Cross-Authoritative Identity Manager for Network Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network infrastructure management systems face challenges in seamlessly integrating and managing multiple authoritative sources, leading to inconsistent identity management, delayed access to resources, and inefficiencies in user-based configurations, particularly as networks grow and change.

Innovation Solution

A system and method for cross-authoritative configuration management using an identity manager that provides a single point of control for configuring users across multiple authoritative sources, enabling real-time integration and seamless interoperability, allowing devices, software, and policies to be directly assigned based on user identity, regardless of the source, without the need for synchronization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If synchronization modules are used to integrate multiple authoritative sources, then integration capability is improved, but real-time access to resources is delayed until synchronization completes

Engineering Contradiction:
Improveintegration capabilityVSAvoidaccess delay
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent extracts the user identity information from multiple authoritative sources and stores it in a local database on the terminal device. This allows the terminal to access user information locally without waiting for synchronization between authoritative sources, thereby eliminating access delays while maintaining integration capability across multiple sources.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system performs preliminary actions by pre-fetching and caching user identity information from authoritative sources into a local database before it is actually needed. This advance preparation ensures that when users need to access resources, their identity information is already available locally, eliminating wait time caused by synchronization processes.

Inventive Principle:
Principle #10Preliminary action

2Device complexity

If a single authoritative source is used for user management, then system simplicity is improved, but flexibility to accommodate different departmental requirements deteriorates

Engineering Contradiction:
Improvesystem simplicityVSAvoidflexibility
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent segments the user management system into multiple independent authoritative sources, each capable of managing user information for specific departments or organizational units. This segmentation allows different departments to maintain their own user management requirements while the terminal device integrates information from all sources, thereby maintaining system simplicity at the access point while providing flexibility across the entire system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The terminal device is designed with universal capability to access and integrate user information from multiple different authoritative sources. It can query and process user data from various sources based on different criteria (department, organization, etc.), providing a unified access interface that maintains simplicity for users while supporting diverse departmental requirements through multi-source integration.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Speed

If user identity information is stored locally on terminal devices, then access speed is improved, but data consistency across multiple authoritative sources deteriorates

Engineering Contradiction:
Improveaccess speedVSAvoiddata consistency
Core Design Contradiction:
SpeedVSStability of the object's composition

Solution Approach 1:

The system implements dynamic data synchronization where the local database on terminal devices is continuously updated based on changes detected in authoritative sources. When a user's identity information changes in any authoritative source, the system dynamically updates the local cache, ensuring data consistency is maintained while preserving fast local access. This dynamic approach allows the system to adapt between speed and consistency based on real-time needs.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS7774472B2System and method for cross-authoritative configuration management
Publication Date: 2010.08.10 EMC IP HLDG CO LLC
  • US7774472B2 patent drawing
  • US7774472B2 patent drawing
  • US7774472B2 patent drawing

AI summary

A system and method for cross-authoritative, user-based network configuration management is provided. Users log-in to a network using any device coupled to the network, and an identity manager may provide the user with a custom computing environment by verifying the user's identity and identifying content, assignments, and other configuration information associated with the user. For instance, the identity manager may retrieve a unique identifier assigned to the user, query one or more authoritative source domains based on the unique identifier, and deliver a computing environment assigned to the user. By seamlessly integrating multiple authoritative sources, administrators can make assignments to users across multiple authoritative source domains, and queries to the sources will always be up-to-date without having to perform synchronization processes.