Unified Identity Cloud Directory for Cross-Platform Authorization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managing identity and access privileges across multiple cloud platforms is burdensome and complex, leading to security vulnerabilities and inefficiencies for organizations with large workforces and numerous applications.
Innovation Solution
A software platform that unifies multiple identity clouds by automating the registration and integration of applications, using a directory to authorize requests based on user credentials and an authorization model, supporting features like single-sign-on and identity governance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If conventional IGA tools are used to manage identity and access privileges, then some identity management functions can be performed, but the tools are deficient or sub-optimal for unified multi-cloud identity management
Solution Approach 1:
The patent merges multiple cloud identity platforms (first cloud platform and second cloud platform) into a unified identity cloud architecture. The software platform integrates identity governance, authorization models, and credential verification across both cloud platforms, eliminating the need to manage separate identity systems and reducing overall system complexity while improving adaptability.
Solution Approach 2:
The software platform provides universal identity management capabilities that work across multiple cloud platforms. The authorization model and directory service are designed to be platform-agnostic, enabling the same system to manage identities, credentials, and access privileges across diverse cloud environments simultaneously.
2Adaptability or versatility
If multiple separate cloud platforms are used for identity management, then flexibility and platform choice are improved, but managing access privileges becomes burdensome and complex
Solution Approach 1:
The software platform acts as an intermediary layer between the first cloud platform and second cloud platform. It provides a unified directory service and authorization model that mediates access requests across both platforms, simplifying privilege management while preserving the flexibility to use multiple cloud providers.
Solution Approach 2:
The patent segments the identity management system into distinct functional components: credential verification (handled by the directory service), authorization model definition, and access privilege management. This segmentation allows each component to operate independently across different cloud platforms while maintaining ease of operation through centralized coordination.
3Reliability
If centralized authorization is implemented across multiple cloud platforms, then security and access control are improved, but system complexity and integration difficulty increase
Solution Approach 1:
The software platform performs preliminary actions by pre-defining authorization models and credential verification rules in the unified directory service. These authorization models are established beforehand and automatically applied across both cloud platforms, ensuring consistent security controls without requiring complex real-time integration logic.
Solution Approach 2:
The patent implements homogeneous authorization mechanisms across both cloud platforms through the unified directory service. The same credential verification process and authorization model structure are applied consistently to both the first cloud platform and second cloud platform, simplifying integration while maintaining strong security controls.
4Ease of operation
If manual identity and access management is performed, then fine-grained control is achieved, but time consumption and operational burden increase significantly
Solution Approach 1:
The software platform enables self-service identity and access management through automated credential verification and authorization model application. The directory service automatically verifies credentials and applies appropriate access privileges based on pre-defined authorization models, reducing manual intervention time while maintaining fine-grained control over access permissions.
Solution Approach 2:
The system implements feedback mechanisms where the directory service continuously verifies credentials and adjusts access privileges based on authorization model evaluations. This automated feedback loop ensures precise access control decisions are made rapidly without manual intervention, reducing management time while maintaining operational precision.
Data Source
AI summary
Methods, systems, and devices for unifying multiple identity clouds are described. A software platform may receive a first request from a first user to build an authorization model for a resource using a first cloud platform. The authorization model may identify parameters associated with accessing the resource. The software platform may receive, from the first user, a second request to integrate the resource with a second cloud platform in accordance with the authorization model. The software platform may authorize the first request and the second request using a directory associated with the software platform. The software platform may receive a third request from a second user to access the resource using the second cloud platform. The software platform may authorize the third request using the directory. Authorization of the third request may be performed accordance to the authorization model and based on a second credential associated with the second user.


