Containerized Identity Management for Cloud Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for managing user authentication and assets across multiple operating systems and cloud services are complex, leading to inefficiencies and vulnerabilities, particularly with virtual machine environments where patching can cause application instability and require frequent interruptions.

Innovation Solution

A platform-independent container technology is used to create a Web-service interface for identity management, allowing seamless authentication to cloud services using the same credentials as on-premise applications, with REST APIs enabling communication between on-premise and cloud environments, eliminating the need for complex installations and third-party systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If virtual machine operating systems are used to support multiple operating systems on the same machine, then the ability to run multiple OS is improved, but the system size and complexity increase

Engineering Contradiction:
Improveability to run multiple operating systemsVSAvoidsystem size and complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent uses container technology to create lightweight copies of operating system environments rather than full virtual machine instances. Each container is a simplified copy that shares the host OS kernel, providing multiple isolated environments without the overhead of complete OS copies. This resolves the contradiction by maintaining multi-OS capability while dramatically reducing system size and complexity.

Inventive Principle:
Principle #26Copying

2Reliability

If operating system patches are applied to virtual machines, then security and stability are improved, but application stability deteriorates due to interruptions and reboots

Engineering Contradiction:
Improvesecurity and stabilityVSAvoidapplication stability
Core Design Contradiction:
ReliabilityVSStability of the object's composition

Solution Approach 1:

The patent segments the operating system into a host OS and multiple containerized application environments. The host OS receives patches independently while containers remain unaffected during patching. This segmentation allows security updates to be applied to the host without interrupting or affecting the stability of running applications in containers, resolving the contradiction between maintaining security through patching and preserving application stability.

Inventive Principle:
Principle #1Segmentation

3Reliability

If separate management frameworks are implemented for each application and asset, then security provisioning is improved, but operational complexity increases

Engineering Contradiction:
Improvesecurity provisioningVSAvoidoperational complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements a universal container management system that can provision and manage multiple containerized applications and assets through a single framework. The container platform provides standardized security, isolation, and resource management that works across all applications, eliminating the need for separate management frameworks for each application while maintaining strong security provisioning.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Adaptability or versatility

If virtual machine environments are used, then multiple operating systems can coexist, but patching causes application downtime and interruptions

Engineering Contradiction:
Improvecoexistence of multiple operating systemsVSAvoidapplication downtime
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent introduces container technology as an intermediary layer between the host operating system and applications. This intermediary allows the host OS to be patched without affecting applications running in containers, as containers share the kernel but maintain isolated process spaces. The intermediary layer absorbs the impact of OS updates, preventing application downtime while maintaining the ability to run multiple OS environments through containerization.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11700260B2Method and apparatus for native authentication to cloud services with identity management of on-premise applications from the cloud
Publication Date: 2023.07.11 AVATIER IP LLC
  • US11700260B2 patent drawing
  • US11700260B2 patent drawing
  • US11700260B2 patent drawing

AI summary

A technique is provided that enables native authentication to cloud services by employing identity management of on-premise applications from the cloud. More specifically, a Web-service interface built on an innovative orchestration of platform-independent container technology is created. An identity management application is made available inside a container and which therefore can execute in any cloud-service provider. Specifically, this application can communicate back into a business' on-premise applications, using the Representation State Transfer (REST) application programming interface architecture. The container is published to the cloud for users to download. Thus, for example, by way of this technique, a user can log onto any cloud application with using the same logon information the user uses on-premise.