Unified identity management method and system based on adapter mode

By adopting the adapter mode in the unified identity management system, the interface and data structure adaptation to multiple data sources and subscribers is solved, and the system's adaptability and scalability are improved.

CN120013475APending Publication Date: 2025-05-16COSCO SHIPPING TECH (BEIJING) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510102073.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-22
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

The existing unified identity management system is highly closed and cannot support multiple data sources at the same time. The interface protocol is fixed when connected to downstream systems and cannot be changed dynamically, resulting in the inability to effectively manage account information between different systems.

Method used

Adopt the unified identity management system based on the adapter mode, through the data source adaptation module and the subscriber adaptation module, the interface adaptation and data structure adaptation of different data sources and subscribers are realized, and the connection between data sources such as Rest API, JDBC, LDAP and standard data interfaces, mail system interfaces and other subscribers are supported.

Benefits of technology

It solves the problem of enclosed identity management system, supports access to multiple data sources at the same time, dynamically defines interface standards, provides full-process data conversion and data field mapping functions, realizes effective takeover of the existing data of downstream systems, and improves the adaptability and scalability of the identity management system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120013475A_ABST
    Figure CN120013475A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a unified identity management system and method based on an adapter mode, and the system comprises a data source adaption module which is matched with the interfaces of different data sources; the data source identity data structure adaptation module is adapted to identity data structures of different data sources; the data source identity data pulling and storing module is configured to obtain and store identity data of different data sources; the subscriber adaptation module is adapted to interfaces of different subscribers; the subscriber identity data structure adaptation module is adapted to identity data structures of different subscribers; and the identity data filtering and routing adaptation module is configured to read and filter the identity data, and respectively route the identity data to different downstream subscriber adapters. The dynamic definition of an interface standard is supported, the functions of data conversion, data field definition and data field mapping are provided, multiple data sources are supported to be accessed at the same time, different downstream systems can be connected in a butt joint mode, and the adaptation degree and expansibility of the identity management system are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of data processing, and in particular relates to a unified identity management method and system based on an adapter mode. Background Art

[0002] The rapid development of the information age usually requires different businesses to be completed in various software systems. Usually, due to the differences in account information and other information, different software systems have different account login information between different systems, and the same user can only log in to different systems with different accounts. For this reason, some unified identity management systems have emerged, but the existing unified identity management systems are closed, and their data sources are all SAP standard interfaces or other standard interfaces. An identity management system can only support one data source at a time, and the existing unified identity management system requires the existing system to rebuild the user system, and the existing accounts of the downstream system cannot be included in the unified identity management system for unified management.

[0003] For example, a certain group has built multiple application systems, including OA systems, reimbursement systems, ERP systems, etc. These systems need to save the company's employee information in the database of each system so that employees can log in to these systems to operate. However, the employee information and employee data range that each system needs to save are different. In order to carry out unified identity management, the group needs to adopt a unified identity management system. However, the identity management system on the market can only connect to a single identity data source, which is basically the SAP HR system, and connecting to other types of identity data sources requires customized secondary development. At the same time, the identity management system on the market can only connect to downstream systems based on a standard interface protocol. This standard protocol fixes the requirements for communication protocols, serialization protocols, data formats, and data fields, and cannot dynamically change data formats and data fields. Summary of the invention

[0004] In view of this, on one hand, some embodiments disclose a unified identity management system based on an adapter mode, the system comprising:

[0005] A data source adapter module, configured to adapt and connect to interfaces of different data sources;

[0006] A data source identity data structure adaptation module configured to adapt to identity data structures of different data sources;

[0007] A data source identity data extraction and storage module is configured to obtain identity data from different data sources and save it;

[0008] A subscriber adapter module configured to adapt and connect to interfaces of different subscribers;

[0009] A subscriber identity data structure adaptation module is configured to adapt to the identity data structures of different subscribers;

[0010] The identity data filtering and routing adapter module is configured to read the identity data and filter it, and route it to different downstream subscriber adapters respectively.

[0011] Furthermore, in some embodiments of the unified identity management system based on the adapter mode, the data source adapter module is configured to implement the management and connection of three types of data sources of three adapters: Rest API, JDBC, and LDAP.

