Identity Provider Migration via Federated SSO Account Linking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current federated user lifecycle management functionality does not accommodate advanced interactions, particularly in account linking and delinking operations, and does not allow for easy migration of user relationships between identity providers, leading to burdensome processes for both users and enterprises.
Innovation Solution
A method for identity provider migration within a federated computational environment, where a user's account is modified to indicate reliance on a new identity provider, allowing seamless transition and account linking/federation with the new provider during single-sign-on operations, thereby enabling migration between identity providers without de-referencing the user's actual identity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If account delinking is performed by simply breaking the link between identity provider and service provider, then the operation is simple to implement, but user migration between identity providers becomes difficult and burdensome
Solution Approach 1:
The patent introduces an intermediary mechanism (account linking information and federation metadata) that mediates between the identity provider and service provider relationships. This allows seamless migration by maintaining reference information that enables the service provider to recognize and transfer user associations to new identity providers without requiring complex reconfiguration or user intervention.
Solution Approach 2:
The system performs preliminary actions by maintaining account linking information and federation metadata before migration is needed. This pre-established information structure allows the service provider to quickly recognize and transfer user associations during migration events, eliminating the need for complex real-time operations when migration actually occurs.
2Ease of operation
If federated user lifecycle management simply breaks links between identity providers and service providers, then the process is straightforward, but administrative burdens increase during identity provider migration
Solution Approach 1:
The patent uses intermediary mechanisms (account linking information stored as federation metadata) to automate the migration process. This eliminates the need for administrators to manually manage complex link-breaking and re-establishing operations, reducing administrative time and effort while maintaining operational simplicity.
Solution Approach 2:
The system enables self-service migration by automatically processing identity provider transitions using pre-stored account linking information. The service provider can autonomously recognize and transfer user associations without requiring administrative intervention, thereby reducing administrative burdens and time losses.
3Device complexity
If user accounts are de-referenced during identity provider migration, then the migration process is simplified, but the user's actual identity and account history are lost
Solution Approach 1:
The patent implements copying by maintaining account linking information as federation metadata that preserves user identity references. Instead of de-referencing user accounts during migration, the system creates and maintains reference copies that allow the service provider to continue recognizing user identities across different identity providers, thereby preserving user identity information while simplifying the migration process.
4Adaptability or versatility
If federated enterprises interoperate to support federation protocols, then interoperability improves, but the operational burdens on users increase due to awareness of underlying mechanisms
Solution Approach 1:
The patent implements self-service by automatically handling federation protocol operations, account linking information management, and identity provider migration processes without requiring user awareness or intervention. Users benefit from improved interoperability between federated enterprises while experiencing no additional operational burden, as the system autonomously manages the underlying complex mechanisms.
Data Source
AI summary
A method is presented for performing an identity provider migration operation with respect to a user within a federated computational environment, wherein the user has a first user account at a first identity provider, a second user account at a second identity provider, and a third user account at a service provider. A request to access a resource is received by the service provider, after which a federated single-sign-on operation for the user is performed between the service provider and the first identity provider. Prior to sending a response to the request to access the protected resource, information in the third user account is modified to indicate that the service provider relies upon the second identity provider to authenticate the user on behalf of the service provider rather than the first identity provider. A response for the request to access the resource is then returned by the service provider.


