Identity Mapping for Cloud Migration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for migrating identities from on-premises environments to cloud environments are inconsistent and often require post-migration fixups, as they rely on guesses about attribute matches, leading to uncertain results and multiple attempts before successful migration.

Innovation Solution

The use of specialized data collectors to gather information from both source and target environments, combined with correlation algorithms to identify matches and non-matches, allows for pre-migration assessment and editing of mappings, ensuring accurate identity and data migration through the creation of migration files.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing migration tools use guess-based attribute matching, then the migration process can be initiated, but the results are inconsistent and require multiple attempts and post-migration fixups

Engineering Contradiction:
Improvemigration success rateVSAvoidnumber of migration attempts
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements pre-migration mapping assessment that evaluates and validates identity attribute mappings before the actual migration occurs. This preliminary action identifies potential mapping issues and allows administrators to correct them beforehand, preventing migration failures and reducing the need for multiple attempts and post-migration fixups.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If migration tools attempt real-time mapping during migration, then the process can proceed, but administrators cannot assess results until after migration, requiring multiple attempts

Engineering Contradiction:
Improvemigration execution speedVSAvoidtime to assess and correct mapping issues
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system performs mapping assessment in advance of the actual migration, allowing administrators to review and validate mappings before commitment. This separates the assessment phase from the execution phase, enabling thorough validation without delaying the actual migration when it is finally executed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mapping assessment layer between the source and target systems. This intermediary evaluates potential mappings, provides feedback on their validity, and allows correction before the actual migration occurs, acting as a buffer that prevents direct trial-and-error migrations.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If simple guess-based matching is used, then the migration tool is easier to operate, but the mapping accuracy is low and requires manual fixups

Engineering Contradiction:
Improvemigration tool usabilityVSAvoidattribute matching accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The system provides feedback mechanisms that show administrators the proposed mappings, their confidence levels, and potential issues. This feedback allows administrators to review automated suggestions and make informed decisions, combining the efficiency of automated matching with the accuracy of human judgment when needed.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11669549B2Identity mapping for cloud migrations
Publication Date: 2023.06.06 MICROSOFT TECHNOLOGY LICENSING LLC
  • US11669549B2 patent drawing
  • US11669549B2 patent drawing
  • US11669549B2 patent drawing

AI summary

Representative embodiments disclose mechanisms for data and identity migration, such as from an on-premises environment to a cloud environment. The system comprises multiple data collectors, each tailored to collect data from a data source. In a representative example, data collectors for a source application, a source identity repository and a target identity repository are utilized. Once the data is collected, it is stored in a database and methods are used to identify correlations (i.e., matches) between the source application data, the source identity repository data and the target identity repository data. The correlations are memorialized and presented to a user for rationalization. The process is stateful so that prior decisions are remembered. Once the user is satisfied with the rationalization, the system exports files that are consumed by a migration process to perform the actual data migration.