[0012] In the unified identity management system based on the adapter mode disclosed in some embodiments, the data source adapter module provides an identity authentication interface, an identity query interface and an identity field configuration interface respectively.

[0013] In some embodiments of the unified identity management system based on the adapter mode disclosed, the subscriber adaptation module is configured to implement the docking of three different interfaces, namely, the standard data interface, the mail system interface, and the enterprise WeChat system interface, in the form of a Rest API.

[0014] In the unified identity management system based on the adapter mode disclosed in some embodiments, the subscriber adaptation module provides an identity authentication interface, an identity push interface and an identity field configuration interface respectively.

[0015] Some embodiments disclose a unified identity management system based on an adapter pattern, in which a data source identity data structure adaptation module is configured to configure the identity data field list definition, field name, field type, field value range, field uniqueness, data conversion definition, field mapping relationship, and field format conversion rules of the data source; a subscriber identity data structure adaptation module is configured to configure the identity data field list definition, field name, field type, field value range, field uniqueness, data conversion definition, field mapping relationship, and field format conversion rules of the subscriber.

[0016] In some embodiments of the unified identity management system based on the adapter mode, the identity field configuration includes:

[0017] Field definitions of data sources, including field name, field type, field length, and field description;

[0018] Definition of the data field where the data is going, including field name, field type, field length, and field description;

[0019] The mapping of data source to destination field, where the destination field is a fixed value, or a value directly taken from the source field, or a value obtained by concatenating and converting multiple field values ​​of the source field, or a value dynamically generated directly using a Groovy script.

[0020] In some embodiments of the unified identity management system based on the adapter mode, the triggering time for filtering identity data is configured to be when pulling from a data source, during data routing, or when pushing to a subscriber; the routing of identity data is implemented using the routing mechanism of Rabbit MQ.

[0021] On the other hand, some embodiments disclose a unified identity management method based on an adapter mode, which is performed based on the unified identity management system based on the adapter mode disclosed in the embodiments of the present invention, including:

[0022] Configure the data source adapter module to adapt and connect to different data source interfaces;

[0023] Configuring the data source identity data structure to adapt to the identity data structure of different data sources;

[0024] Configure the data source identity data pulling and storage module to obtain identity data from different data sources and store it in local storage media;

[0025] Configure the subscriber adapter module to adapt and connect with different subscriber interfaces;

[0026] Configure the subscriber identity data structure adaptation module to adapt to the identity data structures of different subscribers;

[0027] Configure the identity data filtering and routing configuration modules to filter the identity data and route them to different downstream subscriber adapters respectively.

[0028] The unified identity management method of the configuration mode disclosed in some embodiments further includes configuring a data source periodic incremental synchronization timer; and / or configuring a subscriber data incremental delivery timer.

[0029] The unified identity management system and method based on the adapter mode disclosed in the embodiment of the present invention support dynamic definition of interface standards, provide full-process data conversion, data field definition, and data field mapping functions, solve the closed problem of the unified identity management system, support simultaneous access to multiple data sources, and can connect to downstream systems of different standards, thereby improving the adaptability and scalability of the identity management system and solving the problem of the same identity management system taking over the stock data of downstream systems. BRIEF DESCRIPTION OF THE DRAWINGS

[0030] Figure 1 A schematic flow chart of a unified identity management method based on an adapter mode disclosed in some embodiments;

[0031] Figure 2 A schematic diagram of the composition of a unified identity management system based on an adapter pattern disclosed in some embodiments. DETAILED DESCRIPTION

[0032] The word "embodiment" used herein as an "exemplary" does not necessarily mean that any embodiment described is superior or better than other embodiments. Performance index tests in the embodiments of the present invention are performed using conventional test methods in the art unless otherwise specified. It should be understood that the terms described in the embodiments of the present invention are only used to describe specific implementation methods and are not intended to limit the contents disclosed in the embodiments of the present invention.

[0033] Unless otherwise specified, the technical and scientific terms used herein have the same meanings as commonly understood by ordinary technicians in the technical field to which the embodiments of the present invention belong; other experimental methods and technical means not specifically specified in the embodiments of the present invention refer to experimental methods and technical means commonly used by ordinary technicians in the field.

