Access Event Logging with Identity Profile Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access management systems in E-business environments face challenges in securely managing user access and scaling to handle increased traffic and user volume, while also providing comprehensive reporting and load balancing, as they often lack integration with identity management systems and struggle with decentralized administrative scaling.

Innovation Solution

A system that logs access system events, incorporating identity management and access management functionalities, which creates log entries with identity profile information, including authentication and authorization events, resource access details, and rule evaluations, to facilitate business reporting, load balancing, and monitoring.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If access management systems store and manage identity information in application-specific formats on a per-application basis, then each application can access its own identity information, but it becomes labor intensive to maintain consistency across disparate repositories and increases administrative cost

Engineering Contradiction:
Improveapplication-specific identity managementVSAvoidmultiple disparate repositories
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges multiple application-specific identity repositories into a single centralized identity repository that stores identity information in a unified format. This consolidation eliminates the need to maintain consistency across disparate repositories while still providing identity management services to multiple applications, thereby reducing administrative complexity and cost.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The centralized identity repository is designed to serve multiple applications universally, storing identity information in a format that can be accessed and utilized by different applications. This multi-functional approach allows a single repository to replace multiple application-specific repositories, reducing the overall system complexity while maintaining adaptability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Productivity

If access management systems are scaled to handle increased traffic and user volume, then the system can accommodate more users, but additional administrative effort is required which creates bottlenecks

Engineering Contradiction:
Improveuser volume handling capacityVSAvoidadministrative effort
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent segments administrative functions into two categories: centralized identity management for system-wide operations and decentralized policy administration for application-specific operations. This segmentation allows the system to scale user volume efficiently while minimizing the need for additional centralized administrative effort, as policy administration can be delegated to local administrators.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system enables self-service capabilities where administrators can perform policy administration tasks locally without requiring centralized intervention for every operation. This reduces the time loss associated with administrative efforts while the system scales to handle increased user volume and traffic.

Inventive Principle:
Principle #25Self-service

3Loss of information

If access management systems provide detailed logging and reporting capabilities, then administrators gain comprehensive insights for monitoring and load balancing, but the system complexity and resource requirements increase

Engineering Contradiction:
Improveaccess event informationVSAvoidlogging and reporting infrastructure
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent extracts the logging and reporting functions from the core access management system and implements them as separate, modular components. This extraction allows detailed access event information to be captured and analyzed without significantly increasing the complexity of the core system, as the logging infrastructure can be independently configured and managed.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9038170B2Logging access system events
Publication Date: 2015.05.19 ORACLE INT CORP
  • US9038170B2 patent drawing
  • US9038170B2 patent drawing
  • US9038170B2 patent drawing

AI summary

A system is disclosed that logs access system events. When an access system event occurs, a log entry is created for the access system event. Information from an identity profile is stored in the log entry. The identity profile pertains to a first user. The first user is the entity who caused or was involved with the access system event. In one embodiment, the access system includes identity management and access management functionality.