Identity Management Provider for Cloud Platform Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud computing environments, managing identity stores and webtier providers across multiple services is cumbersome, requiring repetitive configurations and lacking centralized management, which complicates the provisioning and maintenance of services.

Innovation Solution

A system and method for providing an identity management provider that centrally manages identity store configurations and associates services with webtier runtimes, allowing platform administrators to specify configurations once and enabling orchestration engines to launch services with appropriate identity stores and webtier configurations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If identity store configurations are managed individually for each service, then each service can have its specific configuration, but the administrative effort and complexity increase significantly

Engineering Contradiction:
Improveservice-specific identity store configurationVSAvoidconfiguration management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal identity store configuration that can be shared across multiple services. The configuration includes service-agnostic parameters such as identity store connection details, authentication methods, and user profile structures that can be applied to any service in the cloud environment, eliminating the need to create separate configurations for each service while still allowing service-specific customization through parameters like service ID and name

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If identity store configurations are created for each service, then each service can be properly configured, but the time and effort required for provisioning increases

Engineering Contradiction:
Improveservice configuration completenessVSAvoidprovisioning time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary configuration by creating a template identity store configuration that contains all necessary parameters and settings before services are provisioned. The configuration is prepared in advance with default values and service-specific parameters that can be automatically populated, allowing services to be quickly instantiated with proper configuration without manual setup time

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If centralized identity store configuration is implemented, then administrative effort is reduced, but the system complexity increases

Engineering Contradiction:
Improveconfiguration management easeVSAvoidcentralized management system complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary configuration file that acts as a mediator between the centralized identity store and individual services. This configuration file contains all necessary connection parameters, authentication details, and service-specific settings in a standardized format that can be automatically processed by the cloud platform, simplifying centralized management while maintaining service-specific requirements

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9847905B2System and method for identity management providers in a cloud platform environment
Publication Date: 2017.12.19 ORACLE INT CORP
  • US9847905B2 patent drawing
  • US9847905B2 patent drawing
  • US9847905B2 patent drawing

AI summary

Described herein is a system and method for supporting an identity management provider in a cloud computing environment. In accordance with an embodiment, an identity management (IDM) provider can provide an identity store (e.g., LDAP directory) configuration for use by a cloud platform (e.g., CloudLogic) service. In accordance with an embodiment, the IDM provider can centrally manage one or more identity store configurations, and supply a particular configuration to the orchestration engine when a service is being provisioned, so that the service can then be launched with an appropriate identity store. This allows a platform administrator to specify identity store configurations once and in one place, instead of having to create an identity store configuration for each service.