Directory Enabler for Dynamic Identity Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing identity management systems face challenges in dynamically expanding to accommodate new users and members, as they require pre-established trust relationships and networks, limiting their ability to handle new users and expand dynamically.

Innovation Solution

The system dynamically provides identity management services by receiving requests related to unknown principals, locating services based on identity attributes, and obtaining or affecting identity management results, using a directory enabler to select services known to the principal and provide necessary identity management or other services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If trust relationships are pre-established in a federation, then security and authentication are ensured, but the system cannot dynamically expand to accommodate new users and members

Engineering Contradiction:
ImprovesecurityVSAvoiddynamic expansion capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a service enabler as an intermediary component that mediates between the requesting system and the target service. This enabler dynamically discovers and locates services without requiring pre-established trust relationships, thus maintaining security while enabling dynamic expansion. The service enabler acts as a broker that facilitates interactions between unknown principals and services.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system transitions from static pre-established trust relationships to dynamic service discovery and location. The service enabler continuously queries and updates information about available services and their accessibility to different principals, allowing the system to adapt to new users and members in real-time without requiring beforehand configuration.

Inventive Principle:
Principle #15Dynamics

2Ease of operation

If a single sign-on server is used for authentication, then user access is simplified, but the system requires a well-established federation with perfect knowledge of all members

Engineering Contradiction:
Improveuser access simplicityVSAvoidfederation establishment complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent extracts the service location and discovery functionality from the traditional single sign-on server model. Instead of requiring a centralized server that knows all members of a federation, the service enabler independently queries and locates services dynamically. This removes the requirement for a pre-established federation while maintaining simplified user access.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The service enabler performs self-service by autonomously discovering and locating services without requiring manual configuration or pre-established relationships. It independently queries the target system to determine service accessibility, eliminating the need for complex federation establishment while maintaining ease of operation.

Inventive Principle:
Principle #25Self-service

3Reliability

If trust networks are well-established beforehand, then authentication and authorization are reliable, but the network cannot discover new members dynamically

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidtime for dynamic member discovery
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The service enabler performs preliminary actions by continuously gathering and caching information about service accessibility and principal knowledge. This preliminary discovery work is done in advance of actual authentication requests, so when new members need to be accessed, the system can quickly determine service availability without time-consuming real-time discovery.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where the service enabler continuously monitors and updates information about which principals are known to which services. This feedback loop allows the system to maintain reliable authentication by keeping current service accessibility information while enabling rapid adaptation to new members through continuous discovery updates.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9674180B2Using identity/resource profile and directory enablers to support identity management
Publication Date: 2017.06.06 ORACLE INT CORP
  • US9674180B2 patent drawing
  • US9674180B2 patent drawing
  • US9674180B2 patent drawing

AI summary

Embodiments of the present invention provide methods, system and machine-readable media for dynamically providing identity management or other services. According to one embodiment, dynamically providing services can comprise receiving a request related to an unknown principal. A service to which the principal is known can be selected. Once a service to which the principal is known has been located, an identity management result can be obtained from the selected service. The method can further comprise determining based on the identity management result whether the principal is authorized to access a requested resource. In response to determining the principal is authorized, the requested resource can be accessed.