (e.g., a notification (e.g., via an instant messaging program)) to the first user. In some examples, software platform 325 may send the request according to identity governance features associated with software platform 325. In such examples, the first user may receive the notification and may approve or deny the request. In other examples, software platform 325 may approve the request based on one or more other criteria that may be determined using the identity governance features. The second user may use the portal to determine whether the request to access the application is authorized.
[0109]
[0114] Additionally or alternatively, a third user (e.g., a marketing designer) may send a request to access cloud platform 315-a to software platform 325 (e.g., via client device 320-c and by using the fourth credential(s). Software platform 325 may grant access to cloud platform 315-a based on the fourth credential(s) satisfying a threshold. In response to the third user gaining access to cloud platform 315-a, the third user may request access to resources 311 within application 310. For example, the third user may use a portal associated with organization 305 to determine whether application 310 and resources 311 may be available to the third user, such that the third user may request access to application 310. In some examples, access to resources 311 by the third user may be based on an authorization model determined by the developer of application 310. In some examples, the third user may receive automatic approval to access the resource 311 through an authorization process associated with the software platform 325 .
[0110]
[0115] In some examples, organization 305 may use cloud platform 315-a (e.g., a workforce identity cloud) to improve employee experience and protect organization 305 (e.g., a company) from cyberattacks that may target employee credentials. For example, organization 305 may acquire (e.g., acquire) another organization. In such an example, organization 305 may decide to integrate one or more technology stacks associated with organization 305 with one or more technology stacks associated with the acquired organization (which may increase organization 305's vulnerability to cyberattacks, such as phishing attacks, in which an attacker may attempt to obtain authentication information, such as passwords and usernames, from organization 305). In some examples, to help protect organization 305 from cyberattacks, organization 305 may decide to use software platform 325 as an identity provider so that organization 305 can forgo the use of passwords. For example, software platform 325 may include one or more features within cloud platform 315-a that may enable organization 305 to access multiple types of resources via passwordless login. For example, a user associated with organization 305 may access (e.g., log in to) multiple applications (e.g., via client device 320-a) by using a fingerprint (or another type of authentication information other than a password) associated with the user. That is, the user may use a fingerprint (e.g., via client device 320-a) to log in to software platform 325 so that the user may access multiple applications, among other types of features. For example, in response to logging in to software platform 325, the user may access an email account associated with the user.
[0111]
[0116] In some examples, software platform 325 may include one or more features capable of detecting phishing attacks (or one or more other types of cyber-attacks) related to resources (e.g., applications 310, resources 311) managed in software platform 325. For example, an attacker may use phishing campaign emails to attack a user (e.g., and one or more other users associated with organization 305) as part of an attempt to gain access to privileged information. In such an example, a user may receive a first email that may include a link (e.g., a hyperlink, a digital reference to data that a user can follow or be directed to by clicking) to a website. The user may select (e.g., click) the link to access the website. In some examples, in response to clicking the link (e.g., via client device 320-a), the user may receive a second email. For example, software platform 325 may send a message (e.g., second email) to the user indicating that the first email may be related to a phishing attack and that software platform 325 may block the user from accessing the link. That is, regardless of whether a user clicks on a link associated with a phishing attack, software platform 325 may detect the phishing attack and may block the phishing attack accordingly (e.g., block access to the link so that the phishing attack can be prevented). In some examples, using a fingerprint to log in to software platform 325 may help prevent phishing attacks (e.g., by eliminating passwords that a phishing attack could attempt to obtain). Additionally or alternatively, software platform 325 may perform a domain check and verify whether the requested website (e.g., associated with the link) may be authentic. In some examples, software platform 325 may block the website in response to detecting that the website is not authentic (e.g., a fake).In some examples, software platform 325 (e.g., a unified platform) may include a workflow that may trigger security actions (e.g., determined by organization 305 using cloud platform 315-a) in response to detecting a phishing attack. For example, according to this workflow, software platform 325 may send a message to one or more other users (e.g., a security team) associated with organization 305 that may indicate to one or more users that a phishing attack has occurred. Additionally or alternatively, the message may indicate first information associated with the phishing attack (e.g., an Internet Protocol address associated with the phishing attack), second information associated with an action to be taken in response to the phishing attack, or both. In some examples, in response to detecting a phishing attack associated with organization 305, software platform 325 may indicate (e.g., share) the first information or the second information (or both) with other organizations that may use software platform 325. That is, software platform 325 may share information (e.g., signals) related to an event (e.g., a phishing attack, other type of cyber-attack) across software platform 325 (e.g., an identity network) to increase insight and action. That is, if software platform 325 detects a security event related to an organization (e.g., a customer), software platform 325 may use the information related to the security event to increase security across multiple (e.g., all) organizations using software platform 325. For example, software platform 325 may block IP addresses (e.g., malicious Internet Protocol addresses) related to a phishing attack across multiple (e.g., various) users across multiple (e.g., various) organizations.
