Federated Login Control for Multi-Cluster Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems require individual log-ins into multiple clusters or products, leading to burdensome configuration of user authorization settings, especially when managing clusters or products from a centralized management system.

Innovation Solution

A centralized management system with a federated login and authorization system that supports SAML-based federated login and RBAC, allowing users to manage multiple clusters or products without individual log-ins, through a centralized management console that configures authority based on object types, cluster types, and data sources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If individual log-ins are required for each cluster or product, then user authorization can be precisely controlled per cluster, but the complexity of configuration and operation increases significantly

Engineering Contradiction:
Improveuser authorization controlVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple individual cluster logins into a single federated login system. The centralized management console aggregates authentication and authorization functions across multiple clusters, allowing users to access any cluster through one unified login session. This combining of separate authentication systems into a single federated system reduces configuration complexity while maintaining precise authorization control through centralized user profile management.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The federated login system creates a universal authentication mechanism that works across all clusters and products. A single user account and credential set can authenticate to multiple different clusters, and the authorization framework provides multi-functional access control that adapts to different cluster types and resource kinds. This universality eliminates the need for separate authorization configurations for each cluster while maintaining granular control.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If individual log-ins are required for each cluster or product, then cluster-specific security policies can be enforced, but the time required for user management and authentication increases

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary action by pre-configuring user profiles, roles, and authorization policies in the centralized management console before users need to access any cluster. User identities, group memberships, and permission sets are established in advance and stored centrally. When users login federatedly, their authorization context is already prepared and can be quickly applied across multiple clusters without real-time configuration delays.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The federated login system enables self-service authentication where users independently manage their own credentials and access requests through the centralized console. The system automatically handles token generation, session management, and authorization synchronization across clusters without requiring manual intervention for each authentication event. This automated self-service approach reduces both authentication time and administrative overhead.

Inventive Principle:
Principle #25Self-service

3Productivity

If centralized management is implemented across multiple clusters, then operational efficiency improves, but the system complexity and processing requirements increase

Engineering Contradiction:
Improveoperational efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The centralized management console acts as an intermediary layer between users and multiple clusters. It mediates authentication requests, authorization decisions, and resource access control without requiring direct complex interactions between users and each individual cluster. The console translates high-level user permissions into cluster-specific authorization tokens, simplifying the overall system architecture while enabling centralized control and improving operational efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250365276A1Federated login with centralized control
Publication Date: 2025.11.27 RUBRIK INC
  • US20250365276A1 patent drawing
  • US20250365276A1 patent drawing
  • US20250365276A1 patent drawing

AI summary

In some examples, a centralized management system comprises a central management console including a federated login system embedded in the centralized management system. The federated login system includes at least one processor configured to perform operations in a method of federated login and authorization allowing a user of the centralized management system to manage connected clusters or products without performing an individual cluster or product login.