[0034] The terms "substantially" and "approximately" used herein are used to describe small fluctuations. For example, they can refer to less than or equal to ±5%, such as less than or equal to ±2%, such as less than or equal to ±1%, such as less than or equal to ±0.5%, such as less than or equal to ±0.2%, such as less than or equal to ±0.1%, such as less than or equal to ±0.05%. The numerical data represented or presented in the range format herein are used only for convenience and brevity, and should therefore be flexibly interpreted as including not only the values ​​clearly listed as the limits of the range, but also all independent values ​​or sub-ranges contained in the range. For example, the numerical range of "1-5%" should be interpreted as including not only the clearly listed values ​​of 1% to 5%, but also the independent values ​​and sub-ranges within the range shown. Therefore, independent values ​​such as 2%, 3.5% and 4% and sub-ranges such as 1%-3%, 2%-4% and 3%-5% are included in this numerical range. This principle also applies to the range of only one numerical value. In addition, such an interpretation applies regardless of the width of the range or the characteristics described.

[0035] In this document, including in the claims, transitional words such as "comprises," "includes," "with," "having," "containing," "involving," "accommodating," etc. are understood to be open-ended, i.e., meaning "including but not limited to." Only the transitional words "consisting of" and "composed of" are closed transitional words.

[0036] In order to better illustrate the present invention, numerous specific details are provided in the specific examples below. It should be understood by those skilled in the art that the present invention can be implemented without certain specific details. In the embodiments, some methods, means, instruments, equipment, etc. well known to those skilled in the art are not described in detail in order to highlight the gist of the present invention.

[0037] Under the premise of no conflict, the technical features disclosed in the embodiments of the present invention may be arbitrarily combined, and the resulting technical solutions belong to the contents disclosed in the embodiments of the present invention.

[0038] In some implementations, a unified identity management system based on an adapter pattern includes:

[0039] A data source adapter module, configured to adapt and connect to interfaces of different data sources;

[0040] In some embodiments, the data source adapter module is configured to implement the management and docking of three types of data sources of three adapters: Rest API, JDBC, and LDAP;

[0041] In some embodiments, the data source adapter module provides an identity authentication interface, an identity query interface, and an identity field configuration interface respectively;

[0042] In some embodiments, the identity field configuration includes: field definition of the data source, including field name, field type, field length, and field description; field definition of the data destination, including field name, field type, field length, and field description; mapping of the data source to the destination field, wherein the destination field is a fixed value, or the value of the source field, or the concatenation and conversion of multiple field values ​​of the source field, or is directly generated dynamically using a Groovy script;

[0043] A data source identity data structure adaptation module is configured to adapt to identity data structures of different data sources; in some embodiments, the data source identity data structure adaptation module is configured to configure the identity data field list definition, field name, field type, field value range, field uniqueness, data conversion definition, field mapping relationship, and field format conversion rules of the data source;

[0044] The data source identity data extraction and storage module is configured to obtain identity data of different data sources and save them; in some embodiments, the data source identity data extraction and storage module is configured to trigger the acquisition of data source identity data at a fixed time, and its acquisition action is to call the identity data query interface of the data source adapter, and the data obtained from the adapter is the converted data; and the data obtained from the data source is stored in the storage medium database;

[0045] A subscriber adapter module configured to adapt and connect to interfaces of different subscribers;

[0046] In some embodiments, the subscriber adaptation module is configured to implement the docking of three different interfaces, namely, the standard data interface, the mail system interface, and the enterprise WeChat system interface, in the form of a Rest API;

[0047] In some embodiments, the subscriber adaptation module provides an identity authentication interface, an identity push interface, and an identity field configuration interface respectively;

[0048] In some embodiments, the identity field configuration includes: field definition of the data source, including field name, field type, field length, and field description; data field definition of the data destination, including field name, field type, field length, and field description; mapping of the data source to the destination field, wherein the destination field is a fixed value, or a value directly taken from the source field, or a value obtained by concatenating and converting multiple field values ​​of the source field, or a value dynamically generated directly using a Groovy script;

[0049] A subscriber identity data structure adaptation module configured to adapt to identity data structures of different subscribers; in some embodiments, the subscriber identity data structure adaptation module is configured to configure the subscriber's identity data field list definition, field name, field type, field value range, field uniqueness, data conversion definition, field mapping relationship, and field format conversion rules;

[0050] The identity data filtering and routing adapter module is configured to read the identity data and filter it, and route it to different downstream subscriber adapters respectively.

