Patent Issued for Secure service isolation between instances of cloud products using a SaaS model (USPTO 11720410): Forgerock Inc. - Insurance News | InsuranceNewsNet

InsuranceNewsNet — Your Industry. One Source.™

Sign in
  • Subscribe
  • About
  • Advertise
  • Contact
Home Now reading Newswires
Topics
    • Advisor News
    • Annuity Index
    • Annuity News
    • Companies
    • Earnings
    • Fiduciary
    • From the Field: Expert Insights
    • Health/Employee Benefits
    • Insurance & Financial Fraud
    • INN Magazine
    • Insiders Only
    • Life Insurance News
    • Newswires
    • Property and Casualty
    • Regulation News
    • Sponsored Articles
    • Washington Wire
    • Videos
    • ———
    • About
    • Meet our Editorial Staff
    • Advertise
    • Contact
    • Newsletters
  • Exclusives
  • NewsWires
  • Magazine
  • Newsletters
Sign in or register to be an INNsider.
  • AdvisorNews
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Exclusives
  • INN Magazine
  • Insurtech
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Video
  • Washington Wire
  • Life Insurance
  • Annuities
  • Advisor
  • Health/Benefits
  • Property & Casualty
  • Insurtech
  • About
  • Advertise
  • Contact
  • Editorial Staff

Get Social

  • Facebook
  • X
  • LinkedIn
Newswires
Newswires RSS Get our newsletter
Order Prints
August 30, 2023 Newswires
Share
Share
Post
Email

Patent Issued for Secure service isolation between instances of cloud products using a SaaS model (USPTO 11720410): Forgerock Inc.

Insurance Daily News

2023 AUG 30 (NewsRx) -- By a News Reporter-Staff News Editor at Insurance Daily News -- Forgerock Inc. (San Francisco, California, United States) has been issued patent number 11720410, according to news reporting originating out of Alexandria, Virginia, by NewsRx editors.

The patent’s inventors are Croteau, Beau (Bay Shore, NY, US), Culp, Scott (Bellevue, WA, US), White, Steve (Battle Ground, WA, US).

This patent was filed on December 14, 2021 and was published online on August 8, 2023.

From the background information supplied by the inventors, news correspondents obtained the following quote: “The subject matter discussed in this section should not be assumed to be prior art merely as a result of its mention in this section. Similarly, a problem mentioned in this section or associated with the subject matter provided as background should not be assumed to have been previously recognized in the prior art. The subject matter in this section merely represents different approaches, which in and of themselves can also correspond to implementations of the claimed technology.

“Businesses depend on computing systems to survive, and enterprise companies often utilize software as a service (SaaS) solutions in the cloud instead of installing servers within the corporate network to deliver services. According to International Data Corporation, almost half of all information technology (IT) spending will be cloud-based in 2018, “reaching 60% of all IT infrastructures and 60-70% of all software, services and technology spending by 2020.”

“Customer data and information created and stored in the cloud is an attractive target for attackers. The service provider for a SaaS app is an important attack vector, so it is especially useful to protect data from the service provider itself. Two attack scenarios to consider include onslaughts from an attacker who compromises the service provider in order to obtain access to the cloud service data, and a second potential strike by an employee of the service provider who already has access. Consequently, a need exists for secure authentication and authorization for customers who utilize cloud-based services, and for isolation of customer data, even from the service provider itself of secure authentications and authorizations.

“An opportunity arises to enable organizations to build trusted relationships with people, services and things, utilizing an identity management service delivered via a SaaS model, to run an identity management instance under sovereign control of the organization. The customer can also pull maintenance updates for the organization’s identity management instance from the identity management service provider without exposing data secured by the customer organization to the service provider.”

Supplementing the background information on this patent, NewsRx reporters also obtained the inventors’ summary information for this patent: “The following detailed description is made with reference to the figures. Sample implementations are described to illustrate the technology disclosed, not to limit its scope, which is defined by the claims. Those of ordinary skill in the art will recognize a variety of equivalent variations on the description that follows.