[0112]
[0117] In some examples, software platform 325 may be able to securely provision and de-provision access to applications (e.g., privileged applications). For example, application 310 may be an example of a ticketing platform used in organization 305 to manage users (e.g., technicians, employees) and delegate tickets (e.g., tasks) to them. In such an example, application 310 may send a request to a first user (e.g., via client device 320-a) indicating that a ticket may have been delegated to the first user. In some examples, the ticket may identify a problem (e.g., an issue) associated with another entity (e.g., an application, a system, a network) associated with software platform 325. For example, the ticket may indicate an issue with a cloud-native k8 infrastructure node (e.g., a Kubernetes node). In response to receiving an indication of the ticket, the first user may update a status associated with the ticket (e.g., via client device 320-a). In some examples, in response to the ticket status being updated and based on the first user logging into software platform 325, software platform 325 may send an indication of the first user's request for access to another entity (e.g., cloud-native k8 infrastructure) so that the first user can address the issue identified by the ticket. For example, software platform 325 may send an indication of this request to a second user associated with organization 305 (e.g., via client device 320-b). In some examples, the second user may receive the indication and approve or deny the request. That is, software platform 325 may include features to automate provisioning and deprovisioning and support identity governance flows (e.g., for managing access requests and credentials). For example, in response to the first user updating the ticket status (e.g., to active or another preferred state), software platform 325 may trigger (e.g., automatically) the sending of a corresponding access request.In some examples, the first user may update the state of the ticket from an active state to another state, such as a closed state (or another preferred state). In such examples, the software platform 325 may (e.g., automatically) revoke the user's access to other entities. That is, the software platform 325 may allow the first user with access (e.g., privileged access) for the period used by the first user to perform (e.g., and complete) work (work related to the request). For example, using the software platform 325 may enable password-less login to multiple resources, thwart cyber-attacks, automate incident response, and enable the organization 305 to improve employee experience by securely managing user access and requests to applications (e.g., privileged applications).
[0113]
[0118] In some examples, a developer of application 310 may use cloud platform 315-b (e.g., via client device 320-d) to build application 310. For example, the developer may seek a balance between security, usability, and innovation for application 310. In such examples, software platform 325 may enable the developer to achieve balance by allowing the developer to build a custom stack for connecting the application (e.g., application 310) to a relatively diverse ecosystem of preferred identity providers and capabilities.
[0114]
[0119] In some examples, a user profile may determine what a user can view and edit within application 310. In such examples, software platform 325 may increase the user experience by allowing users to log in to a user profile with reduced complexity across multiple devices while maintaining security. In some examples, using software platform 225, developers may increase innovation by reducing the amount of time used to maintain standards compliance and security patches associated with maintaining the security of application 310.
[0115]
[0120] In some examples, compromised passwords and forged authentication information can lead to one or more security risks. For example, login boxes can be used to mitigate access to shared computer resources. Some login boxes can include multiple (e.g., two) fields, such as a username and password (e.g., with reduced constraints on the password). In some examples, a user's password can be stored (e.g., as clear text) in a database table associated with a website. In some examples, if passwords are used to protect resources such as finances, utilities, and public documents, a password breach can have relatively severe consequences for both the user and the entity (e.g., the business) that controls access to the resource. Accordingly, secure user logins can be associated with one or more complexity constraints, such as password constraints (e.g., alphanumeric characters, uppercase letters, lowercase letters, special characters, requiring passwords to be changed monthly). However, implementing such authentication complexity can be relatively difficult and can therefore lead to password reuse across multiple websites. In some examples, password reuse can increase the value of passwords, making user credentials a target for hacking or compromise. For example, an attacker may obtain a list of email addresses and compromised passwords to gain unauthorized access to user accounts. That is, passwords may pose a security risk. For example, passwords may be insufficient in securing a user's identity. Therefore, to increase security, some organizations may use multi-factor authentication. However, in some instances, multi-factor authentication may reduce the user experience of an application and therefore may be insufficient.
[0116]
[0121] However, in some examples, the software platform 325 may use a platform authenticator to secure user identities (e.g., at scale). For example, a web authentication authenticator may use hardware device and biometric authentication to increase security. For example, the software platform 325 may use web authentication in combination with device biometric authentication to reduce login complexity and enable user authentication with a security chip built into the device. In some examples, using web authentication in combination with device biometric authentication may provide a phishing-resistant web authentication method.
[0117]
[0122] In some examples, using web authentication along with device biometrics may support a passwordless adoption blocker, but may be device-bound. For example, devices may be individually provisioned and transitioned, for example, if a user changes (e.g., updates) their device. In some examples, the software platform 325 may use a passkey to support passwordless authentication across multiple devices and multiple platforms.
[0118]
[0123] For example, the application 310 may correspond to a streaming service that may be configured to authenticate a user with a username and password. In such an example, a developer may use the cloud platform 315-b (e.g., via the client device 320-d) to update the authentication capabilities of the application 310. A user may send a request to enable a passkey (e.g., by using a database connection associated with the application 310). In such an example, the application 310 may include a feature that allows a user to generate a passkey. For example, the cloud platform 315-b may update code associated with the software platform to include code that may enable the application 310 to detect whether the user's device is capable of using a passkey. In such an example, if the application 310 detects that the user's device is capable of using a passkey, the application may request that the user generate a passkey (e.g., by using a biometric authentication formula). For example, a text box associated with sign-in (e.g., a username field) may include an autocomplete attribute (e.g., an autocomplete tag) that instructs the browser and operating system used by the user to use a passkey. Thus, a user may sign in to an application by using a fingerprint sensor (or another type of biometric authentication). In such an example, the user may use the same flow for authentication across multiple devices that use the same account (e.g., an account associated with a passkey).
[0119]
[0124] Additionally or alternatively, cloud platform 315-b may provide extensibility points (called identity pipelines) throughout the authentication process. For example, cloud platform 315-b may allow users to deploy custom code (which may be called actions) to provide a customizable experience for users, and may allow developers to provide custom user experiences. For example, a developer of application 310 may use several actions and cloud platform 315-b to manage access to resources (e.g., resource 311, streaming content library) within application 310.
[0120]
[0125] Developers of applications 310 may be constrained by regional regulations and copyright laws. Thus, developers may want to block users located in countries where a company associated with the developer of application 310 may not do business. Additionally, developers may want to control the content users are authorized to stream based on their location. In some examples, actions supported in software platform 325 may allow developers to customize and extend points in the identity flow. For example, developers may use no-code solutions provided by software platform 325 (e.g., by using a marketplace), or developers may write and execute custom code. In some examples, coding using software platform 325 may be done using a serverless environment where actions can be tested, debugged, and versioned (e.g., directly from within a browser). In some examples, developers may block logins from certain countries, or may use actions that restrict access to users by country, or both.