[0051] In some embodiments, the triggering timing for filtering identity data is configured to be when pulling from a data source, or during data routing, or when pushing to a subscriber; the routing of identity data is implemented using the routing mechanism of Rabbit MQ.

[0052] Some embodiments disclose a unified identity management method based on an adapter pattern, such as Figure 1 As shown, the unified identity management system based on the adapter mode disclosed in the embodiment of the present invention is performed, including:

[0053] Configure the data source adapter module to adapt and connect with the interfaces of different data sources; usually the data source includes identity data of multiple systems, and the multiple data sources can be the same data source or different data sources;

[0054] Configure the data source identity data structure module to adapt to the identity data structures of different data sources;

[0055] Configure the timer for scheduled incremental synchronization of data sources;

[0056] Configure the data source identity data pulling and storage module to obtain identity data from different data sources and store it in local storage media;

[0057] Configure the subscriber adapter module to adapt and connect with the subscriber interface; usually the subscriber includes multiple systems, and each system can have the same identity information data or different identity information data;

[0058] Configure the subscriber identity data structure adaptation module to adapt to the identity data structures of different subscribers;

[0059] Configure the identity data filtering and routing configuration modules to filter the identity data and route them to different downstream subscriber adapters;

[0060] Configure the incremental delivery timer for subscriber identity data.

[0061] Some embodiments disclose a unified identity management system based on an adapter pattern, such as Figure 2 As shown, including:

[0062] Data source adapter, a component that adapts to and connects to the data source interface. A unified identity management system can be configured with multiple data source adapters and connect to multiple different types of data sources at the same time; it is equipped with an authentication interface, an identity query interface, and an identity field configuration interface;

[0063] Timers, including: data source synchronization timer and subscriber synchronization timer; data source synchronization timer is bound to data source adapter, and according to timer settings, the identity query interface in the data source adapter is periodically triggered to obtain the incremental identity change data of the corresponding data source; subscriber synchronization timer is bound to subscriber adapter, and according to timer settings, the identity push interface in the subscriber adapter is periodically triggered to push the identity change data to the corresponding subscriber;

[0064] Persistent middleware is used to store important data such as configuration data, interface execution results, and local identity data in a unified identity management system; configuration data includes parameters corresponding to each interface of each data source adapter, timer setting data, and parameters corresponding to each interface of the subscriber adapter; interface execution results include identity data obtained after the data source identity query interface is executed, and result data returned after the subscriber adapter identity push interface is executed; local identity data is local identity data generated after the data source identity query interface is executed according to data filtering and data conversion rules;

[0065] The message middleware includes a routing module and a storage module; the routing module routes the identity data from the data source or the local identity data to multiple subscribers; the storage module creates a queue for each subscriber, and the queue stores the identity change data in order;

[0066] Subscriber adapter, a component that adapts to the subscriber interface. A unified identity management system can be configured with multiple subscriber adapters to connect to multiple different types of subscribers at the same time; it is equipped with an authentication interface, an identity push interface, and an identity field configuration interface;

[0067] The technical details are further illustrated below in conjunction with embodiments.

[0068] Example 1

[0069] In Example 1, for the same data source (such as SAP HR) and different types of subscribers (such as ERP system and mail system), the unified identity management method based on the adapter pattern includes:

[0070] Configure the data source, determine the service address, service interface, data format and structure returned by the identity data provider, data filtering conditions and data conversion rules;

[0071] Configure data filtering settings to synchronize all employees whose employee type is "internal employee";

[0072] Configure data conversion settings to convert gender 0 and 1 data to male and female respectively; configure AppId and AppSecret required by the ERP system authentication interface;

[0073] Configure the timer configuration for scheduled incremental synchronization of the data source. After importing the existing data of the data source into the identity management system at one time, start the timer for incremental synchronization of the data source.