“As more and more essential services like banking and commerce move to the cloud, more of people’s personal data and financial instruments, such as credit cards, are housed in the cloud but these same capabilities make the cloud an attractive target for attackers trying to spread malware and carry out other malicious activity. SaaS solutions offer many business applications, including office software for documents, presentations, worksheets, databases, charts, graphs, digital paintings, electronic music and digital video. Additional SaaS services include messaging software, payroll processing software, DBMS software, management software, CAD software, development software, gamification, virtualization, accounting, customer relationship management (CRM), Management Information Systems (MIS), enterprise resource planning (ERP), invoicing, human resource management (HRM), talent acquisition, learning management, content management (CM), Geographic Information Systems (GIS) and service desk management. In one example, customers regularly create, edit and save files via Microsoft Office 365 and Google Apps, among others, in a cloud environment.

“When enterprise companies utilize SaaS solutions to deliver services, they need to be able to protect the private data of their customers in the cloud environment. For the disclosed technology described, when a new customer registers for SaaS, the cloud service creates a new customer environment for the customer. Before the new tenant can begin to use the new customer environment, security resources must be provisioned. Although a straightforward way to provide customer identity and access management would be for the cloud service that creates the new customer environment to provision security resources, this approach would create a point of potential compromise. Inadvertently or through an attacker’s directions, the cloud service that creates the new customer environment might retain information such as service account credentials, decryption keys, etc.

“The disclosed technology is implemented in a cloud service that offers identity and access management services as a SaaS model in the cloud. In that service, every customer’s identity management instance has the services it needs at hand, and the instance controls them, thus transforming the way organizations build trusted relationships. The disclosed technology includes pulling up the drawbridge before the customer’s private data is accessible to even the identity and access management services, to secure the data of the customer’s users. The customer environments’ locus of control is internal. Nothing outside the instance has administrative control over the instance. In one example of using the disclosed technology, a bank may utilize identity and access management (IAM) while shielding the private data of each customer of the bank from the IAM provider as well as from other potential attackers. Identity and access management (IAM) refers to authentication of a user along with confirmation that the user is authorized to access the data they request. The disclosed technology delivers a sovereign instance of a cloud service, in this case identity management (IDM) and access management (AM) and the data services that support those functions, as a product referred to as FR-IDM in this application. In another use case, the disclosed security model could also support a cloud service that provides a different service, such as online games instead of identity and access management services.

“The disclosed identity cloud creates a new customer environment by deploying a vanilla cloud-based computing cluster project with the needed APIs enabled, and then launching a bootstrapper of the security infrastructure for the project configures the cloud-based identity and access management components and then launches a manager that tends to the health of the customer’s identity management instance moving forward. This cloud-based digital identity management service addresses stringent regulations for privacy and consent, including General Data Protection Regulation (GDPR), Health Insurance Portability and Accountability Act of 1996 (HIPAA), Open Banking, etc. for storing data securely, as well as enabling the monetization of customer relationships.”

The claims supplied by the inventors are:

“1. A computer-implemented method of initializing an application instance using a software as a service (abbreviated SaaS) model in a project implemented on a cloud-based computing service, including: at a first time, running a SaaS cluster configuration engine that enables a service provider for a SaaS application to set configuration parameters for the project implemented on the cloud-based computing service and initializing the project in which an application instance will be built, then removing authorization of the SaaS cluster configuration engine to access to the project, including removing access to set the configuration parameters; at a second time following the first time, running a SaaS application infrastructure builder autonomously, without the service provider having access to the builder, to build the application instance in the project; and after the application instance is built, delivering application services.

“2. The computer-implemented method of claim 1, further including a customer organization controlling installation of maintenance updates, from the service provider, to the application instance delivering application services.

“3. The computer-implemented method of claim 1, further including the SaaS application infrastructure builder locking down and securing the project in which an application instance is built.

“4. The computer-implemented method of claim 1, wherein the cloud-based computing service is one of Google Cloud Platform (abbreviated GCP), Amazon Web Services (abbreviated AWS) or Microsoft Azure Virtual Platform.

“5. The computer-implemented method of claim 1, wherein the application instance provides isolated code and data management services to customers.

“6. The computer-implemented method of claim 1, further including the application instance delivering application services to end user apps visiting a customer’s web site.

“7. The computer-implemented method of claim 1, further including the application instance delivering application services to a customer’s web site that is in communication with the application instance running in the project.

“8. The computer-implemented method of claim 1, further including: the service provider for the SaaS application utilizing a “break glass” scenario for accessing escrowed project access credentials, stored on a different platform than the cloud-based computing service, at a time when a customer organization requests support that requires access to the project and/or configuration parameters of the project; and generating one or more notices to the customer organization and a security administrator for the service provider that the “break glass” scenario has been invoked.

