Unified identity services for multi-tenant architectures

US12056249B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12056249-B2
Application numberUS-202117340473-A
CountryUS
Kind codeB2
Filing dateJun 7, 2021
Priority dateJun 15, 2018
Publication dateAug 6, 2024
Grant dateAug 6, 2024

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method for using unified identities in a multi-tenant architecture system is discussed. The method includes receiving a request, at a first service provider, to provide a service for a user. The method includes accessing a representation of a second service provider in a first hierarchical data structure managed by the first service provider. The method includes determining that user data required for the service is managed by the second service provider that manages user identity of the user. The method includes determining that the representation is linked with a full identity reference for the second service provider in a second hierarchical data structure managed by the second service provider. The method includes accessing the user data at the second hierarchical data structure using the full identity reference. The method includes accessing the service via the lightweight identity reference and using the user data at the first service provider.

First claim

Opening claim text (preview).

What is claimed is: 1. A method for using unified identity services in a multi-tenant architecture system, the method comprising: providing a multi-tenant platform, the multi-tenant platform managing, at least using a hierarchical data structure, representations of service providers and respective representations of their entities, the representations of service providers including a first provider representation of a first service provider, the first service provider configured to provide a first set of services including a first service to users; onboarding a new service provider onto the hierarchical data structure to create a new provider representation of the new service provider in the hierarchical data structure and to create a linked identity reference accessible by the first provider representation, wherein said onboarding the new service provider comprises creating a dependency graph indicating relationships and access permissions between entities of the hierarchical data structure and additional entities of new hierarchical data associated with the new service provider and wherein the dependency graph indicates the linked identity reference; and responsive to the onboarding of the new service provider, providing access, via the linked identity reference in the hierarchical data structure, to services of the new service provider to a merchant entity managed by the first service provider. 2. The method of claim 1 , further comprising: receiving, at the first service provider, a request to provide the first service for a customer of merchant corresponding to the merchant entity; and determining, using the request, the linked identity reference in the hierarchical data structure based on relationship data for representations of the first service provider and the new service provider, wherein said providing access via the linked identity reference is performed responsive to the determination of the linked identity reference. 3. The method of claim 1 , further comprising: accessing, using the linked identity reference, user data for a user via a second hierarchical data structure using a full identity reference corresponding to the new service provider, wherein said providing access via the linked identity reference is further based using the full identity reference. 4. The method of claim 1 , wherein the new service provider is configured to directly provide a second set of services to a user; and wherein the second set of services are available for access from the first service provider using the first provider representation. 5. The method of claim 1 , wherein the new provider representation is associated with access permissions at the multi-tenant platform; and wherein said providing access to services of the new service provider is performed based on the access permissions. 6. The method of claim 1 , wherein said onboarding the new service provider comprises: determining a subset of entities of the new service provider that are migrated to the first service provider; and excluding the subset of entities from having representations created in a portion of the hierarchical data structure associated with the first service provider. 7. The method of claim 1 , wherein said onboarding the new service provider comprises: determining a subset of entities of the new service provider that are not being fully integrated to the first service provider; and including the subset of entities in having representations created in a portion of the hierarchical data structure associated with the first service provider. 8. A system comprising: a non-transitory memory storing instructions; and a processor configured to execute the instructions to cause the system to: provide a multi-tenant platform, the multi-tenant platform managing, at least using a hierarchical data structure, representations of service providers and respective representations of their entities, the representation of service providers including a first provider representation of a first service provider, the first service provider configured to provide a first set of services including a first service to users; receive a new service provider with a subset of entities managed by the new service provider; and onboard the new service provider and the subset of entities onto the hierarchical data structure of the multi-tenant platform to create a new provider representation of the new service provider and at least one linked identity reference in the hierarchical data structure, the at least one linked identity reference accessible by the first provider representation for access to an entity of the subset of entities managed by the new service provider from a representation of first service provider, wherein the subset of entities are not fully integrated into the multi-tenant platform, wherein the at least one linked identity reference indicates relationships and access permissions between entities of the hierarchical data structure and additional entities of new hierarchical data. 9. The system of claim 8 , wherein executing the instructions further causes the system to: responsive to the onboarding of the new service provider, provide access, via the linked identity reference in the hierarchical data structure, to services of the new service provider to a merchant entity managed by the first service provider. 10. The system of claim 8 , wherein executing the instructions further causes the system to access, using the linked identity reference, user data for a user via a second hierarchical data structure using a full identity reference corresponding to the new service provider, wherein said providing access via the linked identity reference is further based using the full identity reference. 11. The system of claim 8 , wherein the new provider representation is associated with access permissions at the multi-tenant platform; and wherein said providing access to services of the new service provider is performed based on the access permissions. 12. The system of claim 8 , wherein said onboarding the new service provider comprises: determining another subset of entities of the new service provider that are migrated to the first service provider; and excluding the another subset of entities from having representations created in a portion of the hierarchical data structure associated with the first service provider. 13. The system of claim 8 , wherein the hierarchical data structure is implemented as the dependency graph. 14. A non-transitory machine-readable medium having instructions stored thereon, the instructions executable to cause performance of operations comprising: providing a multi-tenant platform, the multi-tenant platform managing, at least using a hierarchical data structure, representations of service providers and respective representations of their entities, the representations of service providers including a first provider representation of a first service provider, the first service provider configured to provide a first set of services including a first service to users; onboarding a new service provider onto the hierarchical data structure to create a new provider representation of the new service provider in the hierarchical data structure and to create a linked identity reference accessible by the first provider representation, wherein said onboarding the new service provider comprises using a dependency graph indicating relationships and access permissions between entities of the hierarchical data structure and additional entities of new hierarchical data associated with the new service provider and wherein the dependency gra

Assignees

Inventors

Classifications

  • Scheduling or organising the servicing of application requests, e.g. requests for application data transmissions using the analysis and optimisation of the required network resources (admission control or resource allocation H04L47/70) · CPC title

  • Discovery or management thereof, e.g. service location protocol [SLP] or web services · CPC title

  • Graphs; Linked lists (G06F16/9027 takes precedence) · CPC title

  • Entity relationship models · CPC title

  • Entity profiles · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12056249B2 cover?
A method for using unified identities in a multi-tenant architecture system is discussed. The method includes receiving a request, at a first service provider, to provide a service for a user. The method includes accessing a representation of a second service provider in a first hierarchical data structure managed by the first service provider. The method includes determining that user data req…
Who is the assignee on this patent?
Paypal Inc
What technology area does this patent fall under?
Primary CPC classification G06F21/604. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Aug 06 2024 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).