Cross-Authoritative Identity Manager for Network Configuration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network infrastructure management systems face challenges in seamlessly integrating and managing multiple authoritative sources, leading to inconsistent identity management, delayed access to resources, and inefficiencies in user-based configurations, particularly as networks grow and change.
Innovation Solution
A system and method for cross-authoritative configuration management using an identity manager that provides a single point of control for configuring users across multiple authoritative sources, enabling real-time integration and seamless interoperability, allowing devices, software, and policies to be directly assigned based on user identity, regardless of the source, without the need for synchronization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If synchronization modules are used to integrate multiple authoritative sources, then integration capability is improved, but real-time access to resources is delayed until synchronization completes
Solution Approach 1:
The patent extracts the user identity information from multiple authoritative sources and stores it in a local database on the terminal device. This allows the terminal to access user information locally without waiting for synchronization between authoritative sources, thereby eliminating access delays while maintaining integration capability across multiple sources.
Solution Approach 2:
The system performs preliminary actions by pre-fetching and caching user identity information from authoritative sources into a local database before it is actually needed. This advance preparation ensures that when users need to access resources, their identity information is already available locally, eliminating wait time caused by synchronization processes.
2Device complexity
If a single authoritative source is used for user management, then system simplicity is improved, but flexibility to accommodate different departmental requirements deteriorates
Solution Approach 1:
The patent segments the user management system into multiple independent authoritative sources, each capable of managing user information for specific departments or organizational units. This segmentation allows different departments to maintain their own user management requirements while the terminal device integrates information from all sources, thereby maintaining system simplicity at the access point while providing flexibility across the entire system.
Solution Approach 2:
The terminal device is designed with universal capability to access and integrate user information from multiple different authoritative sources. It can query and process user data from various sources based on different criteria (department, organization, etc.), providing a unified access interface that maintains simplicity for users while supporting diverse departmental requirements through multi-source integration.
3Speed
If user identity information is stored locally on terminal devices, then access speed is improved, but data consistency across multiple authoritative sources deteriorates
Solution Approach 1:
The system implements dynamic data synchronization where the local database on terminal devices is continuously updated based on changes detected in authoritative sources. When a user's identity information changes in any authoritative source, the system dynamically updates the local cache, ensuring data consistency is maintained while preserving fast local access. This dynamic approach allows the system to adapt between speed and consistency based on real-time needs.
Data Source
AI summary
A system and method for cross-authoritative, user-based network configuration management is provided. Users log-in to a network using any device coupled to the network, and an identity manager may provide the user with a custom computing environment by verifying the user's identity and identifying content, assignments, and other configuration information associated with the user. For instance, the identity manager may retrieve a unique identifier assigned to the user, query one or more authoritative source domains based on the unique identifier, and deliver a computing environment assigned to the user. By seamlessly integrating multiple authoritative sources, administrators can make assignments to users across multiple authoritative source domains, and queries to the sources will always be up-to-date without having to perform synchronization processes.