[0121]
[0126] In some examples, a developer may use the software platform 325 to customize the content available in the application 310 based on information contained in a user profile and the user's location at the time of sign-in. For example, a developer may create custom actions (e.g., write code using JavaScript or Node) to manage the user profile and enrich the identifier token with custom claims. In some examples, a set of SDKs (e.g., SDKs provided by the software platform 325) may allow a developer to use information from the user profile to define the content a user can access. In some examples, the software platform 325 may include libraries that allow a developer to create actions. Additionally or alternatively, a developer may use the libraries to define triggers and runtimes associated with actions. A developer may deploy (e.g., add and apply) actions to a login flow associated with the application 310. In some examples, developers may use one or more capabilities supported by software platform 325 to manage authentication based on group rates, account partnerships with internet providers, and account tiering, among other examples. In some examples, the actions and extensibility points provided by software platform 325 may enable developers to support and connect to a variety of hybrid environments.
[0122]
[0127] In some examples, software platform 325 may improve a developer's customer identity by supporting identity and security standards to increase security for customers and end users. For example, using software platform 325, cloud platform 315-b may be invoked by application 310, which may be hosted using one or more cloud servers. Additionally or alternatively, software platform 325 may provide security to other servers that developers may use to build and run code. For example, software platform 325 may provide reduced security risks for developers by providing an enterprise-ready identity platform.
[0123]
[0128] In some examples, software platform 325 may be associated with one or more other platforms such that software platform 325 may provide cloud platform 315-b with customer identity capabilities that can be used by developers to build applications. Additionally or alternatively, software platform 325 may support decentralized identity. That is, software platform 325 may support identity standards and passkeys and increase protection of customer identities, support integration of user profiles into business services, and associate (e.g., partner) with cloud providers to increase customer identity for developers (regardless of the framework used to develop the application or where the code associated with the application may run).
[0124]
[0129] In some examples, software platform 325 may support verifiable credentials. For example, by using cloud platform 315-b, software platform 325 may be able to obtain and verify credentials. In some examples, software platform 325 may use an SDK that can be integrated into a hosted application by using cloud platform 315-b. For example, application 310 (e.g., a developer of application 310) may use verifiable credentials, but application 310 may be unable to identify the verifiable credentials. In such examples, application 310 may send a request for verifiable credentials to software platform 325. The request may include one or more parameters (e.g., a country or a hospital with which the vaccination registry may be associated). In response to the request, software platform 325 may provide verifiable credentials to application 310 that may satisfy the one or more parameters. That is, software platform 325 may generate a protocol request (e.g., a wallet) that software platform 325 may use to obtain parameters associated with application 310 and use the parameters to generate a protocol. In some examples, software platform 325 may provide application 310 with a link to a wallet that can satisfy the parameters. In some examples, software platform 325 may include an API that obtains requests for verifiable credentials (e.g., for protocols) from applications such as application 310 (which may be hosted outside of cloud platform 315-b). In some examples, software platform 325 may include a framework for combining credential data and may support a credential builder by using the combined credential data.
[0125]
[0130] In some examples, verifying traditional credentials may be relatively time-consuming and may offer reduced security. For example, an image of the credential may be captured or created. In some examples, a verifiable credential may be used, where a user who possesses the verifiable credential may present it to a requester. In such examples, the verifiable credential may be verified (e.g., immediately) by the requester. In some examples, a user may complete a course to obtain a verifiable credential, which the user may store in a digital wallet. In some examples, a developer may use software platform 325 to configure application 310 as a credential issuer. In such examples, a developer may use cloud platform 315-b to generate a credential template. A developer may provide some information about the template to explain the purpose associated with the template. Additionally or alternatively, a developer may brand the template so that a user receiving the template can determine that the template is relevant to application 310. In some examples, a developer may use software platform 325 to publish templates. For example, to use a template, a developer may use the software platform 325 to configure a sequence of activities and enable one or more settings (eg, related to the use of the template).
[0126]
[0131] FIG. 4 illustrates an example process flow 400 that supports techniques for integrating multiple identity clouds according to some aspects of the present disclosure.
[0127]
[0132] In some examples, process flow 400 may implement aspects of system 100, block diagram 200, and block diagram 300. For example, process flow 400 may depict operations between software platform 425 and client device 405-a and client device 405-b, which may be examples of subsystem 125 and client device 105, respectively, as described with reference to FIGS. 1-3 . Process flow 400 may be implemented in software platform 425, client device 405, or both. In the following description of process flow 400, information communicated between software platform 425 and client device 405 may occur in a different order or at different times than shown. Additionally or alternatively, some operations may be omitted from process flow 400, and other operations may be added to process flow 400.
[0128]
[0133] At 430, the software platform may receive a first request to build a resource from a first user (e.g., via client device 405b). The first user may be an example of a developer as described throughout this disclosure (including as described with reference to FIGS. 2 and 3). For example, the first user may use cloud platform 415-b to build the resource. In some examples, as part of the first request, the first user may build (e.g., request to build) an authorization model for the resource by using cloud platform 415-b, which may be associated with software platform 425. The authorization model may be an example of an authorization model as described throughout this disclosure (including as described with reference to FIGS. 2 and 3). For example, the authorization model may identify one or more parameters associated with accessing the resource by using cloud platform 415b.
[0129]
[0134] At 435, software platform 425 may receive a second request from the first user to integrate resources with cloud platform 415-a according to the authorization model. For example, the first user may request to publish resources on a marketplace (e.g., an integration network) included within cloud platform 415-a. In some examples, as part of the second request, the first user may use one-click configuration, which may be an example of one-click configuration described throughout this disclosure (including that described with reference to FIG. 2). For example, the first user may use one-click configuration (e.g., a process used to build resources) to synchronize metadata from cloud platform 415-b with cloud platform 415-a (e.g., a marketplace with published applications).
