Identity Cloud Service Metadata Replication for Multi-Tenant Availability
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current identity management systems face challenges in providing secure, unified access to cloud-based applications across diverse devices and user types, with inconsistencies in security between cloud and on-premise environments leading to potential security breaches and unauthorized access.
Innovation Solution
A multi-tenant, microservices-based identity cloud service that implements metadata replication, supports secure access across hybrid cloud deployments, and integrates with existing applications and identities, using a distributed data grid for scalable and secure identity management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a multi-tenant cloud system replicates global resources across multiple data centers, then system availability and security are improved, but system complexity and synchronization overhead increase
Solution Approach 1:
The patent segments the identity cloud service into multiple independent data centers (first data center, second data center) that can operate autonomously. Each data center maintains its own global resources and can serve requests independently, improving availability while managing complexity through clear separation of functions.
Solution Approach 2:
The patent implements copying of global resources from the first data center to the second data center. Manifest files and change event messages are used to replicate resource types, schemas, and identity data across data centers, ensuring consistency and availability without requiring complex real-time synchronization mechanisms.
2Adaptability or versatility
If global resources are upgraded to a new version at the first data center, then system functionality is improved, but consistency maintenance across data centers becomes more difficult
Solution Approach 1:
The patent generates manifest files and change event messages at the first data center before or during the upgrade process. These files contain advance notification of resource changes, allowing the second data center to proactively update its copies and maintain consistency without complex real-time coordination.
Solution Approach 2:
The patent implements a feedback mechanism where change event messages are pushed from the first data center to the second data center. The second data center compares current versions with new versions and applies changes only when needed, ensuring consistency while avoiding unnecessary updates and maintaining system reliability.
3Adaptability or versatility
If the system supports multiple user types and device types, then accessibility is improved, but security management complexity increases
Solution Approach 1:
The patent implements a universal identity cloud service that handles multiple user types (employees, partners, customers) and device types (desktop, mobile) through a single unified system. The service provides consistent authentication and authorization mechanisms across all users and devices, simplifying security management while maintaining broad accessibility.
Solution Approach 2:
The patent introduces an identity cloud service as an intermediary between users/devices and cloud-based applications. This intermediary layer manages security policies, authentication, and authorization centrally, allowing diverse users and devices to access applications securely without requiring complex point-to-point security configurations.
4Reliability
If security policies are unified across hybrid cloud environments, then security consistency is improved, but integration complexity with existing systems increases
Solution Approach 1:
The patent creates a universal security framework that operates consistently across hybrid cloud environments (public cloud, private cloud, on-premises). The identity cloud service provides unified authentication, authorization, and security policy enforcement that works the same way regardless of the underlying infrastructure, ensuring security consistency while simplifying integration.
Solution Approach 2:
The identity cloud service acts as an intermediary layer between existing applications/identities and the cloud infrastructure. It provides a standardized interface for security management that can integrate with various existing systems (on-premises directories, cloud applications, mobile devices) without requiring complex custom integrations for each system.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Embodiments operate a multi-tenant cloud system with a first data center. At the first data center, embodiments authenticate a first client and store resources that correspond to the first client, the first data center in communication with a second data center that is configured to authenticate the first client and replicate the resources. In response to upgrading global resources at the first data center to a new version, embodiments generate a manifest file including a listing of global resource types and schemas that are modified or added in response to the upgrading. Embodiments further upgrade global resources based on the manifest file and write the upgraded global resources to a first global database and generate change event messages corresponding to the upgraded global resources.