Authorization Code Flow for Trusted Identity Attribute Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current online authentication methods lack security, consistency, and ease of use, with companies struggling to verify user identities effectively, leading to issues with password theft and invalid sign-ups.

Innovation Solution

A system utilizing identity attributes from trusted identity providers, such as banks, to authenticate users across multiple online platforms, leveraging cryptographic technology for secure and consistent identity verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional password-based authentication is used, then companies can implement authentication systems, but security is compromised due to password theft and invalid sign-ups

Engineering Contradiction:
Improveauthentication securityVSAvoidpassword theft and invalid sign-ups
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a trusted identity provider as an intermediary between users and companies. This identity provider issues digital identity credentials that companies can verify, eliminating the need for companies to directly handle and verify passwords. The intermediary (identity provider) specializes in secure identity verification, thereby improving authentication security while reducing password-related security vulnerabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If each company implements its own authentication system, then authentication can be performed, but consistency and ease of use deteriorate across different platforms

Engineering Contradiction:
Improveuser authentication convenienceVSAvoidcross-platform consistency
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal authentication system where a single digital identity credential issued by a trusted identity provider can be used across multiple companies and platforms. The identity credential is designed to be universally recognized and verified by any company participating in the system, providing both ease of use for users and consistency across different platforms without requiring separate authentication systems for each company.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If comprehensive identity verification is implemented, then authentication security is improved, but system complexity increases

Engineering Contradiction:
Improveidentity verification accuracyVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the complex identity verification functionality from individual company authentication systems and consolidates it into a specialized trusted identity provider. This extraction allows companies to use simple verification processes while the complex identity verification logic resides in the dedicated identity provider system, thereby improving verification accuracy without increasing the complexity of company authentication systems.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12469076B2Authorization code for access
Publication Date: 2025.11.11 EARLY WARNING SERVICES LLC
  • US12469076B2 patent drawing
  • US12469076B2 patent drawing
  • US12469076B2 patent drawing

AI summary

A method for sharing digital identity data, the method comprising, using the identity network, receiving an indication of consent from a user device to share a plurality of identity attributes with a relying party, wherein the plurality of identity attributes are associated with a user of the user device, generating an internal authorization code after receiving the consent, providing the internal authorization code to the user device, receiving the internal authorization code from the relying party, in response to receiving the internal authorization code, providing an internal access token to the relying party, receiving the internal access token from the relying party, and in response to receiving the access token, providing the plurality of identity attributes to the relying party.