Cross-Domain Security Context Projection via Portable References

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In multi-system computing environments with different security domains, existing technologies face challenges in facilitating cross-domain processing due to dissimilar runtime security contexts, requiring homogeneous configurations or incomplete security contexts, which hinder information technology consolidation and identity propagation.

Innovation Solution

A method is introduced where a local security manager in one security domain creates a runtime security context for a user in another domain, using security credentials provided, and sends a reference or portable representation of this context to enable seamless processing across domains, utilizing identity propagation and translation facilities to ensure accurate and efficient security context projection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a common user registry is shared across all systems, then user identity management becomes simplified, but each system and application must be rewritten to access the common registry, which is not workable in heterogeneous environments

Engineering Contradiction:
Improveuser identity managementVSAvoidsystem rewriting requirement
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary mechanism (security context projection facility) that translates security contexts between different domains without requiring direct access to a common registry. This mediator enables cross-domain authentication while preserving domain independence, avoiding the need to rewrite systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the security management architecture into independent domain-specific security contexts rather than forcing a unified registry. Each domain maintains its own security context locally, and the segmentation allows independent management while enabling cross-domain collaboration through context projection.

Inventive Principle:
Principle #1Segmentation

2Device complexity

If homogeneous security domain configurations are used, then cross-domain processing becomes simpler, but information technology consolidation is hindered

Engineering Contradiction:
Improvesecurity domain configurationVSAvoidinformation technology consolidation
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent changes the parameter of security context representation by introducing portable security context structures that can be transformed between different domain configurations. This allows heterogeneous domains to exchange security information without requiring homogeneous configurations, enabling IT consolidation while maintaining domain specificity.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent creates a universal security context projection mechanism that works across multiple domain types and configurations. The projection facility serves multiple functions: authenticating users across domains, translating security contexts, and enabling work transfer, thereby supporting diverse IT consolidations without requiring uniform domain structures.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If dissimilar runtime security contexts are used in different security domains, then domain-specific security requirements are met, but cross-domain processing is hindered

Engineering Contradiction:
Improvedomain-specific securityVSAvoidcross-domain processing
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent creates portable copies of security contexts that can be transported between domains. Instead of requiring direct access to domain-specific security databases, the system copies essential security context information into a portable format that can be used across domains, maintaining security reliability while enabling cross-domain processing productivity.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8627434B2Cross security-domain identity context projection within a computing environment
Publication Date: 2014.01.07 SERVICENOW INC
  • US8627434B2 patent drawing
  • US8627434B2 patent drawing
  • US8627434B2 patent drawing

AI summary

Processing within a computing environment is facilitated by: determining by a local security manager of a first system in a first security domain whether a local security context of a user is acceptable to a second system in a second security domain; responsive to the user's security context being unacceptable to the second system, creating by a local security manager of the second system a runtime security context for the user in the second system; and providing the first system with a reference to the runtime security context for the user in the second system which is resolvable within the computing environment or a portable representation of the runtime security context for the user in the second system, the reference or the portable representation being subsequently returned to the second system with a request from the first system to process work at the second system.