Computer-implemented identity and access management system, method, computer program and recording medium
Through a multi-domain identity and access management system, OEMs and end customers each manage independent subsystems, solving the problems of OEMs being unable to retain control and end customers being unable to flexibly manage access permissions, thus achieving secure and efficient access management and fine-grained control.
Patent Information
- Application Number
- CN202480017669.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-03-09
- Filing Date
- 2024-02-28
- Publication Date
- 2025-11-07
AI Technical Summary
Existing technologies make it difficult to achieve fine-grained access control between end customers and OEMs after the OEM delivers the machine or system. This results in OEMs being unable to retain control over the machine or system, while end customers are unable to flexibly manage access permissions according to their own needs.
A multi-domain identity and access management system is adopted, including separate identity management subsystems for OEMs and end customers. This allows OEMs to retain certain controls over machines or systems, while end customers can configure access permissions according to their own needs, and implement this management through computer-based methods and systems.
It enables OEMs and end customers to manage access permissions securely and efficiently without interfering with each other's management, provides a fine-grained role and permission system, simplifies access management across multiple machines or systems, and improves security and availability.
Smart Images

Figure CN120917709A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to a computer-implemented identity and access management system. The present application also relates to a computer-implemented method for creating an identity and access management system, a computer program and a computer-readable recording medium.
[0002] The present application particularly relates to the field of identity and access management systems (IAM), and more particularly to a multi-domain extended system for identity and access management, which enables an original equipment manufacturer (OEM) to continue to maintain control over certain aspects of its machines or systems after their delivery, while enabling its end customers to manage access to its machines or systems in a way that is suitable for their internal operations. BACKGROUND
[0003] OEMs design and produce machines or systems, which are intended to be delivered to end customers or end users. End customers or end users further operate these machines in order to control their industrial processes.
[0004] During the preparation of these machines and systems, the OEM will program them and configure their functions and data. For example, a CNC drilling machine can have a function for the safe maximum rotation speed, which is defined by data representing the maximum rotation speed of the drill chuck spindle. After delivery, the OEM still needs to access the machines / systems that are no longer in its possession, at least for maintenance and / or service purposes. In this case, access to the machines or systems is typically managed by assigning roles or specific rights to identities (e.g. persons, employees, users). The access preparation step of the machine or system is preferably done before the delivery of the machines and systems to the end customers.
[0005] By employing an identity and access management extended system, the user is supported in performing access management tasks, thereby ensuring that only configured access is allowed and performed.
[0006] When the OEM retains control over specific parameters, data and / or functions (i.e. denies access to the end customer or user) and wishes to have access at any time, the end customer or user wishes to be able to manage access to its machines and systems on its own, according to its operational and organizational needs. Furthermore, the end customer or user typically also has its own identity and access management solution, which it wishes to deploy on the machines and systems it takes over, which conflicts with the OEM’s solution.
[0007] This problem is further exacerbated by the fact that many end customers introduce or have introduced solutions for managing access to their different machines and systems, which are intended to enable access to continue to be configured machine-specifically: for example, employee A of an end customer has access to machine 1, while employee B of the end customer (although having the same role and rights as employee A) has access only to machine 2 and not to machine 1. It is therefore necessary for the end customer to be able to manage the access configuration of these specific functions on different levels of detail.
[0008] In modern industrial systems, it is also becoming increasingly common to integrate access protection into the central systems of the enterprise. In this context, end customers have different requirements from OEMs. End customers want to be able to identify, control and authenticate the use of machines and systems of the enterprise in detail (i.e. precisely to the granularity between machine and machine) and to manage these access rights by themselves and with existing means. On the other hand, OEMs have different requirements, since they do not want to deal with the passwords stored in each machine or the isolation of access between machine and machine, but rather want their employees to be able to access the delivered machines and systems by means of, for example, employee badges, based on the limited requirements for maintenance and customer service.
[0009] It should be noted that the relationship between end customer and OEM can be more complex, since the OEM providing the machine or system can use subcomponents or parts provided by other OEMs, which likewise want to ensure access rights to their components or subcomponents in the same way as the first OEM.
[0010] End customers ultimately want to be able to control in certain applications when the OEM is allowed to access the machines or systems used by them, for example only when on-site service or access by remote service at agreed, operationally suitable times, i.e. in such a way that does not affect the end customer's operational plan.
