Federated Data Distribution Networks Identity Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current pub-sub models require a single administrative domain for identity management and authentication, necessitating a global repository of feeds across all distribution networks and complicating credential management when providers and subscribers are in different domains.

Innovation Solution

A system that federates trusted data distribution networks, allowing identity and authentication management within each network, using a policy engine to combine access policies and enabling data feeds to be created and managed independently across networks, eliminating the need for a global repository and single administrative domain.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a single administrative domain is used for identity management and authentication, then credential management is simplified, but the system requires a global repository of feeds across all distribution networks and cannot support different access policies for different networks

Engineering Contradiction:
Improvecredential managementVSAvoidaccess policy flexibility
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The system divides the centralized administrative domain into multiple independent administrative domains, each capable of managing its own credentials and access policies. Each data distribution network operates as a separate domain with its own identity management, eliminating the need for a global repository while allowing customized access policies per network.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a federation mechanism as an intermediary layer between administrative domains. This federation enables cross-domain data distribution while maintaining independent credential management in each domain, acting as a mediator that translates and validates credentials across different administrative boundaries without requiring centralized control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a global repository of feeds is maintained across all distribution networks, then data distribution is coordinated, but network connectivity must be established to each individual subscriber across domains

Engineering Contradiction:
Improvedata distribution coordinationVSAvoidnetwork connectivity requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The global repository is segmented into local repositories within each administrative domain. Each domain maintains its own feed metadata and subscriber information locally, eliminating the need for a centralized global repository. Data distribution is coordinated through federation protocols that enable domains to query and synchronize with each other as needed, reducing network connectivity requirements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system transitions from a flat, centralized repository architecture to a hierarchical, distributed architecture across multiple administrative domains. This dimensional change allows local autonomy in each domain while maintaining global coordination through the federation layer, reducing the need for direct connectivity to every subscriber.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Measurement precision

If distinct identities are maintained for each data distribution system, then authentication is precise, but credential management becomes complicated when providers and subscribers are in different domains

Engineering Contradiction:
Improveauthentication precisionVSAvoidcredential management complexity
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The patent implements a universal credential format and federation protocol that works across all administrative domains. Each domain maintains its own authentication precision with distinct identities, but the federation mechanism provides a universal interface for credential validation and translation, enabling cross-domain authentication without requiring complex manual credential management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Adaptability or versatility

If a federated system with multiple administrative domains is implemented, then access policy flexibility and independent credential management are enabled, but coordination between domains becomes more complex

Engineering Contradiction:
Improveaccess policy flexibilityVSAvoidinter-domain coordination
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The federation mechanism serves as an intermediary layer that simplifies inter-domain coordination. It provides standardized protocols for credential validation, policy translation, and data routing between domains, reducing the complexity of direct peer-to-peer coordination while maintaining the flexibility of independent domain policies.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11595476B2Systems and methods for data distribution using a publication subscriber model with a federation of trusted data distribution networks
Publication Date: 2023.02.28 AT&T INTELLECTUAL PROPERTY I L P
  • US11595476B2 patent drawing
  • US11595476B2 patent drawing
  • US11595476B2 patent drawing

AI summary

Federation of trusted data distribution systems is accomplished by treating an entire data distribution network as either a publisher or subscriber to a feed in another data distribution network. A first data feed is created in a first data feed management subsystem associated with a first data distribution network. A second data feed related to the first data feed is created in a second data feed management subsystem associated with a second data distribution network. A first data access policy is associated with the second data feed and a publisher for the second data feed is created in the second data distribution network. The identity and authentication of a second subscriber to the second data feed in the second data distribution network is managed by referencing the first data access policy.