Automated Database Upgrade Framework for Multi-Tenant Identity Cloud

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current identity management systems in cloud environments face challenges in providing secure access across diverse devices and user types, including unauthorized access, account hijacking, and inconsistent security between cloud and on-premise environments, particularly when managing access for employees, customers, and partners.

Innovation Solution

A multi-tenant cloud-based identity management system with a global database and tenant databases, implementing an automated upgrade framework, microservices architecture, and secure access protocols like OAuth and SAML to ensure secure, scalable, and unified identity and access management across hybrid cloud deployments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual database upgrade processes are used to ensure security and consistency, then system reliability is improved, but system complexity and time consumption increase

Engineering Contradiction:
Improvedatabase upgrade reliabilityVSAvoidupgrade process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements automated database upgrade capability where the database management system automatically detects, executes, and validates upgrade operations without requiring manual intervention. This self-service approach maintains reliability through built-in validation mechanisms while reducing operational complexity and human error.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary validation and compatibility checks before executing database upgrades. By pre-assessing upgrade requirements and preparing migration scripts in advance, the system ensures reliable upgrades while streamlining the actual execution process, reducing both complexity and downtime.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If frequent database upgrades are implemented to provide new features, then adaptability is improved, but system stability and security risks increase

Engineering Contradiction:
Improvesystem adaptabilityVSAvoidsystem stability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system implements periodic, scheduled database upgrades rather than continuous or ad-hoc updates. This periodic approach allows for thorough testing and validation between upgrades, maintaining system stability while progressively delivering new features and improvements over time.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The system implements backup and rollback mechanisms before executing database upgrades. By preparing recovery procedures in advance, the system can safely implement frequent upgrades while maintaining stability, as any problematic upgrade can be reverted without compromising system integrity.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

3Reliability

If centralized database management is used to ensure consistent security policies, then security consistency is improved, but system complexity and maintenance burden increase

Engineering Contradiction:
Improvesecurity consistencyVSAvoidmanagement complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements a universal database management framework that handles multiple functions including security policy enforcement, upgrade management, and compliance validation through a single centralized interface. This multi-functional approach ensures security consistency across all databases while reducing overall management complexity through consolidation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11669321B2Automated database upgrade for a multi-tenant identity cloud service
Publication Date: 2023.06.06 ORACLE INT CORP
  • US11669321B2 patent drawing
  • US11669321B2 patent drawing
  • US11669321B2 patent drawing

AI summary

Embodiments include a multi-tenant cloud-based identity management system for a plurality of tenants. Embodiments include a global database providing a first set of resources to the plurality of tenants and a plurality of tenant databases, each tenant database providing a second set of resources to one of the plurality of tenants. Embodiments further include a plurality of resources accessible by the tenants and an automated upgrade framework for upgrading the global database and the tenant databases in response to an upgrade of a first release of the system to a second release of the system. For the automated upgrade framework, embodiments determine resource changes between the first release and the second release, generate an upgrade patch based on the resource changes and apply the upgrade patch to the global database.