Containerized Identity Management for Cloud Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems for managing user authentication and assets across multiple operating systems and cloud services are complex, leading to inefficiencies and vulnerabilities, particularly with virtual machine environments where patching can cause application instability and require frequent interruptions.
Innovation Solution
A platform-independent container technology is used to create a Web-service interface for identity management, allowing seamless authentication to cloud services using the same credentials as on-premise applications, with REST APIs enabling communication between on-premise and cloud environments, eliminating the need for complex installations and third-party systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If virtual machine operating systems are used to support multiple operating systems on the same machine, then the ability to run multiple OS is improved, but the system size and complexity increase
Solution Approach 1:
The patent uses container technology to create lightweight copies of operating system environments rather than full virtual machine instances. Each container is a simplified copy that shares the host OS kernel, providing multiple isolated environments without the overhead of complete OS copies. This resolves the contradiction by maintaining multi-OS capability while dramatically reducing system size and complexity.
2Reliability
If operating system patches are applied to virtual machines, then security and stability are improved, but application stability deteriorates due to interruptions and reboots
Solution Approach 1:
The patent segments the operating system into a host OS and multiple containerized application environments. The host OS receives patches independently while containers remain unaffected during patching. This segmentation allows security updates to be applied to the host without interrupting or affecting the stability of running applications in containers, resolving the contradiction between maintaining security through patching and preserving application stability.
3Reliability
If separate management frameworks are implemented for each application and asset, then security provisioning is improved, but operational complexity increases
Solution Approach 1:
The patent implements a universal container management system that can provision and manage multiple containerized applications and assets through a single framework. The container platform provides standardized security, isolation, and resource management that works across all applications, eliminating the need for separate management frameworks for each application while maintaining strong security provisioning.
4Adaptability or versatility
If virtual machine environments are used, then multiple operating systems can coexist, but patching causes application downtime and interruptions
Solution Approach 1:
The patent introduces container technology as an intermediary layer between the host operating system and applications. This intermediary allows the host OS to be patched without affecting applications running in containers, as containers share the kernel but maintain isolated process spaces. The intermediary layer absorbs the impact of OS updates, preventing application downtime while maintaining the ability to run multiple OS environments through containerization.
Data Source
AI summary
A technique is provided that enables native authentication to cloud services by employing identity management of on-premise applications from the cloud. More specifically, a Web-service interface built on an innovative orchestration of platform-independent container technology is created. An identity management application is made available inside a container and which therefore can execute in any cloud-service provider. Specifically, this application can communicate back into a business' on-premise applications, using the Representation State Transfer (REST) application programming interface architecture. The container is published to the cloud for users to download. Thus, for example, by way of this technique, a user can log onto any cloud application with using the same logon information the user uses on-premise.


