Identity Migration System for Centralized Network Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managing multiple network identities across different departments within an organization is cumbersome, leading to difficulties in identity management and user authentication, as each user must have separate identities for each network, making consolidation into a single management system desirable.
Innovation Solution
A system and method for centralizing identity management by retrieving locally managed identities, merging them with centrally managed identities using rules, creating an identity map, and reassigned resources, facilitated by a communication module, identity merge module, and scheduling module, enabling automatic operations and conflict resolution.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple separate network identities are maintained for different departments, then each network can operate independently with its own management, but the complexity of managing multiple identities increases and user authentication becomes difficult
Solution Approach 1:
The patent merges multiple separate network identities into a unified identity structure by creating a parent-child relationship between parent identities (representing departments or networks) and child identities (representing individual users). This consolidation allows independent network management to be maintained while reducing identity management complexity through centralized oversight.
Solution Approach 2:
The patent creates a universal parent identity structure that can serve multiple child identities across different networks and departments. The parent identity acts as a multi-functional container that can manage numerous child identities, providing a single point of control that works across diverse network environments.
2Reliability
If each user has separate identities registered with each network, then each network can authenticate users independently, but the difficulty for employees to remember user identification information increases
Solution Approach 1:
The patent introduces a parent identity as an intermediary between the user and multiple child identities across different networks. Instead of users directly managing multiple separate identities, the parent identity serves as a mediator that consolidates access to all child identities, making authentication easier while maintaining independent network security.
Solution Approach 2:
The patent combines multiple child identities under a single parent identity, allowing users to authenticate once at the parent level and gain access to multiple networks. This merging reduces the number of separate credentials users must remember while preserving independent authentication capabilities at the child identity level.
3Device complexity
If identities are consolidated into a single management system, then identity management complexity is reduced, but the ability to maintain separate network autonomy may be compromised
Solution Approach 1:
The patent segments the unified identity management system into hierarchical levels: parent identities representing autonomous networks or departments, and child identities representing individual users. This segmentation allows centralized management at the parent level while preserving network autonomy at the child level, resolving the contradiction between consolidation and independence.
Solution Approach 2:
The patent adds a hierarchical dimension to identity management by creating parent-child relationships. This dimensional change allows the system to operate at multiple levels simultaneously: unified management at the parent level and autonomous operation at the child level, enabling both consolidation and network independence.
4Adaptability or versatility
If manual management of multiple identities is performed, then flexibility in managing each network separately is maintained, but the time and effort required for management increases
Solution Approach 1:
The patent performs preliminary action by pre-establishing parent-child identity relationships and configuring inheritance rules before users need to access multiple networks. This advance setup automates the creation and management of child identities under parent identities, reducing the time required for manual identity management while maintaining flexible network-specific configurations.
Solution Approach 2:
The patent enables self-service by allowing parent identities to automatically manage their child identities through inheritance mechanisms. Once the parent identity is configured, child identities are automatically created and managed according to predefined rules, reducing the need for manual intervention and saving management time while preserving network autonomy.
Data Source
AI summary
An identity migration agent operating on a local identity server and/or user computer retrieves locally managed identities for an identity migration server. The migration server merges the locally managed identities with centrally managed identities according to a plurality of rules, and creates an identity map that maps the locally managed identities to the centrally managed identities. The migration server communicates the identity map to the identity migration agent that reassigns resources of the locally managed identities to the centrally managed identities in accordance with the identity map. In certain embodiments, the migration server performs identity conflict checks and directs resource assignment rollback operations in response to a user request.


