Identity Bridge for On-Premise Cloud Synchronization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current identity management systems face challenges in providing secure access to cloud-based applications across diverse devices and user types, with inconsistencies in security between on-premise and cloud environments leading to risks such as unauthorized access and inadequate security measures for customers and partners.
Innovation Solution
A microservices-based architecture is implemented for cloud-based multi-tenant identity and access management, using an Identity Bridge between on-premise Active Directory and cloud-based Identity Cloud Service, enabling secure access and synchronization of identities across both environments, with features like Single Sign-On and adaptive authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If identity management systems implement separate security measures for on-premise and cloud environments, then security coverage is expanded, but security consistency deteriorates leading to unauthorized access risks
Solution Approach 1:
The patent merges on-premise Active Directory and cloud-based identity services into a unified identity management system. The Identity Bridge synchronizes user identities, groups, and permissions between both environments, ensuring consistent security policies are applied across on-premise and cloud applications simultaneously, thus maintaining security consistency while expanding coverage.
Solution Approach 2:
The identity management system implements universal security controls that function across both on-premise and cloud environments. The system provides multi-functional capabilities including single sign-on, adaptive authentication, and centralized policy management that work consistently across different deployment types, eliminating the need for separate security measures.
2Ease of manufacture
If traditional identity management architecture is used, then integration with existing systems is simplified, but scalability and flexibility deteriorate when supporting diverse cloud applications and devices
Solution Approach 1:
The system segments identity management functionality into distinct modules: on-premise Active Directory integration, cloud-based Identity Cloud Service, and Identity Bridge synchronization component. This segmentation allows each module to be independently configured and scaled while maintaining overall system coherence, enabling both ease of integration and future scalability.
Solution Approach 2:
The Identity Bridge acts as an intermediary component that connects on-premise Active Directory with cloud-based identity services. It mediates identity synchronization, attribute mapping, and policy translation between the two environments, enabling seamless integration with existing systems while providing the flexibility needed for diverse cloud applications and devices.
3Ease of operation
If basic authentication methods are implemented, then user experience is improved with simpler access, but security control strength deteriorates against unauthorized access and account hijacking
Solution Approach 1:
The system implements adaptive authentication that dynamically adjusts security requirements based on contextual factors such as user location, device type, time of access, and risk assessment. This dynamic approach maintains simple authentication for low-risk scenarios while automatically strengthening security controls for high-risk situations, thus preserving both user experience and security strength.
Solution Approach 2:
The identity management system incorporates feedback mechanisms that continuously monitor authentication attempts, user behavior patterns, and security events. Based on this feedback, the system adaptively adjusts authentication requirements and security policies in real-time, enhancing security control strength while maintaining ease of operation for legitimate users.
Data Source
AI summary
A high availability (HA) Identity Bridge (IDBridge) between an on-premises Active Directory (AD) and a cloud-based Identity Cloud Service (IDCS) is provided. A connection to an AD, coupled to a first network, is established. A connection to an IDCS, coupled to a second network, is established, the IDCS including a System for Cross-domain Identity Management (SCIM) directory. A plurality of selectable AD OUs are displayed in a GUI, and a selection of one or more OUs is then received. Each member group of the selected OUs is displayed in the GUI, and a selection of one or more member groups of the selected OUs is then received. The users of the selected OUs and the selected member groups of the selected OUs are monitored to identify users and groups that have been added, modified or deleted. The identified users and groups are then synchronized to the SCIM directory.


