Unified Identity Replication Across Cloud Regions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cloud infrastructure systems require separate accounts and credentials for customers subscribing to both SaaS/PaaS and IaaS services, leading to an unsatisfactory user experience and obstacles in interactions between these services due to the existence of two separate identity management systems.
Innovation Solution
A cloud infrastructure replication service that replicates domain data from an Identity Cloud Service (IDCS) control plane to the data plane and all subscribed regions, enabling seamless authentication and authorization across regions by generating replication logs and using a new API to transport changes, thus integrating IAM and IDCS platforms transparently to the user.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If two separate identity management systems (IAM for IaaS and IDCS for SaaS/PaaS) are provided, then each service can be independently managed and secured, but customers must maintain separate accounts and credentials, leading to poor user experience and increased operational complexity
Solution Approach 1:
The patent merges IAM and IDCS into a unified identity management system where a single account provides access to both IaaS and SaaS/PaaS services. The system combines the security frameworks of both platforms while maintaining their functional independence, allowing customers to use unified credentials across all services without sacrificing security.
Solution Approach 2:
The unified identity management system is designed to serve multiple functions: it provides authentication and authorization for both IaaS and SaaS/PaaS services, manages access to diverse resource types (compute instances, storage, networks, applications), and offers a single point of access for customers regardless of which services they subscribe to.
2Adaptability or versatility
If two separate identity management systems are used, then service independence and specialized security can be maintained, but interactions between SaaS/PaaS and IaaS services become obstructed
Solution Approach 1:
The system merges the identity management capabilities of IAM and IDCS while preserving the architectural independence of both services. The unified system enables seamless interactions between SaaS/PaaS and IaaS services through a common authentication and authorization framework, eliminating the barriers that previously existed between the two service ecosystems.
3Reliability
If domain data is replicated across multiple regions, then availability and reduced latency are improved, but system complexity and data synchronization overhead increase
Solution Approach 1:
The patent implements domain sharding to divide the unified identity management system into multiple independent domain shards that can be replicated across different regions. Each shard manages a specific portion of the identity data, allowing for parallel processing and independent replication while maintaining overall system coherence through the unified identity framework.
Solution Approach 2:
The system creates replicated copies of domain data across multiple regions using the unified identity management platform. The replication mechanism automatically synchronizes changes across domains while maintaining consistency through the integrated architecture, reducing manual intervention and simplifying the replication management process.
Data Source
AI summary
The present embodiments relate to a CI replication service that can replicate domain data from IDCS control plane to data plane and to all subscribed regions of a domain. For instance, the CI replication service can provide replication of required resources of a domain for AuthN and AuthZ from an IDCS local region to other regions for high availability (e.g., to improve latency). The CI replication service can replicate the resources from a domain's home region to all subscribed regions for local availability of data for workloads running in those regions. Further, when a new region is subscribed for a domain, then the service can bootstrap that domain's data from home region before enabling that region for the domain.


