Reverse Identity Federation for Cloud Resource Auditing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In distributed computing systems, existing federated identity-management systems fail to address user authorization and authentication challenges in new, higher-level distributed systems that allocate computational resources across multiple, separately managed systems, leading to issues with access control and auditing.

Innovation Solution

The implementation of reverse federated identity-management systems that automatically provision local proxy identities and record associations within distributed systems, enabling users to access allocated resources while allowing for detailed auditing and monitoring.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If federated identity-management systems are used to link local identities across multiple data centers, then user access to multiple systems is simplified, but new higher-level distributed systems cannot properly authorize and authenticate users accessing allocated computational resources

Engineering Contradiction:
Improveuser access to multiple systemsVSAvoidauthorization and authentication in higher-level distributed systems
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a reverse federated identity-management system that acts as an intermediary between higher-level distributed systems and remote distributed computer systems. This reverse federation mechanism provisions local proxy identities in remote systems on behalf of users, enabling proper authorization and authentication while maintaining user anonymity. The intermediary resolves the contradiction by creating a two-layer identity management structure where traditional federation handles user access simplicity and reverse federation handles resource allocation reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the identity management function into two distinct components: traditional federated identity management for user access across data centers, and reverse federated identity management for resource allocation authorization. This segmentation allows each component to specialize in its specific function, with the reverse federation layer specifically addressing the authorization needs of higher-level distributed systems without interfering with the operational simplicity provided by traditional federation.

Inventive Principle:
Principle #1Segmentation

2Productivity

If users access computational resources allocated by higher-level distributed systems, then resource utilization efficiency increases, but detailed auditing and monitoring of user actions become difficult

Engineering Contradiction:
Improveresource utilization efficiencyVSAvoidauditing and monitoring information
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The reverse federated identity-management system serves as an intermediary that preserves auditing and monitoring information while enabling efficient resource allocation. By provisioning local proxy identities and maintaining detailed logs of user actions in remote systems, the intermediary ensures that productivity is enhanced through automated resource allocation while auditing capabilities are preserved through comprehensive logging of all user interactions with allocated resources.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates local proxy identities as copies of user identities in remote distributed computer systems. These proxy identities enable users to access allocated resources efficiently while the reverse federated identity-management system maintains detailed logs and associations between users and their actions. The copying mechanism allows resource utilization efficiency to improve through automated access while auditing information is preserved through the logging of proxy identity actions.

Inventive Principle:
Principle #26Copying

3Reliability

If reverse federated identity-management systems provision local proxy identities automatically, then user anonymity is maintained, but system complexity increases

Engineering Contradiction:
Improveuser anonymity and securityVSAvoididentity management system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The reverse federated identity-management system operates autonomously to provision local proxy identities automatically without requiring manual intervention. The system self-manages the creation, association, and management of proxy identities in remote distributed computer systems, thereby maintaining user anonymity while minimizing the operational complexity burden on administrators. The automated nature of the system reduces the effective complexity experienced by users and operators.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10986098B2Reverse identity federation in distributed cloud systems
Publication Date: 2021.04.20 VMWARE INC
  • US10986098B2 patent drawing
  • US10986098B2 patent drawing
  • US10986098B2 patent drawing

AI summary

The current document is directed to reverse federated identity-management systems and to reverse-federated-identity-management methods employed by the reverse federated identity-management systems. The currently disclosed reverse-federated-identity-management systems automatically provision local proxy identities in distributed computers systems from which distributed resource-distribution systems allocate resources on behalf of users and clients of the distributed resource-distribution systems. In addition, the currently disclosed reverse-federated-identity-management systems automatically record associations of local proxy identities with users and clients of the distributed resource-distribution systems so that the users can be subsequently identified to auditing and monitoring organizations should the need for detailed auditing and monitoring subsequently arise.