Identity Management System for Auditable Impersonation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current identity management systems face challenges in efficiently managing permissions and accountability across multiple services, particularly in scenarios where users need to perform tasks that require permissions they do not have, such as ostensible impersonation, which can lead to loss of auditing fidelity and improper delegation of services.

Innovation Solution

The implementation of an identity management system that includes an authority engine, duty engine, termination engine, audit engine, and liability engine, which utilize agency identifiers and duty identifiers to manage agency relationships, authorize access, track actions, and terminate relationships, allowing ostensible impersonation across multiple services while maintaining accountability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If ostensible impersonation is implemented to allow users to perform tasks requiring permissions they do not have, then task completion capability is improved, but auditing fidelity is lost

Engineering Contradiction:
Improvetask completion capabilityVSAvoidauditing fidelity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an identity management system as an intermediary between the user and the service fulfillment system. This intermediary maintains the ability to perform tasks on behalf of users while preserving auditing fidelity by tracking actions taken under the user's identity, thus resolving the contradiction between task completion capability and auditing reliability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates a copy of the user's identity context within the identity management system, allowing impersonation to occur through this copy rather than directly modifying the original identity. This copying mechanism enables task completion while maintaining the original identity's auditing trail intact

Inventive Principle:
Principle #26Copying

2Productivity

If permissions are delegated across multiple services to enable comprehensive task fulfillment, then service coordination capability is improved, but permission management complexity increases

Engineering Contradiction:
Improveservice coordination capabilityVSAvoidpermission management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The identity management system implements a universal permission management mechanism that works across multiple services and fulfillment systems. By creating a centralized authority that can delegate permissions universally, the system improves service coordination while avoiding the complexity of implementing separate permission systems for each service

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent segments the permission management function into distinct components: identity verification, permission delegation, and action tracking. This segmentation allows each component to handle specific aspects of cross-service coordination independently, reducing overall management complexity while maintaining comprehensive service coordination capability

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11334674B2End point identification
Publication Date: 2022.05.17 MICRO FOCUS LLC
  • US11334674B2 patent drawing
  • US11334674B2 patent drawing
  • US11334674B2 patent drawing

AI summary

In some examples, a system provides an agency identifier identifying an authority relationship between a first identity and a second identity, provides a duty identifier based on the agency identifier and a first end point, identifies a second end point based on the first end point, associates authority to access the second end point with the duty identifier, and accesses the second service at the second end point, the accessing comprising an entity identified by the second identity accessing the second end point on behalf of an entity identified by the first identity based on the authority relationship.