[0130]
[0135] At 440, software platform 425 may authorize the first request and the second request by using a directory associated with software platform 425. For example, software platform 425 may authorize the first request based on first authentication information associated with the first user, and in such an example, software platform 425 may authorize the second request based on the authorization of the first request. That is, the first user may submit multiple requests by using SSO.
[0131]
[0136] At 445, software platform 425 may receive a third request from a second user (e.g., via client device 405a) to access a resource by using cloud platform 415-a, which may be associated with software platform 425. In some examples, the request may be an example of an access request described throughout this disclosure (including those described with reference to FIGS. 2 and 3). For example, the third request may be sent by using a message-based application.
[0132]
[0137] At 450, software platform 425 may authorize the third request by using a directory associated with software platform 425. In some examples, authorization of the third request may be performed in software platform 425 according to an authorization model and based on second authentication information associated with the second user.
[0133]
[0138] 5 shows a block diagram 500 of a device 505 that supports techniques for integrating multiple identity clouds according to some aspects of the present disclosure. The device 505 may include an input module 510, an output module 515, and a software platform 520. The device 505 may also include a processor. Each of these components may be in communication with each other (e.g., via one or more buses).
[0134]
[0139] The input module 510 may manage input signals for the device 505. For example, the input module 510 may identify input signals based on interaction with a modem, keyboard, mouse, touchscreen, or similar device. These input signals may relate to user input or processing in other components or devices. In some cases, the input module 510 may utilize an operating system, such as iOS®, ANDROID®, MS-DOS®, MS-WINDOWS®, OS / 2®, UNIX®, LINUX®, or another known operating system, to handle the input signals. The input module 510 may send aspects of these input signals to other components of the device 505 for processing. For example, the input module 510 may send input signals to the software platform 520 to support techniques for integrating multiple identity clouds. In some cases, the input module 510 may be a component of an I / O controller 710, as described with reference to FIG. 7.
[0135]
[0140] Output module 515 may manage output signals of device 505. For example, output module 515 may receive signals from other components of device 505, such as software platform 520, and may transmit these signals to other components or devices. In some examples, output module 515 may transmit output signals for display in a user interface, for storage in a database or data storage, for further processing on a server or cluster of servers, or for any other process in any number of devices or systems. In some cases, output module 515 may be part of an I / O controller 710 as described with reference to FIG. 7.
[0136]
[0141] For example, software platform 520 may include a build request component 525, an integration request component 530, an authorization component 535, an access request component 540, or any combination thereof. In some examples, software platform 520 or its various components may be configured to perform various operations (e.g., receiving, monitoring, transmitting) using or otherwise in conjunction with input module 510, output module 515, or both. For example, software platform 520 may receive information from input module 510 and transmit this information to output module 515, or may be integrated in combination with input module 510, output module 515, or both to receive and transmit information or to perform various other operations as described herein.
[0137]
[0142] The software platform 520 may assist in managing resources in the software platform of the device according to examples such as those disclosed herein. The construction request component 525 may be configured to assist in receiving a first request from a first user to construct an authorization model for a resource by using a first cloud platform associated with the software platform, where the authorization model identifies one or more parameters associated with accessing the resource by using a second cloud platform associated with the software platform. The integration request component 530 may be configured to assist in receiving a second request from the first user to integrate the resource with the second cloud platform according to the authorization model. The authorization component 535 may be configured to assist in authorizing the first request and the second request by using a directory associated with the software platform, where the authorization of the first request and the second request is based on first authentication information associated with the first user. The access request component 540 may be configured to assist in receiving a third request from the second user to access the resource by using a second cloud platform associated with the software platform. The authorization component 535 may be configured to assist in authorizing the third request by using a directory associated with the software platform, where the authorization of the third request is in accordance with an authorization model and is based on second authentication information associated with the second user.
[0138]
[0143] 6 shows a block diagram 600 of a software platform 620 supporting techniques for integrating multiple identity clouds according to some aspects of the present disclosure. Software platform 620 may be an example of a software platform as described herein, or aspects of software platform 520, or both. Software platform 620 or its various components may be an example of a means for performing various aspects of techniques for integrating multiple identity clouds as described herein. For example, software platform 620 may include a construction request component 625, an integration request component 630, an authorization component 635, an access request component 640, a connection component 645, a privilege component 650, an event component 655, or any combination thereof. Each of these components may communicate directly or indirectly with each other (e.g., via one or more buses).
[0139]
[0144] The software platform 620 may assist in managing resources in the software platform of the device according to examples such as those disclosed herein. The construction request component 625 may be configured to assist in receiving a first request from a first user to construct an authorization model for a resource by using a first cloud platform associated with the software platform, where the authorization model identifies one or more parameters associated with accessing the resource by using a second cloud platform associated with the software platform. The integration request component 630 may be configured to assist in receiving a second request from the first user to integrate the resource with the second cloud platform according to the authorization model. The authorization component 635 may be configured to assist in authorizing the first request and the second request by using a directory associated with the software platform, where the authorization of the first request and the second request is based on first authentication information associated with the first user. The access request component 640 may be configured to assist in receiving a third request from the second user to access the resource by using a second cloud platform associated with the software platform. In some examples, the authorization component 635 may be configured to assist in authorizing the third request by using a directory associated with the software platform, where the authorization of the third request follows an authorization model and is based on second authentication information associated with the second user.
[0140]
[0145] In some examples, the connection component 645 may be configured to facilitate establishing a connection between the second cloud platform and the resource in response to authorizing the third request. In some examples, the authorization component 635 may be configured to facilitate establishing an authorization scheme by using the connection between the second cloud platform and the resource according to an authorization model, where the authorization scheme includes single-sign-on authorization.