[0011] The existing solutions require two separate access systems to be set up, one for the OEM and one for the end customer (which can optionally be the same system). In this known solution, the granularity of the role and rights system on the OEM side is not as detailed as on the end customer side. Specifically, this means whether the functionality of the OEM is activated when access is allowed. The OEM can therefore select its own security solution, for example by using passwords, access cards, special keys or the like. This enables the employees of the OEM to unlock the machines by means of their respective passwords, access cards or special keys and thus to gain access to the respective machines.
[0012] On the end customer side, the machines can be freely used or the end customer can set up secure access, for example by one or more passwords. Alternatively, the OEM can also allow integration into the end customer's identity management solution, for example via Microsoft Active Directory, LDAP, OpenID Connect (OIDC) or the like. In this way, access rights for a specific machine can be set up, ensuring that the end customer employees know the password required for the respective machine or, in the case of a centralized identity management system, only register on the machine which employees have access to the machine.
[0013] The document US2021 / 0390170 A1 - Olden et al. "SYSTEMS, METHODS, AND STORAGE MEDIA FOR MIGRATING IDENTITY INFORMATION ACROSS IDENTITY DOMAINS IN AN IDENTITY INFRASTRUCTURE" proposes that in a system environment with multiple domains, a user and their permissions related to the user can be migrated from a first domain to a second domain and the user can exercise the same permissions in the second domain as in the first domain. SUMMARY
[0014] The object of the present invention is to provide an improved multi-domain identity and access management, in particular to enable the OEM to retain control over certain aspects of its machines or systems while allowing the end customer to manage the machine access rights needed for the operation within its organization.
[0015] According to the invention, this object is achieved by a computer-implemented identity and access management system, a method for creating and using the system, a computer program and a recording medium containing the features described in the independent claims.
[0016] The present invention is based on an identity management system which consists of at least two identity management subsystems (or "domains"): one for the OEM and one for the end customer. Each domain is created and managed by the administrator of the respective organization. However, in chronological order, the domain of the OEM is created first, initialized by the OEM and delivered to the end customer as part of the machine or system. The end customer then creates its domain and associates it with the domain of the OEM. In other words, the subsystem / domain of the end customer is an extension of the original system which initially consisted only of the subsystem / domain of the OEM.
[0017] Thus, the end customer is able to configure specific access rights to the machines / systems, e.g. his employee A is able to access machine 1, while employee B, even with the same role / rights, is able to access machine 2. This configuration is the responsibility of the end customer and no additional work is required from the OEM.
[0018] In fact, the present application enables specific access to the machines according to the needs of the end customer, while allowing the OEM to access through the identity cards of his employees, i.e. with different levels of granularity.
[0019] In summary, the present application provides a scalable system, which enables the addition of further OEMs or end customers to the system. Furthermore, the present application provides a granular role / rights system for the field of OEMs and end customers, enabling flexible configuration of access rights.
[0020] Advantageous embodiments and further improvements can be derived from the attached claims as well as from the description in conjunction with the drawings.
[0021] The above-described embodiments and further improvements can be combined with each other in a reasonable manner. Other possible embodiments, improvements and implementations of the present application also include combinations of features of the present application which are not explicitly mentioned, described before or hereinafter with respect to the embodiments. In particular, the person skilled in the art can add individual aspects as improvements or supplements to the basic form of the present application. BRIEF DESCRIPTION OF DRAWINGS
[0022] The present application will be explained in detail with reference to the embodiments shown in the schematic drawings. In the drawings:
[0023] Figure 1 An abstract schematic diagram showing a multi-domain identity and access management extension system for managing access and identity is shown;
[0024] Figure 2 A schematic diagram showing the steps of a computer-implemented method implementing the creation and use of a multi-domain identity and access management extension system for access and identity management is shown.
[0025] The drawings are intended to further deepen the understanding of the embodiments of the present application. The drawings show embodiments and, together with the description, serve to explain the principles and concepts of the present application. Other embodiments and the numerous advantages described can be derived from the drawings. The elements of the drawings are not necessarily drawn to scale.
[0026] In the drawings, identical, functionally identical and identically acting elements, features and components are denoted by the same reference signs, unless stated otherwise. DETAILED DESCRIPTION
[0027] The embodiments will now be described in detail with reference to the accompanying drawings. However, this disclosure is not limited to the embodiments presented in this disclosure. Other embodiments within the scope of this disclosure, or previous disclosures, can be easily implemented by adding, modifying, deleting, or otherwise modifying other elements.
