Federated Identity Management for Seamless Cluster Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for accessing multiple computer systems are not seamless, requiring users to re-enter credentials and manage different passwords, which complicates user and group membership changes across interconnected computer components.

Innovation Solution

A seamless single sign-on system where a primary computing component manages user credentials and issues security tokens, allowing access to associated computing components without requiring users to provide different passwords, with changes in user or group membership being transparent to the application and enabling access through a subset of nodes in the cluster.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users access different separate computer systems separately administered, then each system can maintain its own security credentials and access control, but users must re-enter credentials and manage different passwords for each system

Engineering Contradiction:
Improvesystem securityVSAvoiduser access convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges multiple separate authentication systems into a unified federated identity system where a primary identity manager consolidates user credentials and authorization policies. This allows users to access multiple associated computing components through a single sign-on, eliminating the need to re-enter credentials while maintaining system-specific security requirements through centralized policy enforcement.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The primary identity manager serves as a universal authentication authority that handles credential verification and authorization for multiple different associated computing components. This multi-functional identity provider enables seamless cross-system access while each associated component retains its own application-specific security requirements and access control policies.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If user or group membership changes are made in the primary identity manager, then centralized control and management are improved, but the changes must be propagated to all associated computing components

Engineering Contradiction:
Improvemembership management flexibilityVSAvoidpropagation delay
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by establishing event subscription mechanisms in advance at each associated computing component. When membership changes occur at the primary identity manager, pre-configured event notifications are immediately triggered and propagated to subscribed components, eliminating the need for manual updates or batch synchronization processes.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements a feedback mechanism where associated computing components continuously monitor for membership change events from the primary identity manager. When changes occur, the system provides real-time feedback through event notifications to affected components, ensuring immediate awareness and automatic adaptation without manual intervention or delay.

Inventive Principle:
Principle #23Feedback

3Productivity

If applications are distributed over a plurality of computing nodes, then system availability and scalability are improved, but users must be restricted to specific edge nodes for access

Engineering Contradiction:
Improvesystem scalabilityVSAvoidaccess restriction management
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The primary identity manager acts as an intermediary that handles all authentication and authorization requests for distributed applications across multiple computing nodes. Instead of managing complex node-specific access restrictions, the identity manager centralizes policy enforcement and provides unified access control, simplifying the management of distributed system access while maintaining security requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10122702B2Single sign-on for interconnected computer systems
Publication Date: 2018.11.06 BANK OF AMERICA CORP
  • US10122702B2 patent drawing
  • US10122702B2 patent drawing
  • US10122702B2 patent drawing

AI summary

Methods, systems, and computer-readable media support provisioning a computer application that is executed on an associated computing component through a primary computing component. Even though different passwords may be associated with a user for the primary and the associated computing components, one aspect is seamless single sign-on to a computer cluster that provides the external computer application so that any user or group membership changes at the primary computing component is transparent to the associated computing component. Users may be restricted service for the application at the edge nodes of the cluster and are then able to access data in directories corresponding to the user's group as configured at the primary computing component. A batch process may be initiated to issue a security token to one more users, thus enabling the user to obtain a service ticket and consequently service for the application.