[0074] Import the existing data of data source identity information at one time;

[0075] Using the visual interface, use the ERP system subscriber initialization function to call the subscriber's stock data acquisition interface, match the identity information data stored locally in the identity management system with the ERP system stock data, and establish a mapping relationship; set the unique key of the data on the ERP system side;

[0076] Configure the subscriber configuration of the ERP system. The ERP system is synchronized in the Rest API mode. Select the adapter type of the subscriber as "Standard Rest API Type";

[0077] After completing the initialization of the ERP system subscriber, configure the subscriber timer configuration and enable the timer for incremental delivery of subscriber identity data;

[0078] Configure the subscriber configuration of the mail system. The mail system is synchronized in the form of Web Service. Select the adapter type of the subscriber as "Mailbox System WebService";

[0079] Configure data filtering configuration, and synchronize employees in the employee department at the group headquarters;

[0080] Configure data conversion settings to convert employee names into pinyin; configure the account name and password required by the mail system authentication interface; set the unique key for the data on the mail system side, which is used to map the mail system's stock data with the identity information stored locally in the identity management system, and prevent data duplication when incremental data is sent;

[0081] Using the visual interface, use the mail system subscriber initialization function to initialize the mail system subscriber adapter, and establish a mapping relationship between the identity information data stored locally in the identity management system and the mail system stock data;

[0082] After completing the initialization of the mail system subscriber, configure the subscriber timer configuration and enable the timer for incremental delivery of subscriber identity data.

[0083] Example 2

[0084] In Example 2, for different data sources (SAP HR system-Rest API type and supplier management system-JDBC type), different types of subscribers (for example, internal system 1 and internal system 2), internal system 1 only needs identity data in the HR system, and internal system 2 needs data in the HR system and supplier management system, the unified identity management method based on the adapter pattern includes:

[0085] Configure the SAP HR system data source, fill in the service address of the HR system identity interface, the data format and structure returned by the interface, the required data filtering conditions and data conversion rules;

[0086] Configure the timer configuration for scheduled incremental synchronization of the SAP HR system data source. After importing the existing data of the data source into the identity management system at one time, start the timer for incremental synchronization of the data source.

[0087] Configure the supplier management system data source, fill in the JDBC connection string, database connection username and password, database table name and table field subscription, data filtering conditions and data conversion rules corresponding to the supplier management system database;

[0088] Configure the supplier management system data source, import the existing data of the data source into the identity management system at one time, and start the timer for incremental synchronization of the data source;

[0089] Configure the subscriber configuration of internal system 1. Internal system 1 is synchronized in the Rest API mode. Select the adapter type of the subscriber as "Standard Rest API Type";

[0090] Configure data filtering settings to synchronize all data from the HR system data source;

[0091] Configure data conversion settings to convert gender 0 and 1 data to male and female respectively; configure the AppId and AppSecret required by the internal system 1 authentication interface;

[0092] Import the existing data of data source identity information at one time;

[0093] Using the visual interface, use the subscriber initialization function, which will call the subscriber's stock data acquisition interface to match the identity information data stored locally in the identity management system with the stock data in the internal system 1, and establish a mapping relationship;

[0094] Set a unique key for the data on the internal system 1 side. This unique key is used to map the existing data in the internal system 1 with the identity information stored locally in the identity management system, and to prevent data duplication when incremental data is sent down.

[0095] After completing the initialization of the internal system 1 subscriber, configure the subscriber timer configuration and enable the timer for incremental delivery of subscriber identity data;

[0096] Configure the subscriber configuration of internal system 2. Internal system 2 is synchronized in the Rest API mode. Select the adapter type of the subscriber as "Standard Rest API Type";

[0097] Configure data filtering settings to synchronize all data from the HR system data source or the supplier management system data source;

[0098] Configure data conversion settings to convert gender 0 and 2 data to male and female respectively; configure the AppId and AppSecret required by the internal system 2 authentication interface;

[0099] After completing the one-time import of the stock data of the data source, use the visualization interface and the subscriber initialization function to call the subscriber's stock data acquisition interface, match the identity information data stored locally in the identity management system with the stock data of the internal system 2, and establish a mapping relationship;

[0100] Set the unique key for the data on the internal system 2 side;

[0101] After completing the initialization of the internal system 2 subscriber, configure the subscriber timer configuration and enable the timer for incremental delivery of subscriber identity data.

