External Identity Provider Embedding for Unified Cloud IAM Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The integration of separate identity and access management (IAM) systems for cloud services, such as Oracle Cloud Infrastructure (OCI) and Identity Cloud Services (IDCS), is cumbersome and resource-intensive, leading to poor user experience due to different authentication and authorization frameworks and the need for complex federation processes.

Innovation Solution

An integrated IAM system is generated by creating a domain in a customer tenancy associated with OCI and embedding the IDCS identity provider within this domain, allowing seamless access to resources without requiring federation between the systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If identity federation is implemented between separate IAM systems, then user access to multiple services is enabled, but the process becomes complex and time-consuming

Engineering Contradiction:
Improveuser access to multiple servicesVSAvoidfederation process complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent combines multiple separate IAM systems into a single unified IAM system that can manage users across different cloud services (IaaS, PaaS, SaaS) simultaneously. This eliminates the need for complex federation processes between separate systems while maintaining the ability to provide user access to multiple services through a single authentication mechanism.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If separate IAM systems are used for different cloud services, then service-specific security control is maintained, but user experience deteriorates due to multiple credentials

Engineering Contradiction:
Improveservice-specific security controlVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The unified IAM system performs multiple functions simultaneously: it provides service-specific security control for different cloud services while also serving as a universal authentication system that manages user credentials centrally. This allows users to access multiple services with a single set of credentials while maintaining the security requirements of each specific service.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If identity federation is implemented, then access to resources is enabled, but implementation time and resources increase

Engineering Contradiction:
Improveaccess to resourcesVSAvoidimplementation time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent establishes a unified IAM system in advance that is pre-configured to manage access across multiple cloud services. This preliminary action eliminates the need for time-consuming federation setup later, as the system is already designed to provide resource access functionality across IaaS, PaaS, and SaaS services from the outset.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP4409843B1External identity provider as a domain resource
Publication Date: 2025.09.10 ORACLE INT CORP
  • EP4409843B1 patent drawingFigure 1
  • EP4409843B1 patent drawingFigure 2
  • EP4409843B1 patent drawingFigure 3

AI summary

Described herein is a framework for generating an integrated identity and access management (IAM) system from a first IAM system and a second IAM system that is different than the first IAM system. The integrated IAM system is generated by: (i) creating a domain in a customer tenancy associated with the first IAM system, and (ii) embedding an identity provider of the second IAM system within the domain. The integrated IAM system receives a request from a user to perform an operation with respect to resource associated with the second IAM system. Upon the user being successfully authenticated by the integrated IAM system, the request is executed.