Identity Migration System for Centralized Network Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing multiple network identities across different departments within an organization is cumbersome, leading to difficulties in identity management and user authentication, as each user must have separate identities for each network, making consolidation into a single management system desirable.

Innovation Solution

A system and method for centralizing identity management by retrieving locally managed identities, merging them with centrally managed identities using rules, creating an identity map, and reassigned resources, facilitated by a communication module, identity merge module, and scheduling module, enabling automatic operations and conflict resolution.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple separate network identities are maintained for different departments, then each network can operate independently with its own management, but the complexity of managing multiple identities increases and user authentication becomes difficult

Engineering Contradiction:
Improveindependent network managementVSAvoididentity management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges multiple separate network identities into a unified identity structure by creating a parent-child relationship between parent identities (representing departments or networks) and child identities (representing individual users). This consolidation allows independent network management to be maintained while reducing identity management complexity through centralized oversight.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal parent identity structure that can serve multiple child identities across different networks and departments. The parent identity acts as a multi-functional container that can manage numerous child identities, providing a single point of control that works across diverse network environments.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If each user has separate identities registered with each network, then each network can authenticate users independently, but the difficulty for employees to remember user identification information increases

Engineering Contradiction:
Improveindependent authenticationVSAvoiduser authentication ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a parent identity as an intermediary between the user and multiple child identities across different networks. Instead of users directly managing multiple separate identities, the parent identity serves as a mediator that consolidates access to all child identities, making authentication easier while maintaining independent network security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent combines multiple child identities under a single parent identity, allowing users to authenticate once at the parent level and gain access to multiple networks. This merging reduces the number of separate credentials users must remember while preserving independent authentication capabilities at the child identity level.

Inventive Principle:
Principle #5Merging (Combining)

3Device complexity

If identities are consolidated into a single management system, then identity management complexity is reduced, but the ability to maintain separate network autonomy may be compromised

Engineering Contradiction:
Improveidentity management complexityVSAvoidnetwork autonomy
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent segments the unified identity management system into hierarchical levels: parent identities representing autonomous networks or departments, and child identities representing individual users. This segmentation allows centralized management at the parent level while preserving network autonomy at the child level, resolving the contradiction between consolidation and independence.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds a hierarchical dimension to identity management by creating parent-child relationships. This dimensional change allows the system to operate at multiple levels simultaneously: unified management at the parent level and autonomous operation at the child level, enabling both consolidation and network independence.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

4Adaptability or versatility

If manual management of multiple identities is performed, then flexibility in managing each network separately is maintained, but the time and effort required for management increases

Engineering Contradiction:
Improveflexible network managementVSAvoididentity management time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent performs preliminary action by pre-establishing parent-child identity relationships and configuring inheritance rules before users need to access multiple networks. This advance setup automates the creation and management of child identities under parent identities, reducing the time required for manual identity management while maintaining flexible network-specific configurations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables self-service by allowing parent identities to automatically manage their child identities through inheritance mechanisms. Once the parent identity is configured, child identities are automatically created and managed according to predefined rules, reducing the need for manual intervention and saving management time while preserving network autonomy.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS7895332B2Identity migration system apparatus and method
Publication Date: 2011.02.22 ONE IDENTITY LLC
  • US7895332B2 patent drawing
  • US7895332B2 patent drawing
  • US7895332B2 patent drawing

AI summary

An identity migration agent operating on a local identity server and/or user computer retrieves locally managed identities for an identity migration server. The migration server merges the locally managed identities with centrally managed identities according to a plurality of rules, and creates an identity map that maps the locally managed identities to the centrally managed identities. The migration server communicates the identity map to the identity migration agent that reassigns resources of the locally managed identities to the centrally managed identities in accordance with the identity map. In certain embodiments, the migration server performs identity conflict checks and directs resource assignment rollback operations in response to a user request.