BPEL4WS Identity Transformation in SOA

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In a Service-Oriented Architecture (SOA) environment, there is no straightforward process or policy-based means to transform a user's identity or credentials for transaction fulfillment, leading to difficulties in access control and authentication across different systems, especially in federated environments where multiple authentications are cumbersome and inefficient.

Innovation Solution

Extending business process models with identity and attribute information, conforming to BPEL4WS, to enable identity transformation and propagation, allowing for seamless credential mapping and refinement during transaction execution, facilitating robust Web services exposure even in loosely-coupled environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If single sign-on (SSO) techniques are used to map partner user to locally-known identifier, then ease of operation is improved, but device complexity worsens due to lack of process or policy-based means for identity transformation

Engineering Contradiction:
Improveauthentication processVSAvoididentity transformation system
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces BPEL4WS business process models as an intermediary layer between the SSO system and local applications. These models contain embedded identity mapping information that acts as a mediator to automatically transform partner user identifiers into locally-valid identifiers at each step of the business process, eliminating the need for complex manual identity management while maintaining ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies preliminary action by pre-configuring identity mapping information within the BPEL4WS business process models before execution. The identity transformation rules are defined in advance as part of the process model, allowing automatic credential transformation to occur seamlessly during transaction fulfillment without requiring complex runtime decision-making systems.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If multiple authentications are required to access resources, then security is improved, but ease of operation worsens due to repeated authentication requirements

Engineering Contradiction:
Improveaccess controlVSAvoiduser access process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The BPEL4WS business process model serves as an intermediary that manages the multiple authentication requirements. It contains embedded identity mapping information that automatically handles the transformation of credentials at each access point, maintaining security through proper authentication while eliminating the operational burden of repeated manual authentication for users.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If business process models are extended with identity mapping information, then adaptability is improved, but device complexity increases due to model extension requirements

Engineering Contradiction:
Improveidentity transformation capabilityVSAvoidbusiness process model
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies universality by extending the existing BPEL4WS business process model standard to include identity mapping information. This allows the same model structure to serve multiple functions: both orchestrating business process execution and managing identity transformation, thereby improving adaptability without proportionally increasing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9027093B2Business process enablement for identity management
Publication Date: 2015.05.05 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US9027093B2 patent drawing
  • US9027093B2 patent drawing
  • US9027093B2 patent drawing

AI summary

A method, system and computer program for business process automation facilitates transforming a user's identity/credentials as part of the enablement of transaction fulfillment, e.g., within a SOA environment. In one embodiment, identity and attribute information is added to one or more business process models that each represents a sub-transaction within an overall transaction fulfillment business process flow. As the business model is mapped to an execution environment, the identity and attribute information in the model is used to configure appropriate tooling to define the identity/attribute transformation required to complete the particular portion of the transaction represented by the model. In a representative implementation, the business process models conform to BPEL4WS, and one or more of these models are extended with identity mapping information such that, during transaction fulfillment, local identity mapping transformations provide the identity/credential propagation required to support the business process.