Identity Virtualization for Global Uniqueness Across Disparate Data Sources

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional systems face challenges in establishing globally unique identities across disparate data sources, leading to conflicts and ambiguity, which complicates policy enforcement and access control in networked environments, especially with the use of Network Address Translation (NAT) and Virtual Private Network (VPN) gateways obscuring true endpoint addresses.

Innovation Solution

The ID-Unify (IDU) system performs an iterative join operation across pre-existing data sources to generate a globally unique identifier, using identity virtualization and an Identisphere Manager (IM) for conflict resolution and normalization, enabling identity-based access control through a unified directory server and virtual directories.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional user identifiers are used in disparate systems, then each system can independently authenticate users, but conflicts and ambiguities arise when establishing globally unique identities across multiple data sources

Engineering Contradiction:
ImproveAbility to authenticate users across disparate systemsVSAvoidUniqueness and consistency of user identity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system segments the identity management problem by separating local user identifiers from global identity resolution. Each data source maintains its own user identifiers independently, while the iterative join operation segments the resolution process into discrete steps that progressively build global uniqueness without requiring centralized pre-coordination.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The iterative join operation implements a nested resolution mechanism where local identifiers are progressively nested within broader contextual frameworks. Each iteration nests additional data sources and their identifiers into the growing global identity picture, resolving conflicts at each nesting level before proceeding to the next.

Inventive Principle:
Principle #7Nested doll (Nesting)

2Reliability

If manual intervention is used to resolve identity conflicts, then accuracy can be maintained, but administrative complexity and time consumption increase significantly

Engineering Contradiction:
ImproveAccuracy of conflict resolutionVSAvoidAdministrative procedures and manual intervention requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary automated actions by executing iterative join operations that pre-resolve conflicts before they reach administrative personnel. The automated process prepares conflict-resolved identity mappings in advance, reducing the burden on administrators to manual intervention and allowing them to focus only on exceptional cases that require human judgment.

Inventive Principle:
Principle #10Preliminary action

3Object-affected harmful factors

If Network Address Translation and Virtual Private Network gateways are used, then network security and privacy are improved, but the true endpoint addresses are obscured making identity-based access control difficult

Engineering Contradiction:
ImproveNetwork security and endpoint privacyVSAvoidAbility to enforce access control policies
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The iterative join operation acts as an intermediary layer between the obscured network addresses and the access control policies. Instead of requiring direct visibility into true endpoint addresses, the system uses the iterative join to mediate identity resolution based on available identifiers, enabling access control enforcement without compromising network security measures.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8990910B2System and method using globally unique identities
Publication Date: 2015.03.24 CITRIX SYSTEMS INC
  • US8990910B2 patent drawing
  • US8990910B2 patent drawing
  • US8990910B2 patent drawing

AI summary

Systems and methods are described for creating a globally unique identity for a user or user-container by performing an iterative join where each participating back-end data source. The systems and methods include an ID-Unify (IDU) that performs identity virtualization and creates or generates a globally unique identifier for a user in operational environments in which there is a pre-existing conflict caused by the existence of different identities for a user in different authentication data sources.