“9. The computer-implemented method of claim 8, wherein at least two people must collaborate with the service provider for the SaaS application to retrieve the credentials for the customer organization.

“10. A tangible non-transitory computer readable storage media, including program instructions loaded into memory that, when executed on processors cause the processors to implement a method of initializing an application instance using a software as a service (abbreviated SaaS) model in a project implemented on a cloud-based computing service, the method including: at a first time, running a SaaS cluster configuration engine that enables a service provider for a SaaS application to set configuration parameters for the project implemented on the cloud-based computing service and initializing the project in which an application instance will be built, then removing authorization of the SaaS cluster configuration engine to access to the project, including removing access to set the configuration parameters; at a second time following the first time, running a SaaS application infrastructure builder autonomously, without the service provider having access to the builder, to build the application instance in the project; and after the application instance is built, delivering application services.

“11. The tangible non-transitory computer readable storage media of claim 10, further including a customer organization controlling installation of maintenance updates, from the service provider, to the application instance delivering application services.

“12. The tangible non-transitory computer readable storage media of claim 10, further including the SaaS application infrastructure builder locking down and securing the project in which an application instance is built.

“13. The tangible non-transitory computer readable storage media of claim 10, wherein the cloud-based computing service is one of Google Cloud Platform (abbreviated GCP), Amazon Web Services (abbreviated AWS) or Microsoft Azure Virtual Platform.

“14. The tangible non-transitory computer readable storage media of claim 10, wherein the application instance provides isolated code and data management services to customers.

“15. The tangible non-transitory computer readable storage media of claim 10, further including the application instance delivering application services to end user apps visiting a customer’s web site.

“16. The tangible non-transitory computer readable storage media of claim 10, further including the application instance delivering application services to a customer’s web site that is in communication with the application instance running in the project.

“17. The tangible non-transitory computer readable storage media of claim 10, further including: the service provider for SaaS application utilizing a “break glass” scenario for accessing escrowed project access credentials, stored on a different platform than the cloud-based computing service, at a time when a customer organization requests support that requires access to the project and/or configuration parameters of the project; and generating one or more notices to the customer organization and a security administrator for the service provider that the “break glass” scenario has been invoked.

“18. The tangible non-transitory computer readable storage media of claim 17, wherein at least two people must collaborate with the service provider for SaaS application to retrieve the credentials for the customer organization.

“19. A system for initializing an application instance using a software as a service (abbreviated SaaS) model in a project implemented on a cloud-based computing service, the system including a processor, memory coupled to the processor and computer instructions from the non-transitory computer readable storage media of claim 10 loaded into the memory.

“20. The system of claim 19, further including a customer organization controlling installation of maintenance updates, from the service provider, to the application instance delivering application services.

“21. The system of claim 19, further including the SaaS application infrastructure builder locking down and securing the project in which an application instance is built.

“22. The system of claim 19, further including the application instance delivering application services to end user apps visiting a customer’s web site.

“23. The system of claim 19, further including the application instance delivering application services to a customer’s web site that is in communication with the application instance running in the project.

“24. A computer-implemented method of initializing a secure application instance isolated from malicious code and interacting with a server, the initializing managed using a software as a service (abbreviated SaaS) model in a project implemented on a cloud-based computing service, including: at a first time, running a SaaS cluster configuration engine that enables a service provider for a SaaS service to set configuration parameters for the project implemented on the cloud-based computing service and initializing the project in which the secure application instance will be built, then removing authorization of the SaaS cluster configuration engine to access to the project, including removing access to set the configuration parameters; at a second time following the first time, running a SaaS service infrastructure builder autonomously, without the service provider having access to the builder, to build the secure application instance in the project; and after the secure application instance is built, delivering secure application services for interacting with the server.

“25. The computer-implemented method of claim 24, further including a customer organization controlling installation of maintenance updates, from the service provider, to the secure application instance delivering application services.”

For the URL and additional information on this patent, see: Croteau, Beau. Secure service isolation between instances of cloud products using a SaaS model. U.S. Patent Number 11720410, filed December 14, 2021, and published online on August 8, 2023. Patent URL (for desktop use only): https://ppubs.uspto.gov/pubwebapp/external.html?q=(11720410)&db=USPAT&type=ids

(Our reports deliver fact-based news of research and discoveries from around the world.)

