Identity Management Router Simplifies SCIM Topology

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current SCIM technologies face challenges in managing and filtering identity management data to comply with local data protection requirements and regulations, such as GDPR, due to their point-to-point communication nature, which leads to complex topologies and access rights management issues.

Innovation Solution

An identity management router is introduced to facilitate communication via an identity management protocol like SCIM, implementing a star topology (hub) to simplify data sharing and enforce data compliance policies, thereby reducing the complexity of access controls and data protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If point-to-point SCIM communication is used, then direct data sharing between endpoints is enabled, but topology complexity and access rights management become complicated

Engineering Contradiction:
Improvedata sharing between endpointsVSAvoidtopology complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces a central SCIM endpoint that acts as an intermediary between all other SCIM endpoints. Instead of direct point-to-point connections, all data sharing requests route through this central endpoint, which manages the topology and access rights centrally. This resolves the contradiction by enabling data sharing while keeping the topology manageable through centralized control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The central SCIM endpoint performs multiple functions: it acts as a data provider, data consumer, access rights manager, and topology coordinator simultaneously. This multi-functional design simplifies the overall system architecture by consolidating what would otherwise require multiple specialized components in a point-to-point mesh topology.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If point-to-point SCIM communication is used, then direct access between endpoints is achieved, but access rights management becomes complicated when multiple endpoints are added

Engineering Contradiction:
Improveendpoint connectivityVSAvoidaccess rights management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The central SCIM endpoint serves as an intermediary that centralizes access rights management. Instead of each endpoint needing to manage permissions with every other endpoint individually, the central endpoint maintains a unified access rights database and enforces permissions centrally, simplifying the management of adaptability across multiple endpoints.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system changes the parameter of access rights management from a distributed model (where each endpoint manages its own permissions) to a centralized model (where the central endpoint manages all permissions). This parameter change resolves the contradiction by maintaining endpoint connectivity while simplifying access rights management through centralized control.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If firewall rules are configured for each endpoint in point-to-point topology, then connectivity is enabled, but configuration overhead increases with each new endpoint

Engineering Contradiction:
Improveendpoint connectivityVSAvoidfirewall configuration time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The central SCIM endpoint acts as a single intermediary that requires only one firewall configuration rule set, rather than requiring individual rules for each endpoint pair. This resolves the contradiction by maintaining endpoint connectivity while significantly reducing firewall configuration time and overhead through centralized access points.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If data is shared across multiple regions with different data protection requirements, then global data access is enabled, but compliance with local regulations becomes challenging

Engineering Contradiction:
Improveglobal data accessVSAvoiddata protection compliance
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies local quality by implementing region-specific data protection policies at the central SCIM endpoint. Each geographic region (e.g., EU, non-EU) has its own compliance rules enforced locally, allowing the system to maintain global data access while ensuring each region's data processing adheres to its specific regulatory requirements.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system changes the parameter of data protection from a uniform global policy to a region-specific policy framework. The central endpoint dynamically adjusts data sharing parameters based on the geographic location and regulatory requirements of the involved endpoints, resolving the contradiction between global accessibility and local compliance.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12267363B2Identity management protocol router
Publication Date: 2025.04.01 SAILPOINT TECHNOLOGIES INC
  • US12267363B2 patent drawing
  • US12267363B2 patent drawing
  • US12267363B2 patent drawing

AI summary

Systems and methods for an identity management router to allow application clients/servers to communicate via an identity management protocol to facilitate communication of identity management artifacts with a simplified topology. Specifically, embodiments of an IM router may adhere to various data protection requirements, including, but not limited to, local data protection regulations, when routing identity management information. The identity management router is location aware and applies data compliance policies for areas of data compliance to selectively route or not route identity management data based on location.