Identity Virtualization for Global Uniqueness Across Disparate Data Sources
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional systems face challenges in establishing globally unique identities across disparate data sources, leading to conflicts and ambiguity, which complicates policy enforcement and access control in networked environments, especially with the use of Network Address Translation (NAT) and Virtual Private Network (VPN) gateways obscuring true endpoint addresses.
Innovation Solution
The ID-Unify (IDU) system performs an iterative join operation across pre-existing data sources to generate a globally unique identifier, using identity virtualization and an Identisphere Manager (IM) for conflict resolution and normalization, enabling identity-based access control through a unified directory server and virtual directories.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If conventional user identifiers are used in disparate systems, then each system can independently authenticate users, but conflicts and ambiguities arise when establishing globally unique identities across multiple data sources
Solution Approach 1:
The system segments the identity management problem by separating local user identifiers from global identity resolution. Each data source maintains its own user identifiers independently, while the iterative join operation segments the resolution process into discrete steps that progressively build global uniqueness without requiring centralized pre-coordination.
Solution Approach 2:
The iterative join operation implements a nested resolution mechanism where local identifiers are progressively nested within broader contextual frameworks. Each iteration nests additional data sources and their identifiers into the growing global identity picture, resolving conflicts at each nesting level before proceeding to the next.
2Reliability
If manual intervention is used to resolve identity conflicts, then accuracy can be maintained, but administrative complexity and time consumption increase significantly
Solution Approach 1:
The system performs preliminary automated actions by executing iterative join operations that pre-resolve conflicts before they reach administrative personnel. The automated process prepares conflict-resolved identity mappings in advance, reducing the burden on administrators to manual intervention and allowing them to focus only on exceptional cases that require human judgment.
3Object-affected harmful factors
If Network Address Translation and Virtual Private Network gateways are used, then network security and privacy are improved, but the true endpoint addresses are obscured making identity-based access control difficult
Solution Approach 1:
The iterative join operation acts as an intermediary layer between the obscured network addresses and the access control policies. Instead of requiring direct visibility into true endpoint addresses, the system uses the iterative join to mediate identity resolution based on available identifiers, enabling access control enforcement without compromising network security measures.
Data Source
AI summary
Systems and methods are described for creating a globally unique identity for a user or user-container by performing an iterative join where each participating back-end data source. The systems and methods include an ID-Unify (IDU) that performs identity virtualization and creates or generates a globally unique identifier for a user in operational environments in which there is a pre-existing conflict caused by the existence of different identities for a user in different authentication data sources.


