Declarative Metadata for Third-Party Identity Provider Integration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current identity management systems face challenges in providing secure access to cloud-based applications across diverse devices and user types, with inconsistencies in security between cloud and on-premise environments leading to potential security breaches, and lack of easy integration with new third-party identity providers.
Innovation Solution
A multi-tenant identity cloud service using a declarative framework that allows metadata definition for third-party identity providers, enabling secure access through microservices architecture, unified identity management, and seamless integration with existing systems, without requiring software coding for new provider additions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional identity management systems are used, then security can be maintained, but integration with new third-party identity providers requires software coding and complex configuration
Solution Approach 1:
The patent uses declarative metadata to define third-party identity providers, creating a standardized template that copies the same integration pattern for each provider. This eliminates the need for custom software coding for each integration, as the system repeatedly applies the same metadata structure to different identity providers through standardized processes.
Solution Approach 2:
The system changes integration from a complex software development process to a simple parameter configuration process. By defining identity providers through declarative metadata with parameters like provider name, authorization endpoint, and token endpoint, the system transforms integration into a parameter-setting task rather than a code-writing task.
2Ease of operation
If cloud-based applications are made accessible from diverse devices and user types, then usability is improved, but security risks increase
Solution Approach 1:
The patent segments the identity management process into distinct standardized components: authentication, authorization, and token management. Each component handles specific security aspects independently, allowing the system to maintain security while supporting diverse access scenarios through modular, standardized processing.
Solution Approach 2:
The system creates a universal identity management framework that handles multiple user types (employees, partners, customers) and diverse devices through a single standardized interface. The declarative metadata approach and standardized token processing enable one system to securely manage authentication across all access scenarios without requiring separate security implementations.
Data Source
AI summary
Embodiments provide login functionality to a user using a third party identity provider for a multi-tenant identity cloud service. Embodiments receive declarative metadata that includes an identity of a token endpoint corresponding to the third party identity provider and corresponding parameter values. Embodiments store the declarative metadata in a database and receive a request for a login using the third party identity provider. Embodiments retrieve the metadata and build an authorization request and send the authorization request to the third party identity provider, and in response receive an authorization code. Embodiments retrieve the metadata and build a token request using the authorization code and send the token request to the third party identity provider, and in response receive an access token.


