Multi-tenant Identity Management System with Domain Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud computing environments, existing identity management systems often require separate instances for each organization, leading to duplicative efforts and wasteful use of resources, as they fail to efficiently manage and isolate identities across multiple tenants.

Innovation Solution

A multi-tenant identity management system is implemented, where a single identity management system is partitioned into multiple separate identity domains, using virtualization to provide a dedicated view for each tenant, ensuring isolation and efficient resource utilization by sharing infrastructure across tenants.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate identity management systems are implemented for each organization, then security isolation and organizational autonomy are improved, but resource utilization efficiency and system density deteriorate

Engineering Contradiction:
Improvesecurity isolationVSAvoidresource utilization efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Multiple separate identity management systems are merged into a single multi-tenant system that serves multiple organizations simultaneously. The system combines security isolation mechanisms with resource sharing, allowing each tenant to have dedicated identity domains while sharing the underlying infrastructure, thus improving both security isolation and resource utilization efficiency

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The identity management system is designed with multi-functionality to serve multiple organizations across different identity domains. A single system instance provides identity management services to multiple tenants through virtualization and multi-tenancy capabilities, eliminating the need for separate dedicated systems while maintaining organizational autonomy and security requirements

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Productivity

If a single shared identity management system is used, then resource utilization efficiency and cost-effectiveness are improved, but security isolation and organizational autonomy deteriorate

Engineering Contradiction:
Improveresource utilization efficiencyVSAvoidsecurity isolation
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The single identity management system is segmented into multiple isolated identity domains, each dedicated to a specific organization or tenant. This segmentation creates logical boundaries that ensure security isolation while allowing the underlying infrastructure to be shared, thus maintaining both resource efficiency and security requirements

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An intermediary layer of virtualization and multi-tenancy management is introduced between the shared infrastructure and individual tenants. This intermediary ensures that each tenant experiences dedicated, isolated services while actually sharing the underlying resources, thereby maintaining security isolation without sacrificing resource utilization efficiency

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If separate identity management systems are deployed for each tenant, then organizational autonomy and security control are improved, but system complexity and deployment overhead increase

Engineering Contradiction:
Improveorganizational autonomyVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

A universal identity management platform is designed to handle multiple organizations and identity domains within a single deployment. The system provides configurable multi-tenancy capabilities that allow each organization to maintain autonomy and custom configurations without requiring separate system deployments, thus reducing complexity while preserving organizational versatility

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10581867B2Multi-tenancy identity management system
Publication Date: 2020.03.03 ORACLE INT CORP
  • US10581867B2 patent drawing
  • US10581867B2 patent drawing
  • US10581867B2 patent drawing

AI summary

A multi-tenant identity management (IDM) system enables IDM functions to be performed relative to various different customers' domains within a shared cloud computing environment and without replicating a separate IDM system for each separate domain. The IDM system can provide IDM functionality to service instances located within various different customers' domains while enforcing isolation between those domains. A cloud-wide identity store can contain identity information for multiple customers' domains, and a cloud-wide policy store can contain security policy information for multiple customers' domains. The multi-tenant IDM system can provide a delegation model in which a domain administrator can be appointed for each domain, and in which each domain administrator can delegate certain roles to other user identities belong to his domain. Service instance-specific administrators can be appointed by a domain administrator to administer to specific service instances within a domain.