Older

“Using Historical Data For Subrogation On A Distributed Ledger” in Patent Application Approval Process (USPTO 20230252577): Patent Application

Newer

Insurance Analytics Market Growth, Opportunities Business Scenario, Share, Growth Size, Scope, Key Segments and Forecast to 2026

Advisor News

  • Industry groups applaud House passage of Financial Exploitation Prevention Act
  • Younger workers more likely to be eligible for a retirement plan after changing jobs
  • Bank of America community event unpacks sales tax hike, small business struggles
  • CONGRESSMAN VALADAO DEMANDS ANSWERS FROM CALIFORNIA OVER HEALTHCARE TAX HIKE
  • How executive benefits impact an estate plan
More Advisor News

Annuity News

  • State Farm’s agency overhaul: What distribution can learn
  • IRI, ACLI express support for CLEAR Forms Act
  • A new era at the Federal Reserve
  • Globe Life Inc. (NYSE: GL) Making Surprising Moves in Tuesday Session
  • Why annuities are gaining traction with younger investors
More Annuity News

Health/Employee Benefits News

  • Maryland health insurance rates could rise 13.7% in 2027 under proposal
  • Millions drop Obamacare health coverage after subsidies expire and costs rise
  • Improving how we deliver healthcare in Idaho
  • Healthcare system needs a public option
  • Public healthcare option overdue
More Health/Employee Benefits News

Life Insurance News

  • AM Best Affirms Credit Ratings of Misr Insurance Company
  • State Farm’s agency overhaul: What distribution can learn
  • They Allegedly Enrolled People In Life Insurance Without Consent. Then Death Claims Paid Out
  • How much do state residents need to retire comfortably?
  • How executive benefits impact an estate plan
More Life Insurance News

NEWS INSIDE

  • Companies
  • Earnings
  • Economic News
  • INN Magazine
  • Insurtech News
  • Newswires Feed
  • Regulation News
  • Washington Wire
  • Videos

FEATURED OFFERS

Maximize Your FIA Case Results
Learn a repeatable process to review, reposition, and present FIA opportunities with confidence.

Aim higher during Annuity Awareness Month
Raise the bar with our diverse portfolio of Ascend annuities, backed by superior financial strength

You Could Be Losing Up to 20% of Your Commissions
GreenWave helps you find, fix, and prevent commission errors.

True Independence Means Having Choices
Cambridge offers flexibility, stability, proven tools—no private equity strings attached.

Life moves fast. Your BGA should, too.
Stay ahead with Modern Life's AI-powered tech and expert support.

Looking for stronger rates, amplified growth & real results?
Sentinel's Accumulation Protector Plus℠ Annuity is for clients wanting more from retirement planning

Press Releases

  • Prosperity Life GroupSM Launches Prosperity PathWaySM Series, Bringing Greater Choice and Flexibility to Retirement Income Planning
  • Senior Market Sales® Fortifies Annuity Reach With Acquisition of Retirement Planning Firm Stratton & Company
  • RFP #T01625
  • Rockwood Programs Appoints Kerry Ladouceur as Vice President, Financial Lines
  • JP Insurance Group Launches Commercial Property & Casualty Division; Appoints Joe Webster as Managing Director
More Press Releases > Add Your Press Release >

How to Write For InsuranceNewsNet

Find out how you can submit content for publishing on our website.
View Guidelines

Topics

  • Advisor News
  • Annuity Index
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • From the Field: Expert Insights
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Magazine
  • Insiders Only
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Washington Wire
  • Videos
  • ———
  • About
  • Meet our Editorial Staff
  • Advertise
  • Contact
  • Newsletters

Top Sections

  • AdvisorNews
  • Annuity News
  • Health/Employee Benefits News
  • InsuranceNewsNet Magazine
  • Life Insurance News
  • Property and Casualty News
  • Washington Wire

Our Company

  • About
  • Advertise
  • Contact
  • Meet our Editorial Staff
  • Magazine Subscription
  • Write for INN

Sign up for our FREE e-Newsletter!

Get breaking news, exclusive stories, and money- making insights straight into your inbox.

select Newsletter Options
Facebook Linkedin Twitter
© 2026 InsuranceNewsNet.com, Inc. All rights reserved.
  • Terms & Conditions
  • Privacy Policy
  • InsuranceNewsNet Magazine

Sign in with your Insider Pro Account

Not registered? Become an Insider Pro.
Insurance News | InsuranceNewsNet