Multi-tenant Identity Cloud Service Schema Versioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current identity management systems in cloud environments face challenges in providing secure access across diverse devices and user types, with inconsistencies in security between on-premise and cloud environments leading to potential security breaches, especially when managing access for employees, customers, and partners.
Innovation Solution
The implementation of a cloud-based identity management system that uses a microservices-based architecture for multi-tenant identity and data security management, supporting secure access across hybrid cloud deployments, and integrating with both web and mobile channels, while managing access and auditing across on-premise and cloud environments through a unified Identity and Access Management (IAM) platform.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a cloud-based identity management system is implemented to provide secure access across diverse devices and user types, then security and accessibility are improved, but system complexity increases
Solution Approach 1:
The identity management system is divided into multiple independent microservices, each handling specific identity management functions. This segmentation allows the system to maintain high security through specialized services while reducing overall complexity by enabling independent deployment and management of each service component.
Solution Approach 2:
The system implements a universal identity management platform that serves multiple functions including authentication, authorization, account management, and security policy enforcement across diverse devices and user types. This multi-functionality consolidates what would otherwise require multiple separate systems into a single unified platform.
2Adaptability or versatility
If multiple versions of resource types with schema changes are stored to support evolving attributes, then adaptability is improved, but data management complexity increases
Solution Approach 1:
The system implements dynamic schema versioning where resource type schemas can evolve over time with added or deprecated attributes. Each version is tracked and managed dynamically, allowing the system to adapt to changing requirements while maintaining data consistency through version-aware operations.
Solution Approach 2:
The system manages schema evolution by tracking changes in resource type parameters (attributes) across versions. When attributes are added or deprecated, the system automatically manages the transition between versions, allowing adaptability to new requirements while maintaining backward compatibility through parameter versioning.
3Reliability
If unified security policies are enforced across on-premise and cloud environments, then security consistency is improved, but implementation complexity increases
Solution Approach 1:
The system merges security policy management for both on-premise and cloud environments into a single unified identity management platform. This consolidation enables consistent security policies across hybrid environments while reducing implementation complexity by eliminating the need for separate policy management systems.
Solution Approach 2:
The identity management system acts as an intermediary between on-premise and cloud environments, enforcing unified security policies through centralized authentication and authorization services. This mediator approach ensures security consistency while simplifying implementation by providing a single point of policy enforcement.
Data Source
AI summary
Embodiments provide cloud based identity management by receiving a request from an application for a resource that includes an operation on a resource type out of a plurality of resource types and the request specifies a tenant out of a plurality of tenants, the resource type including a schema, and the schema includes a plurality of schema attributes and metadata for each of the schema attributes, the resource type including one of a user or a second application. Embodiments store multiple versions of the resource type, at least a first version of the resource indicating a deprecated attribute with respect to a first previous version of the resource type, and at least a second version of the resource type indicating an added attribute with respect to a second previous version of resource type, where the request indicates one of the multiple versions of the resource type.


