Unified identity platform for multiple cloud services

US12495044B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12495044-B2
Application numberUS-202318494125-A
CountryUS
Kind codeB2
Filing dateOct 25, 2023
Priority dateJun 14, 2023
Publication dateDec 9, 2025
Grant dateDec 9, 2025

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Systems and methods for providing identity services are provided. A method, according to one implementation, includes a step of assuming unified and centralized responsibility for performing identity-related services for a plurality of network security products. In response to an end user device attempting to initiate a session with a selected network security product of the plurality of network security products, the method may perform the identity-related services to manage or authenticate an identity of the end user device or a user of the end user device. Then, the method includes a step of enabling the end user device to establish the session with or receive a service from the selected network security product after performing the identity-related services.

First claim

Opening claim text (preview).

What is claimed is: 1 . An Identity Provider (IdP) system comprising: a processing device, and a memory device configured to store a computer program having instructions that, when executed, enable the processing device to assume unified and centralized responsibility for performing identity-related services for a plurality of network security products; in response to an end user device attempting to initiate a session with a selected network security product of the plurality of network security products, perform the identity-related services to manage or authenticate an identity of the end user device or a user of the end user device, wherein the IdP system comprises a centralized identity platform configured to execute an authentication process that provides centralized enhancements to identity-related functionalities, wherein the centralized enhancements made within the IdP system are automatically and simultaneously propagated to each of the plurality of network security products, thereby ensuring standardized identity-related configurations, uniform authentication behaviors, and a consistent user experience across all of the plurality of network security products; and enable the end user device to establish the session with or receive a service from the selected network security product after performing the identity-related services. 2 . The IdP system of claim 1 , wherein, by assuming unified and centralized responsibility for performing the identity-related services for the plurality of network security products, the IdP system avoids duplication of the identity-related services by the plurality of network security products. 3 . The IdP system of claim 1 , wherein the IdP system is related to a cloud-based system oriented between the end user device and the Internet. 4 . The IdP system of claim 1 , wherein the instructions further enable the processing device to institute a Single Sign-On (SSO) procedure for accessing the plurality of network security products. 5 . The IdP system of claim 1 , wherein managing or authenticating the identity of the end user device or user includes support of authentication processes associated with one or more of Security Assertion Markup Language (SAML), OAuth 1.0, OAuth 2.0, and OpenID Connect. 6 . The IdP system of claim 1 , wherein managing or authenticating the identity of the end user device or user includes support of authentication processes associated with one or more of a System for Cross-domain Identity Management (SCIM), a system that spans multiple data centers, a Lightweight Directory Access Protocol (LDAP), an Active Directory (AD), and an authentication bridge service. 7 . The IdP system of claim 1 , further comprising one or more of a metadata manager, an organization configuration manager, a provisioning manager, and a notification manager. 8 . The IdP system of claim 1 , further comprising a database configured to store or log ID information related to one or more user IDs, device IDs, and authentication attempts. 9 . The IdP system of claim 1 , further comprising an inbound authentication unit, an authentication manager, and an outbound federated authentication unit configured in combination to perform the identity-related services. 10 . The IdP system of claim 1 , further comprising an inbound provisioning unit, a provisioning manager, and an outbound provisioning unit configured in combination to manage identity-related messaging with the plurality of network security products. 11 . The IdP system of claim 1 , wherein the instructions further enable the processing device to act as a Certificate Authority and sync a mobile portal to an ID store. 12 . The IdP system of claim 1 , wherein the instructions further enable the processing device to protect applications associated with a Cloud Access Security Broker (CASB). 13 . The IdP system of claim 1 , further comprising a single portal or User Interface (UI) allowing a user to navigate the plurality of network security products. 14 . A non-transitory computer-readable storage medium configured to store computer logic having instructions that, when executed, cause one or more processing devices to: assume unified and centralized responsibility for performing identity-related services for a plurality of network security products; in response to an end user device attempting to initiate a session with a selected network security product of the plurality of network security products, perform the identity-related services to manage or authenticate an identity of the end user device or a user of the end user device, wherein the one or more processing devices comprise a centralized identity platform configured to execute an authentication process that provides centralized enhancements to identity-related functionalities, wherein the centralized enhancements made within the IdP system are automatically and simultaneously propagated to each of the plurality of network security products, thereby ensuring standardized identity-related configurations, uniform authentication behaviors, and a consistent user experience across all of the plurality of network security products; and enable the end user device to establish the session with or receive a service from the selected network security product after performing the identity-related services. 15 . The non-transitory computer-readable storage medium of claim 14 , wherein, by assuming unified and centralized responsibility for performing the identity-related services for the plurality of network security products, duplication of the identity-related services by the plurality of network security products is avoided. 16 . The non-transitory computer-readable storage medium of claim 14 , further comprising a single portal or User Interface (UI) allowing a user to navigate the plurality of network security products, wherein the instructions further cause the one or more processing devices to use the single portal or UI to institute a Single Sign-On (SSO) procedure for accessing the plurality of network security products. 17 . The non-transitory computer-readable storage medium of claim 14 , wherein managing or authenticating the identity of the end user device or user includes support of authentication processes associated with one or more of Security Assertion Markup Language (SAML), OAuth 1.0, OAuth 2.0, OpenID Connect, a System for Cross-domain Identity Management (SCIM), a system that spans multiple data centers, a Lightweight Directory Access Protocol (LDAP), an Active Directory (AD), and an authentication bridge service. 18 . A method comprising steps of: assuming unified and centralized responsibility for performing identity-related services for a plurality of network security products; in response to an end user device attempting to initiate a session with a selected network security product of the plurality of network security products, performing the identity-related services to manage or authenticate an identity of the end user device or a user of the end user device, wherein the steps are performed in a centralized identity platform configured to execute an authentication process that provides centralized enhancements to identity-related functionalities, wherein the centralized enhancements made within the IdP system are automatically and simultaneously propagated to each of the plurality of network security products, thereby ensuring standardized identity-related configurations, uniform authentication behaviors, and a consistent user experience across all of the plurality of ne

Assignees

Inventors

Classifications

  • providing single-sign-on or federations · CPC title

  • by delegation of authentication, e.g. a proxy authenticates an entity to be authenticated on behalf of this entity vis-à-vis an authentication entity · CPC title

  • using certificates (cryptographic mechanisms or cryptographic arrangements for entity authentication involving certificates H04L9/3263) · CPC title

  • H04L63/102Primary

    Entity profiles · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12495044B2 cover?
Systems and methods for providing identity services are provided. A method, according to one implementation, includes a step of assuming unified and centralized responsibility for performing identity-related services for a plurality of network security products. In response to an end user device attempting to initiate a session with a selected network security product of the plurality of networ…
Who is the assignee on this patent?
Zscaler Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/0823. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Dec 09 2025 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).