[0102] The unified identity management system and method based on the adapter mode disclosed in the embodiment of the present invention solve the closed problem of the unified identity management system, support simultaneous access to multiple data sources, support dynamic definition of interface standards, provide full-process data conversion, data field definition, and data field mapping functions, and solve the problem of the same identity management system taking over the stock data of the downstream system.

[0103] The technical solutions disclosed in the embodiments of the present invention and the technical details disclosed in the embodiments are merely illustrative of the inventive concept of the present invention and do not constitute a limitation on the technical solutions of the embodiments of the present invention. Any conventional changes, replacements or combinations of the technical details disclosed in the embodiments of the present invention have the same inventive concept as the present invention and are within the protection scope of the claims of the present invention.

Claims

1. A unified identity management system based on the adapter pattern, characterized in that: The system includes: A data source adapter module, configured to adapt and connect to interfaces of different data sources; A data source identity data structure adaptation module configured to adapt to identity data structures of different data sources; A data source identity data extraction and storage module is configured to obtain identity data from different data sources and save it; A subscriber adapter module configured to adapt and connect to interfaces of different subscribers; A subscriber identity data structure adaptation module is configured to adapt to the identity data structures of different subscribers; The identity data filtering and routing adapter module is configured to read the identity data and filter it, and route it to different downstream subscriber adapters respectively.

2. The unified identity management system based on the adapter mode according to claim 1, characterized in that: The data source adapter module is configured to implement the management and docking of three types of data sources of three adapters: Rest API, JDBC, and LDAP.

3. The same identity management system based on the adapter pattern according to claim 2 is characterized in that: The data source adapter module provides an identity authentication interface, an identity query interface and an identity field configuration interface respectively.

4. The unified identity management system based on the adapter mode according to claim 1, characterized in that: The subscriber adaptation module is configured to realize the connection of three different interfaces: standard data interface, mail system interface and enterprise WeChat system interface in the form of Rest API.

5. The unified identity management system based on the adapter mode according to claim 4, characterized in that: The subscriber adaptation module provides an identity authentication interface, an identity push interface and an identity field configuration interface respectively.

6. The unified identity management system based on the adapter mode according to claim 1, characterized in that: The data source identity data structure adaptation module is configured to configure the identity data field list definition, field name, field type, field value range, field uniqueness, data conversion definition, field mapping relationship, and field format conversion rules of the data source; The subscriber identity data structure adaptation module is configured to configure the subscriber's identity data field list definition, field name, field type, field value range, field uniqueness, data conversion definition, field mapping relationship, and field format conversion rules.

7. The unified identity management system based on the adapter mode according to claim 3 or 5, characterized in that: The identity field configuration includes: Field definitions of data sources, including field name, field type, field length, and field description; Definition of the data field where the data is going, including field name, field type, field length, and field description; The mapping of data source to destination field, where the destination field is a fixed value, or a value directly taken from the source field, or a value obtained by concatenating and converting multiple field values ​​of the source field, or a value dynamically generated directly using a Groovy script.

8. The unified identity management system based on the adapter mode according to claim 1, characterized in that: The trigger timing for filtering identity data is configured as when it is pulled from the data source, during data routing, or when it is pushed to the subscriber; the routing of identity data is implemented using the routing mechanism of Rabbit MQ.

9. A unified identity management method based on an adapter mode, based on the unified identity management system based on an adapter mode according to any one of claims 1 to 8, comprising: Configure the data source adapter module to adapt and connect to different data source interfaces; Configuring the data source identity data structure to adapt to the identity data structure of different data sources; Configure the data source identity data pulling and storage module to obtain identity data from different data sources and store it in local storage media; Configure the subscriber adapter module to adapt and connect with different subscriber interfaces; Configure the subscriber identity data structure adaptation module to adapt to the identity data structures of different subscribers; Configure the identity data filtering and routing configuration modules to filter the identity data and route them to different downstream subscriber adapters respectively.

10. The unified identity management method based on configuration mode according to claim 9, characterized in that: Also includes: Configure the data source scheduled incremental synchronization timer; Configure the incremental delivery timer for subscriber data.