Unified Access Provider for Cross-Application Role Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cloud service providers face challenges in managing unified access and authorization for third-party software and applications, as existing protocols like OIDC and SAML lack uniformity and are not under the provider's control, leading to inconsistent user authentication and authorization management across different software and applications.
Innovation Solution
A method and system implemented by the cloud provider, utilizing a Unified Access provider and Policy Register, which populates user policies through an API, adapts user identity information based on approved roles and contextual conditions, and manages authentication and authorization via OIDC or SAML federation, ensuring centralized and uniform access management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If customers use their own identity providers with OIDC or SAML protocols for user authentication, then user authentication can be decentralized and flexible, but unified management of user authorizations and contextual information cannot be achieved across different software and applications
Solution Approach 1:
The cloud provider acts as an intermediary between the customer's identity provider and the hosted software applications. The provider receives authentication information from the identity provider via OIDC or SAML, then processes and standardizes the authorization data before forwarding it to applications. This intermediary role enables unified authorization management while preserving the flexibility of customer-chosen identity providers.
2Adaptability or versatility
If customers choose different identity providers for different departments or applications, then organizational flexibility is improved, but consistent authorization policies cannot be enforced across all users and applications
Solution Approach 1:
The cloud provider implements a universal authorization management system that works with multiple identity providers simultaneously. The system standardizes authorization data formats and enforcement mechanisms so that consistent policies can be applied across all users regardless of which identity provider they use. This multi-functional approach maintains organizational flexibility while ensuring policy consistency.
3Ease of operation
If the cloud provider does not control the identity provider architecture, then customer autonomy is preserved, but uniform management of contextual information and user roles cannot be implemented
Solution Approach 1:
The cloud provider's authorization service serves as a mediator layer between the customer's autonomous identity provider architecture and the hosted applications. This mediator receives various authorization formats from different identity providers, standardizes them according to unified policies, and distributes them to applications. This approach preserves customer autonomy while implementing uniform access management.
4Adaptability or versatility
If multiple identity providers are used across the organization, then user access flexibility is improved, but centralized management of user authorizations becomes difficult
Solution Approach 1:
The cloud provider implements a universal authorization management platform that can handle multiple identity providers through a single interface. The system provides centralized policy management, user role assignment, and contextual information tracking that works consistently across all identity providers. This multi-functional platform improves authorization management efficiency while maintaining user access flexibility.
Data Source
AI summary
There is disclosed a method and system for providing, by a cloud provider to a customer, a unified access by a user of the customer to a service provider hosted by the cloud provider, where the customer establishes a trusted relationship with an identity provider. An administrator populates a policy register with a first policy associated with a user. The service provider delegates the user authentication and authorization to a unified access provider. The unified access provider delegates the user authentication to the identify provider. The unified access provider receives user identify information authenticated by the identify provider. The unified access provider adapts the user identify information to include an approved role. The unified access provider sends the adapted user identify information to the service provider.


