Federated Data Distribution Networks Identity Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current pub-sub models require a single administrative domain for identity management and authentication, necessitating a global repository of feeds across all distribution networks and complicating credential management when providers and subscribers are in different domains.
Innovation Solution
A system that federates trusted data distribution networks, allowing identity and authentication management within each network, using a policy engine to combine access policies and enabling data feeds to be created and managed independently across networks, eliminating the need for a global repository and single administrative domain.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a single administrative domain is used for identity management and authentication, then credential management is simplified, but the system requires a global repository of feeds across all distribution networks and cannot support different access policies for different networks
Solution Approach 1:
The system divides the centralized administrative domain into multiple independent administrative domains, each capable of managing its own credentials and access policies. Each data distribution network operates as a separate domain with its own identity management, eliminating the need for a global repository while allowing customized access policies per network.
Solution Approach 2:
The patent introduces a federation mechanism as an intermediary layer between administrative domains. This federation enables cross-domain data distribution while maintaining independent credential management in each domain, acting as a mediator that translates and validates credentials across different administrative boundaries without requiring centralized control.
2Reliability
If a global repository of feeds is maintained across all distribution networks, then data distribution is coordinated, but network connectivity must be established to each individual subscriber across domains
Solution Approach 1:
The global repository is segmented into local repositories within each administrative domain. Each domain maintains its own feed metadata and subscriber information locally, eliminating the need for a centralized global repository. Data distribution is coordinated through federation protocols that enable domains to query and synchronize with each other as needed, reducing network connectivity requirements.
Solution Approach 2:
The system transitions from a flat, centralized repository architecture to a hierarchical, distributed architecture across multiple administrative domains. This dimensional change allows local autonomy in each domain while maintaining global coordination through the federation layer, reducing the need for direct connectivity to every subscriber.
3Measurement precision
If distinct identities are maintained for each data distribution system, then authentication is precise, but credential management becomes complicated when providers and subscribers are in different domains
Solution Approach 1:
The patent implements a universal credential format and federation protocol that works across all administrative domains. Each domain maintains its own authentication precision with distinct identities, but the federation mechanism provides a universal interface for credential validation and translation, enabling cross-domain authentication without requiring complex manual credential management.
4Adaptability or versatility
If a federated system with multiple administrative domains is implemented, then access policy flexibility and independent credential management are enabled, but coordination between domains becomes more complex
Solution Approach 1:
The federation mechanism serves as an intermediary layer that simplifies inter-domain coordination. It provides standardized protocols for credential validation, policy translation, and data routing between domains, reducing the complexity of direct peer-to-peer coordination while maintaining the flexibility of independent domain policies.
Data Source
AI summary
Federation of trusted data distribution systems is accomplished by treating an entire data distribution network as either a publisher or subscriber to a feed in another data distribution network. A first data feed is created in a first data feed management subsystem associated with a first data distribution network. A second data feed related to the first data feed is created in a second data feed management subsystem associated with a second data distribution network. A first data access policy is associated with the second data feed and a publisher for the second data feed is created in the second data distribution network. The identity and authentication of a second subscriber to the second data feed in the second data distribution network is managed by referencing the first data access policy.


