Cloud Domain Registration Across Multiple Identity Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current federated identity architecture limits the use of a user identity defined in an enterprise identity provider across multiple sovereign cloud services networks, requiring separate cloud tenant setups and preventing the use of the same domain name across different cloud-based identity providers, which hinders seamless authentication and access to services across different cloud networks.

Innovation Solution

A system and method for registering a domain in one cloud services network while concurrently registering it in another, allowing selection of cloud-based identity providers for user authentication and federating authentication requests from different cloud services networks to a single enterprise identity provider, using verification codes and partition table synchronization to manage domain registrations and authentication processes across multiple clouds.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the same domain is registered with multiple cloud-based identity providers, then user identity portability and access across cloud networks is improved, but domain name uniqueness requirements and security validation complexity worsen

Engineering Contradiction:
Improveuser identity portabilityVSAvoiddomain registration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the domain registration process by introducing cloud tenant IDs as unique identifiers for each cloud network registration. This allows the same domain to be divided into multiple registrations across different cloud networks (e.g., cloud tenant ID 102 for first cloud, 104 for second cloud), resolving the contradiction by enabling identity portability while maintaining registration uniqueness through the combination of domain name and cloud tenant ID.

Inventive Principle:
Principle #1Segmentation

2Reliability

If separate cloud tenant setups are required for each cloud network, then domain name uniqueness is maintained, but user authentication complexity and provisioning overhead increase

Engineering Contradiction:
Improvedomain name uniquenessVSAvoidauthentication process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements universality by enabling a single user identity to function across multiple cloud networks through the federation mechanism. The same user credentials can be used to access services in different cloud networks (first cloud network 106, second cloud network 108) by federating authentication requests to the enterprise identity provider, eliminating the need for separate cloud tenant setups while maintaining domain uniqueness through cloud tenant ID differentiation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If cloud-based identity providers require unique domain registration, then security validation is simplified, but cross-cloud service access and collaboration are hindered

Engineering Contradiction:
Improvesecurity validationVSAvoidcross-cloud service access
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces an intermediary mechanism (federation of authentication requests to enterprise identity provider 110) that mediates between cloud-based identity providers and enterprise identities. This intermediary approach maintains security validation by verifying domain ownership through cloud tenant IDs while enabling cross-cloud service access by allowing the same user identity to be authenticated across different cloud networks through the enterprise identity provider.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP4246358B1Registration of the same domain with different cloud services networks
Publication Date: 2024.10.23 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP4246358B1 patent drawingFigure 1
  • EP4246358B1 patent drawingFigure 2~3
  • EP4246358B1 patent drawingFigure 4

AI summary

Embodiments described herein are directed to the registration of the same domain with different cloud services networks. For example, systems and methods described herein enable registering a domain in a cloud services network wherein the same domain is also concurrently registered in another cloud services network. Systems and methods described herein further enable selecting one of a plurality of cloud-based identity providers to process a request to authenticate a user associated with a domain that is registered in more than one cloud services network and generating an authentication response in accordance with the selection. Systems and methods described herein also enable the federation of user authentication requests from different cloud services networks to the same enterprise identity provider.