Identity Fabric for Centralized Administration of Disparate Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The complexity and fragmentation of identity management systems within organizations, resulting from the use of multiple third-party cloud services, make centralized administration difficult, leading to cumbersome management and increased security risks.
Innovation Solution
The introduction of systems, methods, and storage media that enable centralized configuration and management of disparate identity management systems through the use of executable scripts, Discovery Agents, Orchestrating Agents, Fabric Connectors, Monitoring Agents, and Configuration Agents, which facilitate the orchestration, integration, and abstraction of identity data and metadata, allowing for unified policy management and risk assessment across multiple identity domains.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple third-party cloud services are utilized, then service functionality and versatility are improved, but system complexity and administration difficulty increase
Solution Approach 1:
The patent introduces an intermediary layer (identity fabric, agents, and connectors) that sits between the organization's identity management needs and multiple third-party cloud services. This intermediary abstracts the complexity of managing disparate identity systems while enabling versatile service integration, allowing organizations to utilize multiple cloud services without directly managing their individual complexities.
Solution Approach 2:
The identity fabric and agents are designed as universal components that can interface with multiple different third-party cloud services through standardized mechanisms. This multi-functionality allows a single identity management framework to handle diverse service providers, reducing the need for separate management approaches for each service.
2Adaptability or versatility
If multiple third-party cloud services are utilized, then service functionality is improved, but ease of operation deteriorates
Solution Approach 1:
The orchestrating agents and identity fabric serve as intermediaries that centralize the administration of multiple identity management systems. Administrators can manage policies, users, and credentials across different cloud services through a unified interface, significantly improving ease of operation while maintaining access to diverse service functionalities.
Solution Approach 2:
The patent merges the administration of multiple disparate identity management systems into a single unified framework. By combining control plane operations, policy management, and user provisioning into one centralized system, it enables administrators to operate multiple cloud services through a single management console, thereby improving ease of operation.
3Ease of operation
If centralized configuration is implemented, then administration ease is improved, but system complexity increases
Solution Approach 1:
The patent introduces an intermediary identity fabric layer that handles the complexity of centralized configuration. This fabric acts as a buffer between the simplified administrative interface and the underlying complex infrastructure, allowing centralized management without exposing the full complexity to administrators.
Solution Approach 2:
The system employs self-service mechanisms where agents automatically discover, configure, and adapt to connected identity management systems. This automation reduces the manual complexity of implementing centralized configuration, as the system performs much of the complex setup work autonomously without requiring deep administrative intervention.
4Adaptability or versatility
If identity data is dispersed across multiple systems, then service versatility is improved, but security reliability deteriorates
Solution Approach 1:
The patent merges the management of dispersed identity data into a unified control framework. While identity data may physically reside in multiple cloud services, the control plane operations, policy enforcement, and security management are combined into a centralized identity fabric that ensures consistent security standards across all systems, thereby maintaining security reliability while preserving service versatility.
Solution Approach 2:
The monitoring agents and orchestrating agents implement continuous feedback loops that track identity data flows, access patterns, and security events across dispersed systems. This feedback mechanism enables real-time security assessment, policy enforcement, and anomaly detection, ensuring that security reliability is maintained even as identity data is distributed across multiple versatile service platforms.
Data Source
AI summary
Systems, methods, and storage media for management of identity systems in an identity infrastructure are disclosed. Exemplary implementations may: install a discovery agent in the identity infrastructure; assess the identity infrastructure by the discovery agent; install an identity fabric in the identity infrastructure based on the assessing; receive, at the identity infrastructure, one or more data flows pertaining to identity data or identity metadata for at least one identity domain/system; manage, by a controller element, control plane operations across one or more elements or agents; manage, by at least one of the agents, the one or more data flows; detect and monitor, by the one or more elements or agents, at least one event linked to the one or more data flows; and assess the identity data or metadata and an associated state across the identity domains in the identity infrastructure based on the detecting and monitoring.


