Declarative Metadata for Third-Party Identity Provider Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current identity management systems face challenges in providing secure access to cloud-based applications across diverse devices and user types, with inconsistencies in security between cloud and on-premise environments leading to potential security breaches, and lack of easy integration with new third-party identity providers.

Innovation Solution

A multi-tenant identity cloud service using a declarative framework that allows metadata definition for third-party identity providers, enabling secure access through microservices architecture, unified identity management, and seamless integration with existing systems, without requiring software coding for new provider additions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional identity management systems are used, then security can be maintained, but integration with new third-party identity providers requires software coding and complex configuration

Engineering Contradiction:
Improveintegration capabilityVSAvoidintegration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent uses declarative metadata to define third-party identity providers, creating a standardized template that copies the same integration pattern for each provider. This eliminates the need for custom software coding for each integration, as the system repeatedly applies the same metadata structure to different identity providers through standardized processes.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system changes integration from a complex software development process to a simple parameter configuration process. By defining identity providers through declarative metadata with parameters like provider name, authorization endpoint, and token endpoint, the system transforms integration into a parameter-setting task rather than a code-writing task.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If cloud-based applications are made accessible from diverse devices and user types, then usability is improved, but security risks increase

Engineering Contradiction:
ImproveaccessibilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the identity management process into distinct standardized components: authentication, authorization, and token management. Each component handles specific security aspects independently, allowing the system to maintain security while supporting diverse access scenarios through modular, standardized processing.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system creates a universal identity management framework that handles multiple user types (employees, partners, customers) and diverse devices through a single standardized interface. The declarative metadata approach and standardized token processing enable one system to securely manage authentication across all access scenarios without requiring separate security implementations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11012444B2Declarative third party identity provider integration for a multi-tenant identity cloud service
Publication Date: 2021.05.18 ORACLE INT CORP
  • US11012444B2 patent drawing
  • US11012444B2 patent drawing
  • US11012444B2 patent drawing

AI summary

Embodiments provide login functionality to a user using a third party identity provider for a multi-tenant identity cloud service. Embodiments receive declarative metadata that includes an identity of a token endpoint corresponding to the third party identity provider and corresponding parameter values. Embodiments store the declarative metadata in a database and receive a request for a login using the third party identity provider. Embodiments retrieve the metadata and build an authorization request and send the authorization request to the third party identity provider, and in response receive an authorization code. Embodiments retrieve the metadata and build a token request using the authorization code and send the token request to the third party identity provider, and in response receive an access token.