[0141]
[0146] In some examples, the privilege component 650 may be configured to facilitate assigning privileges to the second user by using a connection between the second cloud platform and the resource, where the privileges are based on an authorization model. In some examples, the connection component 645 may be configured to facilitate sending information corresponding to a security event associated with the resource to the first user and based on the connection between the second cloud platform and the resource.
[0142]
[0147] In some examples, the connection component 645 may be configured to facilitate receiving information corresponding to a security event associated with the resource from a first user and based on a connection between the second cloud platform and the resource. In some examples, the event component 655 may be configured to facilitate transmitting information corresponding to a security event associated with the resource to a second user. In some examples, the resource is included within a software application.
[0143]
[0148] 7 shows a diagram of a system 700 including a device 705 that facilitates techniques for integrating multiple identity clouds according to some aspects of the present disclosure. The device 705 may be an example of, or may include components of, device 505 as described herein. The device 705 may include components for two-way data communication, including components for sending and receiving communications (e.g., a software platform 720, an I / O controller 710, a memory 725, and a processor 730). These components may be in electronic communication or otherwise coupled (e.g., operably, communicatively, functionally, electronically, electrically) via one or more buses (e.g., bus 740).
[0144]
[0149] The I / O controller 710 may manage input signals 745 and output signals 750 for the device 705. The I / O controller 710 may also manage peripheral devices not integrated into the device 705. In some cases, the I / O controller 710 may represent a physical connection or port to an external peripheral device. In some cases, the I / O controller 710 may utilize an operating system such as iOS®, ANDROID®, MS-DOS®, MS-WINDOWS®, OS / 2®, UNIX®, LINUX®, or another known operating system. In other cases, the I / O controller 710 may represent or interact with a modem, keyboard, mouse, touchscreen, or similar device. In some cases, the I / O controller 710 may be implemented as part of the processor 730. In some examples, a user may interact with the device 705 through the I / O controller 710 or through hardware components controlled by the I / O controller 710.
[0145]
[0150] Memory 725 may include random access memory (RAM) and ROM. Memory 725 may store computer-readable, computer-executable software that includes instructions that, when executed, cause processor 730 to perform various functions described herein. In some cases, memory 725 may include a BIOS that may control basic hardware or software operations, such as interaction with peripheral components or devices, among other things.
[0146]
[0151] The processor 730 may include an intelligent hardware device (e.g., a general-purpose processor, a DSP, a CPU, a microcontroller, an ASIC, an FPGA, a programmable logic device, discrete gate or transistor logic components, discrete hardware components, or any combination thereof). In some cases, the processor 730 may be configured to operate a memory array by using a memory controller. In other cases, the memory controller may be integrated into the processor 730. The processor 730 may be configured to execute computer-readable instructions stored in the memory 725 to perform various functions (e.g., functions or tasks that support techniques for integrating multiple identity clouds).
[0147]
[0152] The software platform 720 may assist in managing resources in a software platform of a device according to examples such as those disclosed herein. For example, the software platform 720 may be configured to assist in receiving a first request from a first user to establish an authorization model for a resource by using a first cloud platform associated with the software platform, where the authorization model identifies one or more parameters associated with accessing the resource by using a second cloud platform associated with the software platform. The software platform 720 may be configured to assist in receiving a second request from the first user to integrate the resource with the second cloud platform according to the authorization model. The software platform 720 may be configured to assist in authorizing the first request and the second request by using a directory associated with the software platform, where the authorization of the first request and the second request is based on first authentication information associated with the first user. The software platform 720 may be configured to assist in receiving a third request from the second user to access the resource by using a second cloud platform associated with the software platform. The software platform 720 may be configured to assist in authorizing the third request by using a directory associated with the software platform, where the authorization of the third request is in accordance with an authorization model and is based on second authentication information associated with the second user.
[0148]
[0153] By including or configuring software platform 720 according to examples as described herein, device 705 may support reduced latency, improved user experience techniques.
[0149]
[0154] FIG. 8 shows a flowchart illustrating a method 800 facilitating techniques for integrating multiple identity clouds according to some aspects of the present disclosure. The operations of method 800 may be performed by a device such as those described herein or components thereof. For example, the operations of method 800 may be performed by a device such as those described with reference to FIGS. 1-7. In some examples, the device may execute a set of instructions that control functional elements of the device to perform the described functions. Additionally or alternatively, the device may perform aspects of the described functions by using dedicated hardware.
[0150]
[0155] At 805, the method may include receiving a first request from a first user to build an authorization model for a resource by using a first cloud platform associated with the software platform, where the authorization model identifies one or more parameters associated with accessing the resource by using a second cloud platform associated with the software platform. The operations of 805 may be performed according to examples as disclosed herein. In some examples, aspects of the operations of 805 may be performed by a build request component 625 as described with reference to FIG. 6.
[0151]
[0156] At 810, the method may include receiving a second request from the first user to integrate resources with a second cloud platform according to the authorization model. The operations of 810 may be performed according to examples as disclosed herein. In some examples, aspects of the operations of 810 may be performed by an integration request component 630 as described with reference to FIG. 6.
[0152]
[0157] At 815, the method may include authorizing the first request and the second request by using a directory associated with the software platform, where the authorization of the first request and the second request is based on first authentication information associated with the first user. The operations of 815 may be performed according to examples as disclosed herein. In some examples, aspects of the operations of 815 may be performed by an authorization component 635 as described with reference to FIG. 6.
[0153]
[0158] At 820, the method may include receiving a third request from a second user to access the resource by using a second cloud platform associated with the software platform. The operations of 820 may be performed according to examples as disclosed herein. In some examples, aspects of the operations of 820 may be performed by the access request component 640 as described with reference to FIG. 6.
