Universal Identity Governance via Virtual Data Modeling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current identity management systems face challenges in efficiently managing privileges across diverse applications, leading to compliance violations due to excess privileges and toxic combinations, and require multiple connectors and additional software layers for life cycle operations, which complicates data synchronization and governance.

Innovation Solution

A multi-layer approach for universal governance, where a governance layer handles object lifecycle for all entities, a governance entities layer represents information and tasks, and an application-specific layer models target applications, allowing for uniform governance and real-time translation of CRUD operations without data synchronization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional identity management systems use multiple connectors and software layers to manage privileges across diverse applications, then governance coverage is improved, but system complexity increases and data synchronization becomes difficult

Engineering Contradiction:
Improvegovernance coverageVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal governance layer that can manage multiple applications and data sources through a single unified interface. The system uses a common data model with standardized entities (User, Group, Role, Application, Entitlement) that can represent diverse application structures without requiring application-specific connectors. This multi-functional approach allows the same governance engine to handle different application types (SaaS, on-premise, cloud) uniformly, achieving broad governance coverage while maintaining low system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Stability of the object's composition

If traditional systems synchronize data across multiple applications, then data consistency is improved, but performance decreases due to synchronization overhead

Engineering Contradiction:
Improvedata consistencyVSAvoidsystem performance
Core Design Contradiction:
Stability of the object's compositionVSProductivity

Solution Approach 1:

The patent creates virtual copies of application data through its data model rather than maintaining actual synchronized copies. The governance layer represents application entities (users, roles, entitlements) as standardized objects that mirror the structure of various applications without physically duplicating or synchronizing the actual application data. This virtual copying approach maintains data consistency for governance purposes while avoiding the performance overhead of continuous data synchronization.

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If multiple connectors are used to integrate with different applications, then application compatibility is improved, but ease of operation deteriorates due to complex integration management

Engineering Contradiction:
Improveapplication compatibilityVSAvoidintegration management
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The system employs a universal data model that can represent various application types and structures through standardized entities. Instead of requiring separate connectors for different applications, the same governance engine and data model handle diverse applications (HR systems, CRM, ERP, SaaS applications) uniformly. This eliminates the need for complex connector management while maintaining broad application compatibility through flexible entity relationships and hierarchical structures.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3867786B1Universal governance
Publication Date: 2023.04.05 ORACLE INT CORP
  • EP3867786B1 patent drawingFigure 1
  • EP3867786B1 patent drawingFigure 2
  • EP3867786B1 patent drawingFigure 3

AI summary

Techniques for identity management, and more particularly, to techniques for performing universal identity management or governance over a wide variety of applications. In one aspect a computer-implement method is provided that includes receiving a request for a query of data or a CRUD operation on the data. The data is part of a target application hosted by an enterprise. The method further includes obtaining a schema of objects associated with the target application. The schema models a relationship between the objects, and the objects represent the data of the target application. The method further includes executing the query or CRUD operation on the objects based on the schema, executing the query or CRUD operation on the data based on the schema, and reporting results of the query or CRUD operation on the data.