[0028] The terminology used in this specification has been selected to cover general and widely used terms. In some cases, a particular term may be arbitrarily defined by the applicant. In such cases, the meaning of the relevant term will be defined in the corresponding section of the detailed description. Therefore, the terms used in this specification should not be defined solely by their names, but rather according to their meanings and the general description of the content of this application.
[0029] This invention relates to a multi-domain identity and access management (IAM) extension system for managing access and authentication of industrial machines and systems. The system enables original equipment manufacturers (OEMs) that produce these machines and systems to maintain unique control over certain functions and data, while end users can manage the access permissions required for operations within their organizations.
[0030] like Figure 1 As shown, the multi-domain identity and access management extension system 100 includes at least two identity management systems or domains: a domain 101 for the OEM 200 and a domain 102 for the end customer 300. Each domain is created and managed by the administrator of the respective organization. In other words, the OEM administrator 201 creates and manages the OEM's domain 101, while the end customer administrator 301 creates and manages the end customer's domain 102.
[0031] Each domain of the multi-domain identity and access management extension system comprises sub-modules in which functions and data are stored. In particular, the OEM domain 101 comprises modules 1011 for storing functions and modules 1012 for storing data. Thus, using the above example, the modules 1011 for storing functions can contain the function of the maximum safe rotational speed of a CNC drilling machine, while the data modules 1012 of the OEM domain can contain the corresponding numerical value of this maximum safe rotational speed. The functions and data present in the OEM domain 101 should not be known, accessed or altered by any person in the organization of the end customer 300. In other words, the multi-domain identity and access management extension system 100 is configured so that only the OEM administrator 201 or the OEM employee 202 is allowed to access the OEM domain 101. However, in a particular embodiment of the present application, the multi-domain identity and access management extension system 100 is configured for providing special access rights to the administrator 301 of the end customer 300. This special access right is limited to allowing or preventing a person in the OEM organization from accessing the OEM domain 101 of the system 100. This function is intended to enable the end customer 300 to limit the operations that can be performed by the OEM on the machine / system when it is not desired to use them, while ensuring that the same end customer administrator 301 cannot interfere with the functions or data of the OEM domain in any case. Thus, the OEM domain 101 remains a domain reserved for the OEM.
[0032] In chronological order, the OEM domain 101 is initially created as the base domain of the identity and access management system 100, since this domain has been prepared and implemented before the machine or system is delivered to the end customer 300. Thus, the end customer's domain 102 is subsequently created as an extension domain of the identity and access management system 100, which is added as an additional domain of the system 100, which the end customer 300 can access. In the preferred embodiment, only the administrator 301 of the end customer 300 or the employee 302 of the end customer 300 can access the end customer domain 102.
[0033] Similarly to the domain 101 of the OEM, the domain 102 of the end customer 300 comprises modules 1021 for storing end customer functions and modules 1022 for storing end customer data. The identity and access management system 100 and the end customer domain 102 of the end customer 300 are configured so that only the persons in the organization of the end customer 300 are allowed to access the end customer domain 102 of the end customer 300.
[0034] It is important to note that, in the preferred embodiment, the administrator 201 of the OEM 200 and the administrator 301 of the end customer 300 refer to the persons in their respective organizations who are responsible for defining the roles, functions and access rights of the employees in their respective organizations.
[0035] It is worth noting that the multi-domain identity and access management extended system 100 for access rights and identity management can be installed in several ways.
[0036] One way can be to install the identity and access management system 100 directly locally on the delivered machine or on the delivered industrial system, i.e. in the computer system of the machine or system, which comprises at least one memory for storing the domains and their modules. However, other forms of implementation exist which do not affect the functioning of the invention. Indeed, the system 100 can be installed entirely in the centralized system of the end customer 300 or even in the centralized system of the OEM 200. It is quite feasible to implement the system 100 distributed between the computer systems of the end customer 300 and the OEM. Likewise, the system can also be implemented in the cloud outside the computer systems of the end customer 300 and the OEM 200.
[0037] Figure 2 The steps of a computer-implemented method are illustrated which make possible the creation and use of the multi-domain identity and access management extended system 100 to implement access and identity management.
[0038] In step SO, the OEM creates the system 100. This can take any of the forms discussed previously, for example it can be installed on the memory of the machine. In this case, the machine will be equipped with a communication module so that it can communicate with the systems of the end customer and the OEM.