[0154]
[0159] At 825, the method may include authorizing the third request by using a directory associated with the software platform, where the authorization of the third request is according to an authorization model and based on second authentication information associated with the second user. The operations of 825 may be performed according to examples as disclosed herein. In some examples, aspects of the operations of 825 may be performed by an authorization component 635 as described with reference to FIG. 6.
[0155]
[0160] FIG. 9 shows a flowchart illustrating a method 900 facilitating techniques for integrating multiple identity clouds in accordance with some aspects of the present disclosure. The operations of method 900 may be performed by a device such as those described herein or components thereof. For example, the operations of method 900 may be performed by a device such as those described with reference to FIGS. 1-7. In some examples, the device may execute a set of instructions that control functional elements of the device to perform the described functions. Additionally or alternatively, the device may perform aspects of the described functions by using dedicated hardware.
[0156]
[0161] At 905, the method may include receiving a first request from a first user to build an authorization model for a resource by using a first cloud platform associated with the software platform, where the authorization model identifies one or more parameters associated with accessing the resource by using a second cloud platform associated with the software platform. The operations of 905 may be performed according to examples as disclosed herein. In some examples, aspects of the operations of 905 may be performed by a build request component 625 as described with reference to FIG. 6.
[0157]
[0162] At 910, the method may include receiving a second request from the first user to integrate resources with a second cloud platform according to the authorization model. The operations of 910 may be performed according to examples as disclosed herein. In some examples, aspects of the operations of 910 may be performed by an integration request component 630 as described with reference to FIG. 6.
[0158]
[0163] At 915, the method may include authorizing the first request and the second request by using a directory associated with the software platform, where the authorization of the first request and the second request is based on first authentication information associated with the first user. The operations of 915 may be performed according to examples as disclosed herein. In some examples, aspects of the operations of 915 may be performed by an authorization component 635 as described with reference to FIG. 6.
[0159]
[0164] At 920, the method may include receiving a third request from a second user to access the resource by using a second cloud platform associated with the software platform. The operations of 920 may be performed according to examples as disclosed herein. In some examples, aspects of the operations of 920 may be performed by an access request component 640 as described with reference to FIG. 6.
[0160]
[0165] At 925, the method may include authorizing the third request by using a directory associated with the software platform, where the authorization of the third request is according to an authorization model and based on second authentication information associated with the second user. The operations of 925 may be performed according to examples as disclosed herein. In some examples, aspects of the operations of 925 may be performed by an authorization component 635 as described with reference to FIG. 6.
[0161]
[0166] At 930, the method may include establishing a connection between the second cloud platform and the resource in response to authorizing the third request. The operations of 930 may be performed according to examples as disclosed herein. In some examples, aspects of the operations of 930 may be performed by a connection component 645 as described with reference to FIG. 6.
[0162]
[0167] A method for managing resources in a software platform of a device is described. The method may include receiving a first request from a first user to establish an authorization model for the resource by using a first cloud platform associated with the software platform, the authorization model identifying one or more parameters associated with accessing the resource by using a second cloud platform associated with the software platform; receiving a second request from the first user to integrate the resource with the second cloud platform according to the authorization model; authorizing the first request and the second request by using a directory associated with the software platform, the authorization of the first request and the second request being based on first authentication information associated with the first user; receiving a third request from a second user to access the resource by using the second cloud platform associated with the software platform; and authorizing the third request by using the directory associated with the software platform, the authorization of the third request being according to the authorization model and based on second authentication information associated with the second user.
[0163]
[0168] An apparatus for managing resources in a software platform of a device is described. The apparatus may include a processor, a memory coupled to the processor, and instructions stored in the memory. The instructions may be executable by a processor to cause the apparatus to: receive a first request from a first user to establish an authorization model for a resource by using a first cloud platform associated with the software platform, the authorization model identifying one or more parameters associated with accessing the resource by using a second cloud platform associated with the software platform; receive a second request from the first user to integrate the resource with the second cloud platform according to the authorization model; authorize the first request and the second request by using a directory associated with the software platform, the authorization of the first request and the second request being based on first authentication information associated with the first user; receive a third request from a second user to access the resource by using a second cloud platform associated with the software platform; and authorize the third request by using a directory associated with the software platform, the authorization of the third request being according to the authorization model and based on second authentication information associated with the second user.
[0164]
[0169] Another apparatus for managing resources in a software platform of a device is described. The apparatus may include means for receiving a first request from a first user to establish an authorization model for a resource by using a first cloud platform associated with the software platform, the authorization model identifying one or more parameters associated with accessing the resource by using a second cloud platform associated with the software platform; means for receiving a second request from the first user to integrate the resource with the second cloud platform according to the authorization model; means for authorizing the first request and the second request by using a directory associated with the software platform, the authorization of the first request and the second request being based on first authentication information associated with the first user; means for receiving a third request from a second user to access the resource by using a second cloud platform associated with the software platform; and means for authorizing the third request by using a directory associated with the software platform, the authorization of the third request being according to the authorization model and based on second authentication information associated with the second user.
[0165]
[0170] A non-transitory computer-readable medium storing code for managing resources in a software platform of a device is described. The code may include instructions executable by a processor to: receive a first request from a first user to establish an authorization model for a resource by using a first cloud platform associated with the software platform, the authorization model identifying one or more parameters associated with accessing the resource by using a second cloud platform associated with the software platform; receive a second request from the first user to integrate the resource with the second cloud platform according to the authorization model; authorize the first request and the second request by using a directory associated with the software platform, the authorization of the first request and the second request being based on first authentication information associated with the first user; receive a third request from a second user to access the resource by using a second cloud platform associated with the software platform; and authorize the third request by using a directory associated with the software platform, the authorization of the third request being according to the authorization model and based on second authentication information associated with the second user.
