Identity Propagation for Multi-Product Auditing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Identity-based auditing is complex and inefficient in multi-product software environments where each product has its own authentication mechanism and identity registry, requiring costly mapping and mining of audit records to determine the actual user responsible for operations.
Innovation Solution
Propagating the user's identity from the authentication point to multiple applications, ensuring that audit records generated by each application include the identity passed during the SSH/RXA login, facilitating identity-based auditing across applications with distinct authentication processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If identity mapping is performed at the boundary between individual products, then identity information can be captured in audit records, but the process becomes complex and costly requiring mining of mapped audit records
Solution Approach 1:
The patent introduces an identity store as an intermediary component that maintains a mapping between product-specific user identifiers and a universal identifier. This intermediary enables direct capture of accurate identity information in audit records without requiring complex post-processing or mining of mapped records, thus resolving the contradiction between measurement precision and device complexity
Solution Approach 2:
The system performs preliminary identity resolution by obtaining the universal identifier from the identity store before the user performs operations across multiple products. This preliminary action ensures that audit records contain accurate identity information from the outset, eliminating the need for complex post-audit mining processes
2Adaptability or versatility
If each product has its own authentication mechanism and identity registry, then product independence is maintained, but determining the actual user requires complex mining of mapped audit records
Solution Approach 1:
The patent implements a universal identifier that works across all products in the suite while maintaining each product's independent authentication mechanisms. The identity store provides a universal mapping layer that enables cross-product user identification without requiring changes to individual product authentication systems, thus resolving the contradiction between adaptability and time loss
Solution Approach 2:
The identity store acts as a mediator that translates between product-specific identifiers and a universal identifier. This intermediary enables rapid user identification across products without requiring complex mining of audit records, reducing the time lost while preserving product independence
3Reliability
If identity mapping is implemented across multiple products, then audit information can be captured, but the cost and efficiency of determining the actual user deteriorates
Solution Approach 1:
The system performs preliminary resolution of user identities to universal identifiers before operations occur across multiple products. This preliminary action ensures complete audit information is captured with accurate user identification from the start, eliminating the need for expensive and inefficient post-audit mining processes, thus resolving the contradiction between reliability and productivity
Data Source
AI summary
An identity of a user performing an operation with respect to an application is propagated, from a point at which the user authenticates, to one or more other applications in a multi-product environment. The application may be a management console associated with an information cluster. In an embodiment, an administrator logs on to a management console (using an identity) and invokes a management operation. The management console then performs a programmatic remote access login (e.g., using SSH/RXA) to one or more nodes using a system account, invokes an application, and passes in the identity. As the application performs one or more management operations, audit events are logged, and these events each contain the identity that has been passed in by the management console during the SSH/RXA login. The technique thus provides a method for identity-based auditing in an environment having a plurality of applications, where each application typically has a respective authentication process or mechanism and distinct identity registries.