[0039] In step SI, the OEM creates its domain 101 within the system 100 or the base domain, initializes it and configures the content of the functional storage module 1011 and the data storage module 1012. During this creation, the access rights to the domain 101 of the OEM 200 are configured (for example by the administrator 201) to prevent members of the organization other than the OEM from accessing the content of the modules 1011 and 1012 of the domain 101 of the OEM 200. Likewise, these access rights can only be reconfigured by the OEM 300.
[0040] Optionally, the OEM can create and initialize the end customer domain 102 in the system 100 in sub-step S101. However, this step can also be performed later in the flow, for example by the end customer when the machine and system are transferred to the end customer, by the end customer.
[0041] In the case where sub-step S101 has been performed, another optional sub-step S102 can be performed in which the OEM can pre-configure the domain 102 of the end customer 300 by configuring the content of the data storage module 1022 and the functional storage module 1021 of the end customer domain.
[0042] In step S2, the end customer 300 can create and initialize the end customer domain 102 or the extended domain, if the optional sub-step S101 is not performed.
[0043] Likewise, the end customer 300 can configure the domain 102 of the end user 300 by configuring the content of the data storage module 1022 and the function storage module 1021 of the domain of the end customer, if the optional sub-step S102 is not performed.
[0044] In optional step S3, the end customer 300 can access its domain 102 and make new reservations in the function and data storage modules 1021 and 1022 of its domain 102.
[0045] In optional step S4, the end customer 300 can block the OEM from accessing its domain 101. In this way, the end customer can prevent unintended interventions in the machine or system.
[0046] In optional step S5, the end customer 300 can unlock the OEM's access to its domain 101.
[0047] In optional step S6, the OEM 200 can access its domain 101 and perform new write operations in the function and data storage modules 1021 and 1022 of its domain 101.
[0048] The multi-domain extended IAM 100 allows the original equipment manufacturer (OEM) to always maintain access control to settings, data, and functions. The end customer can configure access rights according to the specific circumstances of the machine, allowing them to assign specific roles or permissions to identity holders such as individuals, employees, and users.
[0049] Embodiments of the present application will be described in detail below with reference to the accompanying drawings. Note that the same reference numbers are used throughout the drawings to refer to the same or like elements.
[0050] In summary, the multi-domain IAM extension system described above provides several technical advantages over the prior art. First, it allows the OEM and the end customer to safely and efficiently manage access to the machine or system without interfering with the identity and access management of the respective other party. This is achieved by creating at least two independent identity management subsystems (or domains) managed by administrators of the respective organizations.
[0051] Second, the invention provides a fine-grained role and permission system for the OEM and the end customer, allowing them to easily manage access to specific functions and data. This improves the security of the machine or system, ensuring that only authorized employees of the relevant organization can access sensitive information or functions.
[0052] Third, the invention enables the integration of machine or system access protection into the end customer's central system, thus simplifying access management to multiple machines or systems. This eliminates the need to manage passwords separately for each machine or system and improves overall security by ensuring that all access rights are centrally managed.
[0053] Furthermore, the invention allows the original equipment manufacturer (OEM) to always control access to its protected data and functions, while the end customer is able to manage access to the machines or systems required for operation within its organization. Moreover, the end customer is able to configure access rights per specific machine, thus allowing different employees to have different roles and rights on different machines or systems.
[0054] Finally, another advantage of the proposed solution is that the end customer is able to block or allow access to the OEM. This ensures that in a remote intervention / remote service environment, the OEM is not able to intervene in a way that compromises the production process implemented by the customer. This significantly improves availability and security on the end customer side.
[0055] Overall, the multi-domain IAM extended system has significant improvements over existing solutions, as it provides a secure and efficient way to manage access to machines or systems with fine control over roles and rights, centralized access management, and the ability to protect data and OEM functions.
[0056] Although the content of the present application has been described in the foregoing by way of preferred embodiments, it is not limited thereto, but can be modified in various ways.
Claims
1. A computer-implemented identity and access management system (100) comprising at least two domains (101, 102) assigned respectively to users of an organization, - wherein, - the first domain (101) being an OEM domain (200) associated with users of an OEM organization, - wherein the second domain (102) is an end customer domain (300) associated with users of an end customer organization, - wherein each domain (101, 102) comprises modules (1011, 1021) for storing functions and modules (1012, 1022) for storing data corresponding to said functions, - wherein the modules (1011) for storing functions and the modules (1012) for storing data of the OEM domain (101) are configured so that the modules for storing functions and the modules for storing data of the OEM domain only authorize access by users (201, 202) of the OEM organization, characterized in that - the system is configured to authorize restricted access to the OEM domain (101) by users (301, 302) of the end customer organization, thereby enabling to block or allow access to the modules (1011) for storing functions and the modules (1012) for storing data of the OEM domain (101) by users (201, 202) of the OEM (200). The modules (1011, 1012) of the OEM domain (101) are configured so that the access rights can only be configured by an administrator (201) of the OEM organization (200).