[0166]
[0171] Some examples of the methods, apparatus, and non-transitory computer-readable media described herein may further include operations, features, means, or instructions for establishing a connection between the second cloud platform and the resource in response to granting the third request.
[0167]
[0172] Some examples of the methods, apparatuses, and non-transitory computer-readable media described herein may further include operations, features, means, or instructions for establishing an authorization scheme by using a connection between the second cloud platform and the resource according to an authorization model, wherein the authorization scheme includes single-sign-on authorization.
[0168]
[0173] Some examples of the methods, apparatuses, and non-transitory computer-readable media described herein may further include operations, features, means, or instructions for assigning privileges to the second user by using a connection between the second cloud platform and the resource, where the privileges may be based on an authorization model.
[0169]
[0174] Some examples of the methods, apparatus, and non-transitory computer-readable media described herein may further include operations, features, means, or instructions for transmitting information corresponding to a security event associated with the resource to the first user and based on a connection between the second cloud platform and the resource.
[0170]
[0175] Some examples of the methods, apparatus, and non-transitory computer-readable media described herein may further include operations, features, means, or instructions for receiving information corresponding to a security event associated with a resource from a first user and based on a connection between a second cloud platform and the resource.
[0171]
[0176] Some examples of the methods, apparatus, and non-transitory computer-readable media described herein may further include operations, features, means, or instructions for transmitting information corresponding to a security event associated with the resource to a second user.
[0172]
[0177] In some examples of the methods, the devices, and non-transitory computer-readable media, resources described herein may be included within a software application.
[0173]
[0178] It should be noted that the above-described methods describe possible implementations, that operations and steps may be rearranged or otherwise modified, and that other implementations are possible. Furthermore, aspects from two or more of the methods may be combined.
[0174]
[0179] The descriptions set forth herein with reference to the accompanying drawings illustrate example configurations and, as such, do not represent every example that may be implemented or that is within the scope of the claims. As used herein, the term "exemplary" means "serving as an example, instance, or illustration," and therefore does not mean "preferred" or "advantageous over other examples." The detailed description includes specific details for the purpose of providing an understanding of the described technology. However, these technologies may be practiced without these specific details. In some instances, well-known structures and devices are shown in block diagram form to avoid unnecessarily obscuring the concepts of the described examples.
[0175]
[0180] In the accompanying drawings, similar parts or features may have the same reference label. Furthermore, various parts of the same type may be distinguished by following the reference label with a dash and a second label that distinguishes among the similar parts. Even if only the first reference label is used herein, the description is applicable to any one of the similar parts having the same first reference label regardless of the second reference label.
[0176]
[0181] The information and signals described herein may be represented using any of a wide variety of technologies and techniques. For example, the data, instructions, commands, information, signals, bits, symbols, and chips that may be referenced throughout the above description may be represented by voltages, currents, electromagnetic waves, magnetic fields or particles, optical fields or particles, or any combination thereof.
[0177]
[0182] The various example blocks and modules described in connection with this disclosure may be implemented or performed by a general purpose processor, a DSP, an ASIC, an FPGA or other programmable logic device, discrete gate or transistor logic, discrete hardware components, or any combination thereof designed to perform the functions described herein. A general purpose processor may be a microprocessor, but in the alternative, the processor may be any conventional processor, controller, microcontroller, or state machine. A processor may also be implemented as a combination of computing devices (e.g., a combination of a DSP and a microprocessor, multiple microprocessors, one or more microprocessors in conjunction with a DSP core, or any other such configuration).
[0178]
[0183] The functions described herein may be implemented in hardware, software executed by a processor, firmware, or any combination thereof. If implemented in software executed by a processor, the functions may be stored on or transmitted as one or more instructions or code on a computer-readable medium. Other examples and implementations are within the scope of this disclosure and the appended claims. For example, due to the nature of software, the functions described above may be implemented using software executed by a processor, hardware, firmware, hardwired, or any combination thereof. Features implementing the functions may also be physically located in various locations (including being distributed so that portions of the function are performed in various physical locations). Also, as used herein (including in the claims), "or" used in a list of items (e.g., a list of items prefaced by phrases such as "at least one of" or "one or more of") indicates an inclusive list, such as, for example, a list of at least one of A, B, or C means A or B or C or AB or AC or BC or ABC (i.e., A and B and C). Also, as used herein, the phrase "based on" should not be construed as a reference to a closed set of conditions. For example, an exemplary process described as "based on condition A" may be based on both condition A and condition B without departing from the scope of the present disclosure. In other words, as used herein, the phrase "based on" shall be interpreted in the same manner as the phrase "based at least in part on."
[0179]
[0184] Computer-readable media includes both non-transitory computer storage media and communication media, including any medium that facilitates transfer of a computer program from one place to another. Non-transitory storage media may be any available medium that can be accessed by a general-purpose or special-purpose computer. By way of example, and without limitation, non-transitory computer-readable media may include RAM, ROM, Electrically Erasable Programmable Read Only Memory (EEPROM), Compact Disc (CD) ROM or other optical disk storage, magnetic disk storage, or other magnetic storage devices, or any other non-transitory medium that can be used to carry or store desired program code means in the form of instructions or data structures and that can be accessed by a general-purpose or special-purpose computer or a general-purpose or special-purpose processor. Also, any connection is properly termed a computer-readable medium. For example, if software is transmitted from a website, server, or other remote source using coaxial cable, fiber optic cable, twisted pair, digital subscriber line (DSL), or wireless technology (such as infrared, radio, and microwave), the coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technology (such as infrared, radio, and microwave) are included within the definition of medium. As used herein, disk and disc include CD, laser disc, optical disc, digital versatile disc (DVD), floppy disk, and Blu-ray disc. Note that disks typically replicate data magnetically, while discs replicate data optically with a laser. Combinations of the above are also included within the scope of computer-readable media.
