Identity Management System Automating Entitlement Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise systems face challenges in effectively managing user identities and access to resources across multiple target systems, leading to complexities in provisioning and managing entitlements.

Innovation Solution

An Identity Management (IDM) system is introduced to unify and integrate security, enabling automated provisioning of resources and managing entitlements by identifying and synchronizing accounts, roles, and dependencies within the system, allowing users to request resources and receive appropriate access permissions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If automated provisioning is implemented to streamline user access management, then productivity and ease of operation are improved, but device complexity and system integration requirements increase

Engineering Contradiction:
Improveuser access management efficiencyVSAvoidsystem integration complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

An identity management system is introduced as an intermediary component between users and multiple target systems. This mediator handles account identification, dependency resolution, and entitlement provisioning automatically, reducing the complexity burden from the overall system while improving access management productivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary actions by pre-identifying required accounts and resolving dependencies before actual resource provisioning. This advance preparation automates the provisioning workflow, enhancing productivity while containing complexity through structured pre-processing.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If multiple target systems are integrated to provide comprehensive resource access, then adaptability and versatility are improved, but device complexity and management difficulty increase

Engineering Contradiction:
Improveresource access capabilityVSAvoidsystem management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The identity management system is designed with universal functionality to work across multiple different target systems. It provides a unified interface for account identification, entitlement management, and dependency resolution that adapts to various system types, enhancing versatility while maintaining consistent management procedures.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system segments the complex task of multi-system integration into distinct functional modules: target system connection management, account identification, dependency resolution, and entitlement provisioning. This modular approach reduces management complexity by organizing complexity into manageable segments.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If dependency relationships between accounts are automatically resolved, then ease of operation is improved, but measurement precision and detection difficulty increase

Engineering Contradiction:
Improveprovisioning process simplicityVSAvoiddependency relationship complexity
Core Design Contradiction:
Ease of operationVSDifficulty of detecting and measuring

Solution Approach 1:

The system implements feedback mechanisms that automatically detect account dependencies by analyzing entitlement requirements and system relationships. This automated detection provides feedback loops that resolve dependencies without user intervention, improving ease of operation while systematically handling the detection complexity through iterative analysis.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9723025B2Dependent entity provisioning
Publication Date: 2017.08.01 ORACLE INT CORP
  • US9723025B2 patent drawing
  • US9723025B2 patent drawing
  • US9723025B2 patent drawing

AI summary

A method and system for managing entitlements provided by a target system in an organization is provided. In one embodiment, a user of an organization may utilize services provided by an identity management system to request for resources stored in one or more target systems of the organization. Upon receiving the request, the identity management system may identify if an account is associated with the user that enables the user access to the resource in one of the target systems. In some examples, the identity management system may provision a new account for the user, associate the new account with the user and grant an entitlement to the new account, wherein the entitlement enables the user to access the requested in the target system.