Multi-tenant Identity Cloud Service Schema Versioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current identity management systems in cloud environments face challenges in providing secure access across diverse devices and user types, with inconsistencies in security between on-premise and cloud environments leading to potential security breaches, especially when managing access for employees, customers, and partners.

Innovation Solution

The implementation of a cloud-based identity management system that uses a microservices-based architecture for multi-tenant identity and data security management, supporting secure access across hybrid cloud deployments, and integrating with both web and mobile channels, while managing access and auditing across on-premise and cloud environments through a unified Identity and Access Management (IAM) platform.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a cloud-based identity management system is implemented to provide secure access across diverse devices and user types, then security and accessibility are improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The identity management system is divided into multiple independent microservices, each handling specific identity management functions. This segmentation allows the system to maintain high security through specialized services while reducing overall complexity by enabling independent deployment and management of each service component.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements a universal identity management platform that serves multiple functions including authentication, authorization, account management, and security policy enforcement across diverse devices and user types. This multi-functionality consolidates what would otherwise require multiple separate systems into a single unified platform.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If multiple versions of resource types with schema changes are stored to support evolving attributes, then adaptability is improved, but data management complexity increases

Engineering Contradiction:
ImproveadaptabilityVSAvoiddata management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system implements dynamic schema versioning where resource type schemas can evolve over time with added or deprecated attributes. Each version is tracked and managed dynamically, allowing the system to adapt to changing requirements while maintaining data consistency through version-aware operations.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system manages schema evolution by tracking changes in resource type parameters (attributes) across versions. When attributes are added or deprecated, the system automatically manages the transition between versions, allowing adaptability to new requirements while maintaining backward compatibility through parameter versioning.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If unified security policies are enforced across on-premise and cloud environments, then security consistency is improved, but implementation complexity increases

Engineering Contradiction:
Improvesecurity consistencyVSAvoidimplementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system merges security policy management for both on-premise and cloud environments into a single unified identity management platform. This consolidation enables consistent security policies across hybrid environments while reducing implementation complexity by eliminating the need for separate policy management systems.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The identity management system acts as an intermediary between on-premise and cloud environments, enforcing unified security policies through centralized authentication and authorization services. This mediator approach ensures security consistency while simplifying implementation by providing a single point of policy enforcement.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11258797B2Data management for a multi-tenant identity cloud service
Publication Date: 2022.02.22 ORACLE INT CORP
  • US11258797B2 patent drawing
  • US11258797B2 patent drawing
  • US11258797B2 patent drawing

AI summary

Embodiments provide cloud based identity management by receiving a request from an application for a resource that includes an operation on a resource type out of a plurality of resource types and the request specifies a tenant out of a plurality of tenants, the resource type including a schema, and the schema includes a plurality of schema attributes and metadata for each of the schema attributes, the resource type including one of a user or a second application. Embodiments store multiple versions of the resource type, at least a first version of the resource indicating a deprecated attribute with respect to a first previous version of the resource type, and at least a second version of the resource type indicating an added attribute with respect to a second previous version of resource type, where the request indicates one of the multiple versions of the resource type.