Federated Access via Federation Registrar and Proxy Interfaces

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current federated systems in business communications are limited by the need for explicit, point-to-point configuration and lack transitivity, making it difficult for enterprises to manage complex relationships and transitions in customer service scenarios, such as outsourcing, where seamless data and communication access are crucial.

Innovation Solution

A federation system with a configuration server and database, along with a federation registrar and proxy interfaces, allows dynamic and flexible connections between enterprises, enabling transitivity and intelligent access control, allowing unknown third parties to join if they meet entrance requirements, with data and communication infrastructure managed for security and quality.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If explicit point-to-point federation configuration is used, then security and control are improved, but system complexity and difficulty of management increase

Engineering Contradiction:
Improvesecurity and controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a federation registrar as an intermediary component that manages federation relationships centrally. The registrar receives federation requests, validates them against stored federation data, and automatically establishes connections without requiring manual point-to-point configuration. This mediator approach maintains security through centralized validation while eliminating the complexity of manual pairwise setup between enterprises.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables automatic federation establishment through self-service mechanisms. When an enterprise requests federation, the registrar automatically processes the request, validates it against stored federation data, and establishes the connection without requiring manual intervention from administrators at both enterprises. This self-service approach reduces operational complexity while maintaining security through automated validation.

Inventive Principle:
Principle #25Self-service

2Manufacturing precision

If explicit point-to-point federation configuration is used, then access control precision is improved, but ease of operation and scalability worsen

Engineering Contradiction:
Improveaccess control precisionVSAvoidease of operation
Core Design Contradiction:
Manufacturing precisionVSEase of operation

Solution Approach 1:

The federation registrar acts as an intermediary that maintains precise access control rules centrally while automating their application. The registrar stores detailed federation data including authorized enterprises, contacts, and access permissions, then automatically applies these rules when processing federation requests. This eliminates the need for manual configuration at each endpoint while preserving precise access control through centralized rule management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The federation registrar provides universal access control functionality for all federation relationships within an enterprise. Instead of requiring separate access control configurations for each pairwise federation, the registrar implements a unified system that manages access permissions across multiple federations simultaneously. This multi-functional approach maintains precise control while significantly improving ease of operation through centralization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If transitive access permissions are enabled, then productivity and collaboration are improved, but security risks and control difficulty increase

Engineering Contradiction:
ImproveproductivityVSAvoidsecurity and control
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The federation registrar serves as a security intermediary that manages transitive permissions centrally. When an enterprise grants transitive access permissions, the registrar stores these permissions in the federation data and automatically validates them against the requesting enterprise before allowing access. This centralized mediation enables productivity through transitive permissions while maintaining security through automated validation at each access request.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where the registrar continuously validates access requests against stored federation data and transitive permission rules. Each access attempt triggers a validation process that checks whether the requested access aligns with established federation relationships and permission levels. This feedback loop enables productive transitive permissions while maintaining security through real-time validation and control.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8949470B2Federated access
Publication Date: 2015.02.03 GENESYS CLOUD SERVICES INC
  • US8949470B2 patent drawing
  • US8949470B2 patent drawing
  • US8949470B2 patent drawing

AI summary

A federation system operating in a first enterprise includes a configuration server and a database for creating and storing federation configuration data and a federation registrar having an interface for dealing with a second enterprise seeking to federate. In the system the second enterprise connects to the federation registrar, negotiation takes place concerning details of federation, agreement is reached, configuration is stored in the configuration database, and the second enterprise is then coupled to the first enterprise through a pair of federation proxy interfaces, one at the first enterprise and one at the second enterprise, the proxy interfaces configured by details of the federation.