Unified Identity Federation Configuration Interface

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The configuration of identity federation across different computing systems is inefficient due to the need for system administrators to manage disparate proprietary environments, interfaces, and data formats, leading to increased workload and error probability.

Innovation Solution

A method and apparatus that acquire and identify associated identity federation configuration properties across systems, display necessary configurations in a unified interface, and automatically assign values where possible, reducing manual input and ensuring consistency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If system administrators configure identity federation manually in proprietary environments of each system, then configuration flexibility and system-specific adaptation are improved, but configuration complexity and administrator workload increase significantly

Engineering Contradiction:
Improveconfiguration flexibilityVSAvoidconfiguration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a configuration synchronization mechanism that acts as an intermediary between multiple identity federation systems. This mediator captures configuration actions performed on one system and automatically propagates them to other connected systems, thereby reducing the complexity of manual configuration while preserving system-specific adaptability through the intermediary layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a universal configuration interface that can interact with multiple different proprietary identity federation systems through standardized protocols. This universal layer translates between different system-specific formats and a common configuration representation, allowing administrators to manage diverse systems through a single unified interface without sacrificing system-specific capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If system administrators manually configure identity federation parameters in each proprietary environment, then system-specific requirements are met, but time consumption and error probability increase

Engineering Contradiction:
Improvesystem-specific adaptationVSAvoidconfiguration time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by establishing configuration synchronization and propagation mechanisms before actual identity federation operations begin. The system pre-configures translation rules, mapping relationships, and synchronization protocols between different proprietary environments, so that when configuration changes are made, they are automatically propagated without requiring manual reconfiguration in each system, thereby reducing configuration time while maintaining system-specific adaptation.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If administrators configure identity federation in multiple proprietary interfaces with different data formats, then each system's specific format requirements are satisfied, but ease of operation decreases due to learning multiple interfaces

Engineering Contradiction:
Improveformat compatibilityVSAvoidinterface usability
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent employs copying by creating a unified virtual representation of identity federation configurations that mirrors the structure and semantics of multiple proprietary formats. This virtual copy serves as a universal interface that administrators interact with, while the system automatically translates and propagates configurations to the actual proprietary systems in their required formats, thereby simplifying the user interface without sacrificing format compatibility.

Inventive Principle:
Principle #26Copying

4Manufacturing precision

If manual configuration of identity federation parameters is performed across multiple systems, then configuration accuracy can be controlled, but productivity decreases due to repetitive manual work

Engineering Contradiction:
Improveconfiguration accuracyVSAvoidconfiguration efficiency
Core Design Contradiction:
Manufacturing precisionVSProductivity

Solution Approach 1:

The patent implements feedback mechanisms that automatically verify configuration consistency across multiple identity federation systems. The system monitors configuration changes, propagates them to connected systems, and provides feedback on successful or failed propagation. This automated feedback loop maintains configuration accuracy by detecting and reporting inconsistencies while eliminating repetitive manual configuration work, thereby improving productivity without sacrificing precision.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9576125B2Configuring identity federation configuration
Publication Date: 2017.02.21 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US9576125B2 patent drawing
  • US9576125B2 patent drawing
  • US9576125B2 patent drawing

AI summary

A method and apparatus for configuring identity federation configuration. The method includes: acquiring a set of identity federation configuration properties of a first computing system and a set of identity federation configuration properties of a second computing system; identifying one or more pairs of associated properties in the first and the second sets, where the pairs of associated properties include one property from each set of identity federation configuration; displaying, properties that need to be configured manually from the each sets of identity federation configuration properties, where the properties that need to be configured manually do not include the property in any pair of associated properties for which the value can be derived from the value of another property in the pair; automatically assigning a property that can be derived from the value of another property; and providing each computing systems with each set of identity federation properties.