API Hub Architecture for IAM Message Translation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Configuring provisioning systems to interact with multiple identity and access management (IAM) systems is difficult and time-consuming due to the need for specialized configuration for each IAM system, which operates with different APIs and user attribute requirements.
Innovation Solution
An API hub architecture that establishes relationships between provisioning systems, IAM systems, and an intermediate API hub system, enabling message translation and format adjustment for seamless communication between systems, using a pre-processor, translation module, invoker module, receiver module, and post-processor, along with an API metadata store and artificial intelligence for optimized functionality.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If provisioning systems are configured to interact with multiple IAM systems using specialized configuration for each system, then communication capability with specific IAM systems is achieved, but configuration complexity and time consumption increase significantly
Solution Approach 1:
The patent introduces an API hub as an intermediary component that sits between provisioning systems and multiple IAM systems. The API hub receives messages from provisioning systems, determines which IAM systems should receive them, translates messages into appropriate formats for each target IAM system, and forwards them accordingly. This mediator approach allows provisioning systems to interact with multiple IAM systems without requiring specialized configuration for each one, thereby reducing configuration complexity while maintaining versatile communication capability.
Solution Approach 2:
The API hub is designed with multi-functional capabilities to handle diverse IAM system communications through a single unified interface. It can identify multiple target IAM systems, translate between different message formats, and manage communications with various provisioning systems all through one system. This universality allows the provisioning system to gain access to multiple IAM systems without needing separate specialized configurations for each, thus improving adaptability while reducing device complexity.
2Reliability
If provisioning systems are specially configured for each IAM system, then deep connection and precise communication are achieved, but time consumption and configuration effort increase
Solution Approach 1:
The API hub performs preliminary actions by pre-configuring translation rules and message format mappings for multiple IAM systems. When a provisioning system sends a message, the API hub has already prepared the necessary translation templates and target system mappings in advance. This preliminary configuration work eliminates the need for time-consuming setup when adding new IAM systems, as the API hub can quickly adapt using pre-established patterns and rules, thereby reducing configuration time while maintaining reliable communication.
Solution Approach 2:
The API hub acts as a mediator that handles the complex translation and routing logic, allowing provisioning systems to maintain simple, standardized configurations. The intermediary absorbs the complexity of dealing with multiple IAM system protocols and formats, while provisioning systems only need to communicate with the unified API hub interface. This approach ensures reliable communication through proper message translation while significantly reducing the time required to configure connections with multiple IAM systems.
3Adaptability or versatility
If multiple IAM systems with different APIs are supported, then system versatility is improved, but message translation complexity increases
Solution Approach 1:
The API hub segments the message translation process into distinct modular components: message reception, target system identification, format determination, translation execution, and message forwarding. Each IAM system's translation requirements are handled as separate, independent modules within the API hub. This segmentation allows the system to support multiple IAM systems with different APIs by adding or modifying individual translation modules without affecting the entire system, thereby improving versatility while managing translation complexity through modular architecture.
Data Source
AI summary
An application programming interface (API) hub architecture establishes relationships among the provisioning systems, the IAM target systems, and an intermediate API hub system. A provisioning system can send the API hub system a message in a format associated with the IAM system. The API hub determines and identifies which of one or more available IAM systems should receive the message. The API hub system translates the message into a correct format for each of the determined target IAM systems and sends the translated messages to the appropriate target systems. Similarly, the API hub system can receive a message from an IAM system, identify, based on the message, which of one or more provisioning systems should receive the message, translate the message into an appropriate format for each of the determined one or more provisioning systems, and send the formatted message to the determined provisioning systems.


