Shared Identity Management Integration in Multi-Tenant Cloud Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Integration of tenant hierarchy information between shared identity management (IDM) systems and Nimbula systems is challenging due to differences in representation, making direct migration from one system to another complicated.

Innovation Solution

A method is described where a new tenant is created in a Nimbula system with a combined name from the shared IDM system, and the Nimbula system authenticates users and associates roles from the IDM system to determine access permissions, enabling seamless interaction and data transfer between the two systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a separate IDM system is implemented for each cloud tenant, then each tenant has dedicated identity management control, but computing resources are wasted due to duplication

Engineering Contradiction:
Improveidentity management controlVSAvoidcomputing resource waste
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent merges multiple tenant-specific IDM systems into a single shared IDM system that serves all tenants. The shared IDM system maintains separate identity domains for each tenant, allowing dedicated identity management control while eliminating the resource waste of duplication. This is achieved by consolidating authentication and authorization services into one system that can handle multiple tenants' identity requirements simultaneously.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The shared IDM system is segmented into multiple identity domains, with each domain dedicated to a specific tenant. This segmentation allows the system to maintain tenant-specific identity management control while operating within a single shared infrastructure. Each identity domain can be independently configured and managed, ensuring tenant isolation and control without requiring separate physical IDM systems.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If tenant hierarchy information is migrated directly between systems with different representations, then integration is achieved, but the migration process becomes complicated

Engineering Contradiction:
Improvesystem integrationVSAvoidmigration process complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The shared IDM system acts as an intermediary between tenants with different identity representation formats. It provides a standardized interface for identity management while accommodating various tenant-specific formats through identity domains. This mediator approach simplifies migration by handling format conversions and representation differences within the shared IDM framework, rather than requiring direct complex mappings between systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The shared IDM system provides universal identity management capabilities that work across multiple tenants with different representation formats. It implements a unified authentication and authorization framework that can handle various identity domain structures, making the migration process simpler by providing a single universal system rather than requiring tenant-specific customization for each migration scenario.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If cloud providers outsource hardware and software maintenance to cloud providers, then operational costs are reduced, but organizations lose control over their infrastructure

Engineering Contradiction:
Improveoperational cost efficiencyVSAvoidinfrastructure control
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The shared IDM system implements local quality by providing tenant-specific identity domains that give each organization control over their own identity management policies, authentication methods, and authorization rules. While the infrastructure is shared and managed by the cloud provider, each tenant maintains local control over their identity characteristics and security requirements through their dedicated identity domain within the shared system.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10372936B2Shared identity management (IDM) integration in a multi-tenant computing environment
Publication Date: 2019.08.06 ORACLE INT CORP
  • US10372936B2 patent drawing
  • US10372936B2 patent drawing
  • US10372936B2 patent drawing

AI summary

Techniques are disclosed for enabling tenant hierarchy information to be migrated directly between different multi-tenant system (e.g., from a shared IDM system to a Nimbula system, or vice versa). A corresponding new tenant is created in a Nimbula system based on a combination of the tenant information and the service information from the shared IDM system. The Nimbula system extracts the tenant name and the service name from a request and asks the shared IDM system to verify that the user actually is a member of the tenant identified by the extracted tenant name. Upon successful authentication of the user, the Nimbula system requests the IDM system for roles that are associated with both the user and the extracted service name. The Nimbula system enable access to the service upon determining whether the requested operation can be performed relative to the specified service based on the roles.