[0180]
[0185] The description herein is provided to enable any person skilled in the art to make or use the disclosure. Various modifications to the disclosure will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other variations without departing from the scope of the disclosure. Thus, the disclosure is not intended to be limited to the examples and designs described herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. 1. A method for managing resources in a software platform of a device, comprising: receiving a first request from a first user to establish an authorization model for a resource by using a first cloud platform associated with the software platform, the authorization model identifying one or more parameters associated with accessing the resource by using a second cloud platform associated with the software platform; receiving a second request from the first user to integrate the resource with the second cloud platform in accordance with the authorization model; authorizing the first request and the second request by using a directory associated with the software platform, wherein authorization of the first request and the second request is based at least in part on first authentication information associated with the first user; receiving a third request from a second user to access the resource by using the second cloud platform associated with the software platform; and authorizing the third request by using the directory associated with the software platform, wherein the authorization of the third request is in accordance with the authorization model and is based at least in part on second authentication information associated with the second user; A method comprising:
2. The method of claim 1 , further comprising establishing a connection between the second cloud platform and the resource in response to authorizing the third request.
3. 3. The method of claim 2, further comprising establishing an authorization scheme by using the connection between the second cloud platform and the resource according to the authorization model, wherein the authorization scheme includes single sign-on authorization.
4. 3. The method of claim 2, further comprising assigning privileges to the second user by using the connection between the second cloud platform and the resource, wherein the privileges are based at least in part on the authorization model.
5. 3. The method of claim 2, further comprising transmitting information corresponding to a security event associated with the resource to the first user and based at least in part on the connection between the second cloud platform and the resource.
6. 3. The method of claim 2, further comprising receiving information corresponding to a security event associated with the resource from the first user and based at least in part on the connection between the second cloud platform and the resource.
7. The method of claim 6 , further comprising transmitting the information corresponding to the security event associated with the resource to the second user.
8. The method of claim 1 , wherein the resource is contained within a software application.
9. 1. An apparatus for managing resources in a software platform of a device, comprising: processor, a memory coupled to the processor; and Instructions stored in the memory, the instructions comprising: receiving a first request from a first user to establish an authorization model for a resource by using a first cloud platform associated with the software platform, the authorization model identifying one or more parameters associated with accessing the resource by using a second cloud platform associated with the software platform; receiving a second request from the first user to integrate the resource with the second cloud platform in accordance with the authorization model; authorizing the first request and the second request by using a directory associated with the software platform, wherein authorization of the first request and the second request is based at least in part on first authentication information associated with the first user; receiving a third request from a second user to access the resource by using the second cloud platform associated with the software platform; and authorizing the third request by using the directory associated with the software platform, wherein the authorization of the third request is in accordance with the authorization model and is based at least in part on second authentication information associated with the second user; instructions executable by the processor to cause the device to An apparatus comprising:
10. 10. The apparatus of claim 9, wherein the instructions are further executable by the processor to cause the apparatus to establish a connection between the second cloud platform and the resource in response to granting the third request.
11. 11. The apparatus of claim 10, wherein the instructions are further executable by the processor to cause the apparatus to establish an authorization scheme by using the connection between the second cloud platform and the resource in accordance with the authorization model, wherein the authorization scheme includes single sign-on authorization.
12. 11. The apparatus of claim 10, wherein the instructions are further executable by the processor to cause the apparatus to assign privileges to the second user by using the connection between the second cloud platform and the resource, the privileges based at least in part on the authorization model.
13. 11. The device of claim 10, wherein the instructions are further executable by the processor to cause the device to transmit information corresponding to a security event associated with the resource to the first user and based at least in part on the connection between the second cloud platform and the resource.
14. 11. The device of claim 10, wherein the instructions are further executable by the processor to cause the device to receive information corresponding to a security event associated with the resource based at least in part on the connection from the first user and between the second cloud platform and the resource.
15. 15. The device of claim 14, wherein the instructions are further executable by the processor to cause the device to transmit the information corresponding to the security event associated with the resource to the second user.
16. The apparatus of claim 9 , wherein the resource is contained within a software application.
17. 1. A non-transitory computer-readable medium storing code for managing resources in a software platform of a device, the code comprising instructions executable by a processor, the instructions comprising: receiving a first request from a first user to establish an authorization model for a resource by using a first cloud platform associated with the software platform, the authorization model identifying one or more parameters associated with accessing the resource by using a second cloud platform associated with the software platform; receiving a second request from the first user to integrate the resource with the second cloud platform in accordance with the authorization model; authorizing the first request and the second request by using a directory associated with the software platform, wherein authorization of the first request and the second request is based at least in part on first authentication information associated with the first user; receiving a third request from a second user to access the resource by using the second cloud platform associated with the software platform; and authorizing the third request by using the directory associated with the software platform, wherein the authorization of the third request is in accordance with the authorization model and is based at least in part on second authentication information associated with the second user; A non-transitory computer-readable medium containing instructions for performing the steps of:
18. 20. The non-transitory computer-readable medium of claim 17, wherein the instructions are further executable by the processor to establish a connection between the second cloud platform and the resource in response to granting the third request.
19. 20. The non-transitory computer-readable medium of claim 18, wherein the instructions are further executable by the processor to establish an authorization scheme by using the connection between the second cloud platform and the resource according to the authorization model, wherein the authorization scheme includes single sign-on authorization.
20. 20. The non-transitory computer-readable medium of claim 18, wherein the instructions are further executable by the processor to assign privileges to the second user by using the connection between the second cloud platform and the resource, the privileges based at least in part on the authorization model.
Citation Information
Patent Citations
Local writes for multi-tenant identity cloud services
JP2021518933A
System and method for externally-delegated access control and authorization
US20190306171A1
Unified identity and access management (IAM) control plane for services associated with a hybrid cloud
US20220038449A1