2. The system of claim 1, wherein, Each domain (101, 102) is locally installed on a computer system of a machine.
3. The system of claim 1 or 2, wherein, Each domain (101, 102) is installed on a central computer system.
4. The system of claim 1 or 2, wherein, The first domain (101) is an OEM domain (200) assigned to users of an OEM organization, and wherein the second domain (102) is an end customer domain (300), 5. A computer-implemented method for creating an identity and access management system (100), in particular according to any one of claims 1 to 6, having at least two domains (101, 102) which are respectively assigned to a user organization, wherein, assigned to users of an end customer organization, wherein the method comprises the steps of: - creating (SO) the identity and access management system (100) by an OEM (200); - creating (SI) the OEM domain (101) by the OEM (200) and initializing and configuring modules (1011) for storing functions and modules (1012) for storing data in the OEM domain (101), wherein the modules (1011) are configured for storing the functions and the modules (1012, 1022) are configured for storing data of the OEM domain (101) so that the modules (1011) and the modules (1012, 1022) only allow access by users of the organization of the OEM (200); - creating (S2) the end customer domain (101) in the system (100) by the OEM (200) or by an end customer (300), characterized in that - the system is configured to authorize restricted access to the OEM domain (101) by users (301, 302) of the end customer organization, thereby enabling to block or allow access to the modules (1011) for storing functions and the modules (1012) for storing data of the OEM domain (101) by users (201, 202) of the OEM (200). authorizing users (301, 302) of the end customer organization to have restricted access to the OEM domain (101), so as to be able to prevent or allow access to the modules (1011) for storing functions and to the modules (1012) for storing data of the OEM domain (101) by users (201, 202) of the OEM (200).
6. The method of claim 5, wherein, The method further comprises: configuring access rights to the OEM domain (101) by an administrator (201) of the OEM (200).
7. The method of claim 6, wherein, The step of configuring access comprises: configuring access rights to the end customer's domain (102) by an administrator (301) of the end customer (300).
8. The method according to any of the preceding claims, characterized in that, The method further comprises: initializing (S101) and configuring (S102) modules for storing functions (1021) and for storing data in the end customer's domain (102) by the OEM (200), or initializing (S101) and configuring (S102) modules for storing functions (1021) and for storing data in the end customer's domain (102) by the end customer (300).
9. The method of claim 8, wherein, The method further comprises: accessing (S3) the end customer's domain (102) by the end customer (300) and performing write operations in the modules for storing functions (1021) and for storing data of the end customer's domain (102).
10. The method according to any of the preceding claims, characterized in that, The method further comprises: preventing (S4) access to the OEM's domain (101) by users (201, 202) of the OEM (200) by the end customer (300).
11. The method according to any of the preceding claims, characterized in that, The method further comprises: unlocking (S5) access to the OEM's domain (101) by the OEM entity (200) by the end customer (300).
12. The method according to any of the preceding claims, characterized in that, The method further comprises: accessing (S6) the OEM domain (101) via the OEM (200) and performing write operations in the modules (1012) of the OEM domain (101) and in the modules (1011) for storing functions.
13. A computer program for creating an identity and access management system (100) having at least two domains (101, 102) which are respectively assigned to user organizations, the computer program having instructions which, when the program is executed by a computer, cause the computer to perform the steps of the method according to any one of claims 5 to 12.
14. A computer-readable recording medium having instructions for creating an identity and access management system (100) having at least two domains (101, 102) which are respectively assigned to user organizations, the instructions causing a computer to perform the steps of the method according to any one of claims 5 to 12 when the instructions are executed by the computer.
Citation Information
Patent Citations
Systems, methods, and storage media for migrating identity information across identity domains in an identity infrastructure
US20210390170A1
Access control apparatus, access control method and printing system
CN101192135A
Multi-domain identity management system
CN104769911A
Domain based authentication scheme
US20100125895A1
Registration and credential roll-out for accessing a subscription-based service
WO2011047276A2