Federated Identity Management for Seamless Cluster Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems for accessing multiple computer systems are not seamless, requiring users to re-enter credentials and manage different passwords, which complicates user and group membership changes across interconnected computer components.
Innovation Solution
A seamless single sign-on system where a primary computing component manages user credentials and issues security tokens, allowing access to associated computing components without requiring users to provide different passwords, with changes in user or group membership being transparent to the application and enabling access through a subset of nodes in the cluster.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If users access different separate computer systems separately administered, then each system can maintain its own security credentials and access control, but users must re-enter credentials and manage different passwords for each system
Solution Approach 1:
The patent merges multiple separate authentication systems into a unified federated identity system where a primary identity manager consolidates user credentials and authorization policies. This allows users to access multiple associated computing components through a single sign-on, eliminating the need to re-enter credentials while maintaining system-specific security requirements through centralized policy enforcement.
Solution Approach 2:
The primary identity manager serves as a universal authentication authority that handles credential verification and authorization for multiple different associated computing components. This multi-functional identity provider enables seamless cross-system access while each associated component retains its own application-specific security requirements and access control policies.
2Adaptability or versatility
If user or group membership changes are made in the primary identity manager, then centralized control and management are improved, but the changes must be propagated to all associated computing components
Solution Approach 1:
The system performs preliminary actions by establishing event subscription mechanisms in advance at each associated computing component. When membership changes occur at the primary identity manager, pre-configured event notifications are immediately triggered and propagated to subscribed components, eliminating the need for manual updates or batch synchronization processes.
Solution Approach 2:
The patent implements a feedback mechanism where associated computing components continuously monitor for membership change events from the primary identity manager. When changes occur, the system provides real-time feedback through event notifications to affected components, ensuring immediate awareness and automatic adaptation without manual intervention or delay.
3Productivity
If applications are distributed over a plurality of computing nodes, then system availability and scalability are improved, but users must be restricted to specific edge nodes for access
Solution Approach 1:
The primary identity manager acts as an intermediary that handles all authentication and authorization requests for distributed applications across multiple computing nodes. Instead of managing complex node-specific access restrictions, the identity manager centralizes policy enforcement and provides unified access control, simplifying the management of distributed system access while maintaining security requirements.
Data Source
AI summary
Methods, systems, and computer-readable media support provisioning a computer application that is executed on an associated computing component through a primary computing component. Even though different passwords may be associated with a user for the primary and the associated computing components, one aspect is seamless single sign-on to a computer cluster that provides the external computer application so that any user or group membership changes at the primary computing component is transparent to the associated computing component. Users may be restricted service for the application at the edge nodes of the cluster and are then able to access data in directories corresponding to the user's group as configured at the primary computing component. A batch process may be initiated to issue a security token to one more users, thus enabling the user to obtain a service ticket and consequently service for the application.


