US 11,729,169 B2
Identity defined secure connect
Cameron Williams, Denver, CO (US); Ryan Privette, Denver, CO (US); Christopher Chad Wheeler, Denver, CO (US); Andrew John Cer, Highlands Ranch, CO (US); and Joseph Nathan Zendle, Centennial, CO (US)
Assigned to SailPoint Technologies, Inc., Wilmington, DE (US)
Filed by Sailpoint Technologies, Inc., Wilmington, DE (US)
Filed on Dec. 17, 2021, as Appl. No. 17/554,942.
Application 17/554,942 is a continuation of application No. 16/100,068, filed on Aug. 9, 2018, granted, now 11,240,240.
Claims priority of provisional application 62/543,118, filed on Aug. 9, 2017.
Prior Publication US 2022/0109675 A1, Apr. 7, 2022
This patent is subject to a terminal disclaimer.
Int. Cl. H04L 9/40 (2022.01); H04L 12/46 (2006.01)
CPC H04L 63/0884 (2013.01) [H04L 12/4633 (2013.01); H04L 12/4641 (2013.01); H04L 63/0272 (2013.01); H04L 63/062 (2013.01); H04L 63/0823 (2013.01); H04L 63/0846 (2013.01); H04L 63/0876 (2013.01)] 21 Claims
OG exemplary drawing
 
1. A system for computer security, the system comprising:
a triage zone and a production zone logically or physically separate from the triage zone, wherein a set of protected resource can be accessed through the production zone but cannot be accessed through the triage zone, and wherein:
the triage zone is adapted to obtain an authentication request associated with a client device, the triage zone including:
an identity manager to, upon successful validation in association with the authentication request, generate an ephemeral token and enable an associated dynamic certificate set to expire at a specific time, and to create or update a stored entry based on the dynamic certificate, wherein the ephemeral token is adapted to be provided to the client device to allow access to the production zone, and not the triage zone, based on the associated dynamic certificate;
the production zone adapted to:
establish a connection with the client device based on the dynamic certificate, ephemeral token, and a username; and
verify, by accessing the stored entry, that the authentication request provided by the client device is valid.