Identity Session Abstraction Layer for Multi-Domain Cloud Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The fragmentation and dispersion of identity management systems across multiple third-party cloud services create a cumbersome environment for administrators, making it difficult to effectively manage and enforce identity sessions across disparate identity domains.

Innovation Solution

A system that enables identity session abstraction, allowing different identity management systems to passively provide identity session information to protected resources without pre-configuration, using discovery agents to detect and assess the identity infrastructure and connecting agents to manage and transform identity data across domains, ensuring seamless access and enforcement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple third-party identity management systems are used across cloud services, then service functionality and adaptability are improved, but system complexity and administrative burden increase

Engineering Contradiction:
Improveservice functionalityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces an identity session abstraction layer that acts as an intermediary between multiple identity management systems and protected resources. This abstraction layer receives identity session information from various identity domains, standardizes the data format, and presents a unified interface to applications, thereby reducing system complexity while maintaining support for multiple identity management systems

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a universal identity session abstraction mechanism that can handle identity session information from multiple different identity management systems through a single standardized interface. This multi-functional approach allows the system to work with various identity domains without requiring separate integration mechanisms for each system

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Productivity

If identity session information is passed across disparate identity domains, then access efficiency is improved, but security risks and enforcement difficulty increase

Engineering Contradiction:
Improveaccess efficiencyVSAvoidsecurity enforcement
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The abstraction layer serves as a security intermediary that validates and standardizes identity session information before passing it to protected resources. It implements security policies, verifies session validity, and ensures proper authentication credentials are present, thereby maintaining security enforcement while enabling efficient cross-domain access

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transforms identity session information from various identity domains into a standardized parameter format. This parameter transformation includes normalizing user identifiers, session tokens, and authentication credentials into a common structure that maintains security requirements while enabling seamless access across different identity systems

Inventive Principle:
Principle #35Parameter changes

3Reliability

If pre-configuration is required for identity domain integration, then system reliability is improved, but implementation time and complexity increase

Engineering Contradiction:
Improvesystem reliabilityVSAvoidimplementation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements automatic discovery mechanisms that allow the identity session abstraction layer to self-configure by detecting available identity domains and their capabilities without requiring manual pre-configuration. The system automatically establishes communication channels and adapts to different identity domain protocols, reducing implementation time while maintaining reliable integration

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11876796B2Systems, methods, and storage media for abstraction and enforcement in an identity infrastructure
Publication Date: 2024.01.16 RUBRIK INC
  • US11876796B2 patent drawing
  • US11876796B2 patent drawing
  • US11876796B2 patent drawing

AI summary

Systems, methods, and storage media for abstraction and enforcement of protected resources in an identity infrastructure are disclosed. Exemplary implementations may: identify one or more protected resources for one or more identity domains of an identity infrastructure; receive, at the identity infrastructure, a dataflow pertaining to first identity data for a first identity domain; request the first identity session based at least in part on the first identity data; receive a request to access a first protected resource of the one or more protected resources; accept the first identity session by the first protected resource; and provide the first user access to the first protected resource.