API Hub Architecture for IAM Message Translation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Configuring provisioning systems to interact with multiple identity and access management (IAM) systems is difficult and time-consuming due to the need for specialized configuration for each IAM system, which operates with different APIs and user attribute requirements.

Innovation Solution

An API hub architecture that establishes relationships between provisioning systems, IAM systems, and an intermediate API hub system, enabling message translation and format adjustment for seamless communication between systems, using a pre-processor, translation module, invoker module, receiver module, and post-processor, along with an API metadata store and artificial intelligence for optimized functionality.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If provisioning systems are configured to interact with multiple IAM systems using specialized configuration for each system, then communication capability with specific IAM systems is achieved, but configuration complexity and time consumption increase significantly

Engineering Contradiction:
Improvecommunication capability with IAM systemsVSAvoidconfiguration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces an API hub as an intermediary component that sits between provisioning systems and multiple IAM systems. The API hub receives messages from provisioning systems, determines which IAM systems should receive them, translates messages into appropriate formats for each target IAM system, and forwards them accordingly. This mediator approach allows provisioning systems to interact with multiple IAM systems without requiring specialized configuration for each one, thereby reducing configuration complexity while maintaining versatile communication capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The API hub is designed with multi-functional capabilities to handle diverse IAM system communications through a single unified interface. It can identify multiple target IAM systems, translate between different message formats, and manage communications with various provisioning systems all through one system. This universality allows the provisioning system to gain access to multiple IAM systems without needing separate specialized configurations for each, thus improving adaptability while reducing device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If provisioning systems are specially configured for each IAM system, then deep connection and precise communication are achieved, but time consumption and configuration effort increase

Engineering Contradiction:
Improvecommunication reliabilityVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The API hub performs preliminary actions by pre-configuring translation rules and message format mappings for multiple IAM systems. When a provisioning system sends a message, the API hub has already prepared the necessary translation templates and target system mappings in advance. This preliminary configuration work eliminates the need for time-consuming setup when adding new IAM systems, as the API hub can quickly adapt using pre-established patterns and rules, thereby reducing configuration time while maintaining reliable communication.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The API hub acts as a mediator that handles the complex translation and routing logic, allowing provisioning systems to maintain simple, standardized configurations. The intermediary absorbs the complexity of dealing with multiple IAM system protocols and formats, while provisioning systems only need to communicate with the unified API hub interface. This approach ensures reliable communication through proper message translation while significantly reducing the time required to configure connections with multiple IAM systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If multiple IAM systems with different APIs are supported, then system versatility is improved, but message translation complexity increases

Engineering Contradiction:
Improvesupport for multiple IAM systemsVSAvoidmessage translation complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The API hub segments the message translation process into distinct modular components: message reception, target system identification, format determination, translation execution, and message forwarding. Each IAM system's translation requirements are handled as separate, independent modules within the API hub. This segmentation allows the system to support multiple IAM systems with different APIs by adding or modifying individual translation modules without affecting the entire system, thereby improving versatility while managing translation complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11403156B2API hub architecture
Publication Date: 2022.08.02 THE BANK OF NEW YORK MELLON
  • US11403156B2 patent drawing
  • US11403156B2 patent drawing
  • US11403156B2 patent drawing

AI summary

An application programming interface (API) hub architecture establishes relationships among the provisioning systems, the IAM target systems, and an intermediate API hub system. A provisioning system can send the API hub system a message in a format associated with the IAM system. The API hub determines and identifies which of one or more available IAM systems should receive the message. The API hub system translates the message into a correct format for each of the determined target IAM systems and sends the translated messages to the appropriate target systems. Similarly, the API hub system can receive a message from an IAM system, identify, based on the message, which of one or more provisioning systems should receive the message, translate the message into an appropriate format for each of the determined one or more provisioning systems, and send the formatted message to the determined provisioning systems.