Multi-tenant IAM Application Templates for Secure Update Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current identity and access management systems in cloud environments face challenges in providing secure and unified access across diverse devices and user types, with inconsistencies in security between on-premise and cloud environments leading to potential security breaches and unauthorized access.

Innovation Solution

A multi-tenant, microservices-based identity and access management system that manages tenant application updates, provides secure access through application templates, and integrates with both on-premise and cloud systems using standards-based services, ensuring consistent security policies across all access points.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a multi-tenant cloud-based IAM system is implemented to provide unified access across diverse devices and users, then security consistency and access control are improved, but system complexity and difficulty of managing application updates across multiple tenants increase

Engineering Contradiction:
Improvesecurity consistencyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments application management into template-level definitions and instance-level deployments. Application templates encapsulate security configurations and access policies, which can be independently updated without affecting the entire multi-tenant system. This segmentation allows security consistency to be maintained across tenants while reducing the complexity of system-wide updates.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary actions by defining application templates with embedded security configurations before actual application deployment. These templates pre-configure access policies, authentication methods, and security parameters, so that when applications are instantiated across multiple tenants, the security consistency is automatically enforced without requiring complex post-deployment management.

Inventive Principle:
Principle #10Preliminary action

2Ease of manufacture

If application templates are used to manage tenant applications, then ease of deployment and consistency are improved, but flexibility in applying updates and changes to individual applications is reduced

Engineering Contradiction:
Improveease of deploymentVSAvoidflexibility in applying updates
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The system implements dynamic update mechanisms that allow application templates to be updated centrally while providing flexible propagation options for individual tenant instances. Administrators can control whether updates are applied automatically, manually, or selectively to specific tenants, enabling both consistent deployment through templates and flexible adaptation when individual applications require custom modifications.

Inventive Principle:
Principle #15Dynamics

3Productivity

If automatic update mode is used for tenant applications, then productivity and speed of applying security patches are improved, but risk of introducing errors and compromising security increases

Engineering Contradiction:
Improvespeed of applying updatesVSAvoidsecurity accuracy
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system implements feedback mechanisms in the automatic update process where application updates are first tested in a validation environment, and only after successful verification are they propagated to production tenant instances. This feedback loop ensures that security patches and updates are validated before deployment, maintaining both high productivity through automation and high reliability through error checking.

Inventive Principle:
Principle #23Feedback

4Reliability

If manual update mode is used for tenant applications, then control and accuracy in applying updates are improved, but time consumption and operational overhead increase

Engineering Contradiction:
Improveupdate accuracyVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements a hybrid update approach where updates are automatically applied to a subset of tenant instances (partial action) while requiring manual approval for others, especially those with custom configurations. This partial automation reduces time consumption compared to fully manual updates while maintaining accuracy through selective human oversight, applying the right level of automation to each update scenario.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10705823B2Application templates and upgrade framework for a multi-tenant identity cloud service
Publication Date: 2020.07.07 ORACLE INT CORP
  • US10705823B2 patent drawing
  • US10705823B2 patent drawing
  • US10705823B2 patent drawing

AI summary

A system manages tenant application updates in a multi-tenant cloud-based identity and access management (IAM) system by defining one or more application templates; creating one or more applications for one or more tenants of the multi-tenant cloud-based IAM system using the one or more application templates; applying a change to at least one of the one or more application templates; determining whether the one or more applications need to be updated in an automatic mode, a semi-automatic mode, or a manual mode, to incorporate the change; and updating at least one of the one or more applications in an applicable one of the automatic mode, the semi-automatic mode, or the manual mode, based on the outcome of the determining.