Declarative Policy Management in Multi-Tenant Cloud IAM
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current identity and access management systems in cloud environments face challenges in providing secure and unified access across diverse devices and user types, including unauthorized access, account hijacking, and inconsistent security between on-premise and cloud environments.
Innovation Solution
A declarative policy management system within a multi-tenant cloud-based identity and access management (IAM) system that configures and enforces policies using a policy engine, supporting microservices architecture for secure access and identity management across hybrid cloud deployments, ensuring consistent security across all access points.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional identity management systems are used in cloud environments, then access control can be implemented, but security consistency across diverse devices and user types deteriorates
Solution Approach 1:
The patent implements a universal identity store that centralizes identity information for all user types (employees, partners, customers) and all device types (desktop, mobile, tablet). This single identity store provides consistent authentication and authorization across diverse access points, resolving the contradiction between security consistency and adaptability to diverse devices and users.
Solution Approach 2:
The system segments identity management into distinct functional components: identity store, authentication service, authorization service, and policy enforcement points. Each component handles specific aspects of access control, allowing the system to maintain security consistency while adapting to various device types and user scenarios through specialized handling in different segments.
2Reliability
If separate identity management systems are used for on-premise and cloud environments, then each environment can be secured independently, but unified security policy enforcement deteriorates
Solution Approach 1:
The patent merges on-premise and cloud identity management into a unified hybrid identity store that maintains separate identity data for different environments while enforcing consistent security policies across both. The centralized policy management layer ensures that security policies are uniformly applied whether access originates from on-premise systems or cloud applications, resolving the contradiction between environmental security and policy consistency.
3Reliability
If complex security policies are implemented to address all access scenarios, then security coverage is improved, but system complexity and difficulty of management increases
Solution Approach 1:
The patent introduces policy decision points as intermediary components that mediate between security policies and access requests. These PDPs evaluate authentication results, user attributes, and contextual information to make authorization decisions based on predefined policies. This intermediary layer simplifies policy management by providing a standardized interface for policy evaluation across diverse access scenarios, reducing the complexity of implementing comprehensive security coverage.
4Reliability
If centralized identity management is implemented, then security control is improved, but scalability to multiple tenants and devices deteriorates
Solution Approach 1:
The patent adds a multi-tenant dimension to the centralized identity management system by implementing tenant-aware identity stores and policy evaluation contexts. The system maintains centralized security control through unified authentication and authorization services while scaling to multiple tenants by isolating identity data and policy enforcement per tenant. This dimensional extension allows the system to provide both centralized control and multi-tenant scalability simultaneously.
Data Source
AI summary
One embodiment provides declarative policy management in a multi-tenant cloud-based identity and access management (“IAM”) system. The embodiment receives at least one Application Programming Interface (“API”) request by a policy engine of the multi-tenant cloud-based IAM system from a tenant of the multi-tenant cloud-based IAM system. The embodiment configures a declarative policy for the tenant of the multi-tenant cloud-based IAM system based on the at least one API request. The embodiment then enforces the declarative policy in an IAM service performed for the tenant of the multi-tenant cloud-based IAM system.


