Discovery Application Mapping Authentication System Relationships

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems fail to effectively map relationships between authentication systems and other computing resources within and outside a remote computing system, as attributes alone do not indicate usage or interconnections, leading to incomplete visualization and management of resource access control.

Innovation Solution

A discovery application uses a unique resource identifier to determine and map authentication system relationships by parsing attributes of computing resources, generating a mapping between the authentication system and resources that utilize it, allowing for visual representation and interactive management of access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If attributes of computing resources are obtained from the remote computing system, then information about the authentication system is gathered, but the relationships between the authentication system and other computing resources cannot be determined

Engineering Contradiction:
Improveinformation about authentication system usageVSAvoiddifficulty of determining relationships
Core Design Contradiction:
Loss of informationVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces a discovery application as an intermediary component that mediates between the remote computing system and the user. This discovery application actively queries the API to obtain attributes, parses them to extract relationship information, and presents the findings in a visual map format, thereby bridging the gap between available attributes and meaningful relationship detection

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a visual map that is a graphical copy or representation of the actual authentication system relationships. This visual map copies the structural relationships between the authentication system and computing resources, allowing users to interact with and analyze relationships without directly accessing the complex underlying system attributes

Inventive Principle:
Principle #26Copying

2Ease of operation

If a visual map of computing resources is generated, then relationships can be visualized, but the complexity of parsing and matching unique resource identifiers increases

Engineering Contradiction:
Improveease of visualizing relationshipsVSAvoidcomplexity of discovery application
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The discovery application is segmented into distinct functional modules: an API interaction module that queries attributes, a parsing module that extracts unique resource identifiers, a matching module that compares identifiers, and a visualization module that generates the visual map. This segmentation reduces overall complexity by localizing specific tasks to dedicated components

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The discovery application performs self-service by automatically querying the API, parsing attributes, identifying unique resource identifiers, matching them between the authentication system and computing resources, and generating the visual map without requiring manual intervention. This automation reduces operational complexity despite the intricate processing required

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3987749B1Discovery and mapping of a cloud-based authentication, authorization, and user management service
Publication Date: 2023.01.25 SERVICENOW INC
  • EP3987749B1 patent drawingFigure 1
  • EP3987749B1 patent drawingFigure 2
  • EP3987749B1 patent drawingFigure 3

AI summary

A computing system includes persistent storage and a discovery application configured to perform operations including obtaining, from a remote computing system, first attributes of a first computing resource, which indicate a first unique resource identifier associated with an authentication system provided by the remote computing system and utilized by the first computing resource. The operations also include obtaining, from the remote computing system, second attributes of the authentication system, which indicate a second unique resource identifier used by the authentication system. The operations additionally include determining that the first unique resource identifier matches the second unique resource identifier and, based on this determination, generating a mapping between the first computing resource and the authentication system to indicate that access to the first computing resource is controlled by the authentication system. The operations further include storing, in the persistent storage, the mapping as one or more configuration items.