Identity Governance Suite with Organization-Specific Soft-Lockout Policies

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises face challenges in managing user access and enforcing governance controls due to the lack of a unified identity governance suite, leading to increased complexity and costs, as well as inadequate auditing capabilities, particularly with SPML requests originating from a single proxy account.

Innovation Solution

Implementing a unified identity governance suite with features like organization-specific soft-lockout policies, a uniform interface for heterogeneous account state repositories, and propagating real user identities in SPML calls to enhance auditing accuracy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a single proxy account is used for all SPML requests, then system complexity is reduced and authentication is simplified, but auditing accuracy deteriorates because the real user identity cannot be tracked

Engineering Contradiction:
Improveauthentication complexityVSAvoidauditing accuracy
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent introduces an intermediary mechanism that passes the real user identity through the proxy account authentication process. The identity management system extracts the authenticator from the SPML request and propagates it through the provisioning workflow, enabling accurate auditing while maintaining the simplified single-proxy authentication model.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple vendor products are implemented as point solutions, then specific governance needs are addressed, but system complexity and integration costs increase

Engineering Contradiction:
Improvegovernance functionalityVSAvoidintegration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges provisioning, privileged access management, role management, and compliance functions into a unified identity governance suite from a single vendor. This consolidation eliminates the need for multiple point solutions and reduces integration complexity while maintaining comprehensive governance capabilities.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The identity management system provides universal functionality that handles multiple governance tasks through a single platform. The system can perform provisioning, access management, role assignment, and auditing through integrated workflows, reducing the need for separate specialized products.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If organization-specific soft-lockout policies are implemented, then security behavior can be customized per organization, but policy management complexity increases

Engineering Contradiction:
Improvesecurity policy customizationVSAvoidpolicy management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by allowing different soft-lockout policies for different organizations within the identity management system. Each organization can have customized security behaviors such as different lockout durations or attempt thresholds, while the system manages this diversity through centralized policy configuration.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9838435B2Authenticator for user state management
Publication Date: 2017.12.05 ORACLE INT CORP
  • US9838435B2 patent drawing
  • US9838435B2 patent drawing
  • US9838435B2 patent drawing

AI summary

Different types of soft-lockout policies can be associated with different organizations (or groups) in an identity management system. Each soft-lockout policy can indicate different parameters such as a number of login attempts allowed and an amount of time that a user account will be locked-out if the maximum allowed attempts are exceeded unsuccessfully. Users can be associated with the different organizations. For each user, the soft-lockout policies for the organization with which that user is associated are applied to that user when that user attempts to log in. Thus, different groups of users can be handled with different security behaviors regarding unsuccessful login attempts. If, for example, a user were to become moved from one organization to another, then the soft-lockout policies associated with the user's new organization would become applicable to that user.