Identity Provider Migration via Federated SSO Account Linking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current federated user lifecycle management functionality does not accommodate advanced interactions, particularly in account linking and delinking operations, and does not allow for easy migration of user relationships between identity providers, leading to burdensome processes for both users and enterprises.

Innovation Solution

A method for identity provider migration within a federated computational environment, where a user's account is modified to indicate reliance on a new identity provider, allowing seamless transition and account linking/federation with the new provider during single-sign-on operations, thereby enabling migration between identity providers without de-referencing the user's actual identity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If account delinking is performed by simply breaking the link between identity provider and service provider, then the operation is simple to implement, but user migration between identity providers becomes difficult and burdensome

Engineering Contradiction:
Improveease of implementationVSAvoiduser migration capability
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent introduces an intermediary mechanism (account linking information and federation metadata) that mediates between the identity provider and service provider relationships. This allows seamless migration by maintaining reference information that enables the service provider to recognize and transfer user associations to new identity providers without requiring complex reconfiguration or user intervention.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary actions by maintaining account linking information and federation metadata before migration is needed. This pre-established information structure allows the service provider to quickly recognize and transfer user associations during migration events, eliminating the need for complex real-time operations when migration actually occurs.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If federated user lifecycle management simply breaks links between identity providers and service providers, then the process is straightforward, but administrative burdens increase during identity provider migration

Engineering Contradiction:
Improveoperational simplicityVSAvoidadministrative time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent uses intermediary mechanisms (account linking information stored as federation metadata) to automate the migration process. This eliminates the need for administrators to manually manage complex link-breaking and re-establishing operations, reducing administrative time and effort while maintaining operational simplicity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service migration by automatically processing identity provider transitions using pre-stored account linking information. The service provider can autonomously recognize and transfer user associations without requiring administrative intervention, thereby reducing administrative burdens and time losses.

Inventive Principle:
Principle #25Self-service

3Device complexity

If user accounts are de-referenced during identity provider migration, then the migration process is simplified, but the user's actual identity and account history are lost

Engineering Contradiction:
Improvemigration process complexityVSAvoiduser identity information
Core Design Contradiction:
Device complexityVSLoss of information

Solution Approach 1:

The patent implements copying by maintaining account linking information as federation metadata that preserves user identity references. Instead of de-referencing user accounts during migration, the system creates and maintains reference copies that allow the service provider to continue recognizing user identities across different identity providers, thereby preserving user identity information while simplifying the migration process.

Inventive Principle:
Principle #26Copying

4Adaptability or versatility

If federated enterprises interoperate to support federation protocols, then interoperability improves, but the operational burdens on users increase due to awareness of underlying mechanisms

Engineering Contradiction:
ImproveinteroperabilityVSAvoiduser operational burden
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent implements self-service by automatically handling federation protocol operations, account linking information management, and identity provider migration processes without requiring user awareness or intervention. Users benefit from improved interoperability between federated enterprises while experiencing no additional operational burden, as the system autonomously manages the underlying complex mechanisms.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS7657639B2Method and system for identity provider migration using federated single-sign-on operation
Publication Date: 2010.02.02 SERVICENOW INC
  • US7657639B2 patent drawing
  • US7657639B2 patent drawing
  • US7657639B2 patent drawing

AI summary

A method is presented for performing an identity provider migration operation with respect to a user within a federated computational environment, wherein the user has a first user account at a first identity provider, a second user account at a second identity provider, and a third user account at a service provider. A request to access a resource is received by the service provider, after which a federated single-sign-on operation for the user is performed between the service provider and the first identity provider. Prior to sending a response to the request to access the protected resource, information in the third user account is modified to indicate that the service provider relies upon the second identity provider to authenticate the user on behalf of the service provider rather than the first identity provider. A response for the request to access the resource is then returned by the service provider.