Identity Synchronization Agent Across Disparate Domains

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing fragmentation, layering, and dispersion of identity management systems across multiple domains lead to cumbersome administration, conflicting behaviors, security gaps, additional labor, and costs due to incompatible systems, making it challenging to migrate identity information and maintain a secure and synchronized identity infrastructure.

Innovation Solution

A system and method for synchronizing identity information across identity domains, involving hardware processors configured by machine-readable instructions to identify and update identity data and metadata, allowing for seamless changes and migrations while ensuring compatibility with different domain requirements, using synchronizing and migration agents to manage identity data and metadata across disparate identity domains.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple disparate identity management systems are used across different domains, then each system can be optimized for its specific domain requirements, but the overall system complexity increases and administration becomes cumbersome

Engineering Contradiction:
Improvedomain-specific optimizationVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a synchronization agent as an intermediary component that mediates between multiple identity management domains. This agent establishes trust relationships and enables automatic synchronization of identity information across domains without requiring direct integration between each pair of systems, thereby reducing overall system complexity while maintaining domain-specific optimization

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The synchronization agent serves multiple functions including establishing trust relationships, synchronizing identity information, validating credentials, and managing security policies across different domains. This multi-functional approach consolidates what would otherwise require multiple separate components, reducing administrative burden while supporting diverse domain requirements

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If identity information is synchronized across multiple domains, then security consistency is improved, but the time and computational resources required for synchronization increase

Engineering Contradiction:
Improvesecurity consistencyVSAvoidsynchronization time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system establishes trust relationships and synchronization protocols in advance between domains. Identity information is pre-validating and pre-synchronized according to established policies, so that when synchronization is needed, the process is accelerated by previously configured trust frameworks and validation rules

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The synchronization agent operates periodically to update and validate identity information across domains rather than continuously. This periodic synchronization maintains security consistency while reducing computational overhead and time requirements compared to real-time synchronization, as changes are propagated at scheduled intervals

Inventive Principle:
Principle #19Periodic action

3Manufacturing precision

If manual migration of identity information between domains is performed, then data accuracy can be controlled, but labor costs and potential for errors increase

Engineering Contradiction:
Improvedata accuracyVSAvoidmigration efficiency
Core Design Contradiction:
Manufacturing precisionVSProductivity

Solution Approach 1:

The synchronization agent enables automatic self-service migration of identity information between domains. The system autonomously extracts, transforms, and loads identity data according to pre-configured synchronization rules and domain requirements, eliminating manual intervention while maintaining data accuracy through validated transformation processes

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements feedback mechanisms where the synchronization agent continuously monitors and validates migrated identity information. Any discrepancies or errors are automatically detected and corrected through iterative synchronization cycles, ensuring data accuracy while reducing manual review requirements

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11818114B2Systems, methods, and storage media for synchronizing identity information across identity domains in an identity infrastructure
Publication Date: 2023.11.14 RUBRIK INC
  • US11818114B2 patent drawing
  • US11818114B2 patent drawing
  • US11818114B2 patent drawing

AI summary

Systems, methods, and storage media for synchronizing identity information across identity domains in an identity infrastructure are disclosed. Exemplary implementations may: identify at least one of first identity data and first identity metadata in a first identity domain; identify at least one of second identity data and second identity metadata in a second identity domain; receive a request to change the at least one of the first identity data and the first identity metadata for at least one user; and update the at least one of second identity data and second identity metadata for the at least one user based on the request to change the at least one of the first identity data and the first identity metadata for the at least one user.