Identity Cloud Service Metadata Replication for Multi-Tenant Availability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current identity management systems face challenges in providing secure, unified access to cloud-based applications across diverse devices and user types, with inconsistencies in security between cloud and on-premise environments leading to potential security breaches and unauthorized access.

Innovation Solution

A multi-tenant, microservices-based identity cloud service that implements metadata replication, supports secure access across hybrid cloud deployments, and integrates with existing applications and identities, using a distributed data grid for scalable and secure identity management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a multi-tenant cloud system replicates global resources across multiple data centers, then system availability and security are improved, but system complexity and synchronization overhead increase

Engineering Contradiction:
Improvesystem availabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the identity cloud service into multiple independent data centers (first data center, second data center) that can operate autonomously. Each data center maintains its own global resources and can serve requests independently, improving availability while managing complexity through clear separation of functions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements copying of global resources from the first data center to the second data center. Manifest files and change event messages are used to replicate resource types, schemas, and identity data across data centers, ensuring consistency and availability without requiring complex real-time synchronization mechanisms.

Inventive Principle:
Principle #26Copying

2Adaptability or versatility

If global resources are upgraded to a new version at the first data center, then system functionality is improved, but consistency maintenance across data centers becomes more difficult

Engineering Contradiction:
Improvesystem functionalityVSAvoiddata consistency
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent generates manifest files and change event messages at the first data center before or during the upgrade process. These files contain advance notification of resource changes, allowing the second data center to proactively update its copies and maintain consistency without complex real-time coordination.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements a feedback mechanism where change event messages are pushed from the first data center to the second data center. The second data center compares current versions with new versions and applies changes only when needed, ensuring consistency while avoiding unnecessary updates and maintaining system reliability.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If the system supports multiple user types and device types, then accessibility is improved, but security management complexity increases

Engineering Contradiction:
ImproveaccessibilityVSAvoidsecurity management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal identity cloud service that handles multiple user types (employees, partners, customers) and device types (desktop, mobile) through a single unified system. The service provides consistent authentication and authorization mechanisms across all users and devices, simplifying security management while maintaining broad accessibility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an identity cloud service as an intermediary between users/devices and cloud-based applications. This intermediary layer manages security policies, authentication, and authorization centrally, allowing diverse users and devices to access applications securely without requiring complex point-to-point security configurations.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If security policies are unified across hybrid cloud environments, then security consistency is improved, but integration complexity with existing systems increases

Engineering Contradiction:
Improvesecurity consistencyVSAvoidintegration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal security framework that operates consistently across hybrid cloud environments (public cloud, private cloud, on-premises). The identity cloud service provides unified authentication, authorization, and security policy enforcement that works the same way regardless of the underlying infrastructure, ensuring security consistency while simplifying integration.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The identity cloud service acts as an intermediary layer between existing applications/identities and the cloud infrastructure. It provides a standardized interface for security management that can integrate with various existing systems (on-premises directories, cloud applications, mobile devices) without requiring complex custom integrations for each system.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3794797B1Replication of resource type and schema metadata for a multi-tenant identity cloud service
Publication Date: 2022.01.19 ORACLE INT CORP
  • EP3794797B1 patent drawingFigure 1
  • EP3794797B1 patent drawingFigure 2
  • EP3794797B1 patent drawingFigure 3

AI summary

Embodiments operate a multi-tenant cloud system with a first data center. At the first data center, embodiments authenticate a first client and store resources that correspond to the first client, the first data center in communication with a second data center that is configured to authenticate the first client and replicate the resources. In response to upgrading global resources at the first data center to a new version, embodiments generate a manifest file including a listing of global resource types and schemas that are modified or added in response to the upgrading. Embodiments further upgrade global resources based on the manifest file and write the upgraded global resources to a first global database and generate change event messages corresponding to the upgraded global resources.