Automated Digital Identity Representation Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current digital identity systems require manual creation and provisioning of digital identity representations (DIRs) by administrators, leading to ad-hoc, error-prone, and security-vulnerable processes that are labor-intensive.

Innovation Solution

A system and method for automating the provisioning of DIRs, involving a DIR generation system, an identity provider, and an identity data store, where the DIR generation system accesses the identity data store to create DIRs and the identity provider generates identity tokens, with features like authentication, descriptor generation, and synchronization with data availability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If administrators manually create and provision DIRs using software utilities, then DIRs can be created and saved to specific locations, but the process becomes labor-intensive, error-prone, and security-vulnerable

Engineering Contradiction:
Improveease of DIR creationVSAvoidadministrator workload
Core Design Contradiction:
Ease of manufactureVSProductivity

Solution Approach 1:

The system enables principals to self-provision their own DIRs by automatically generating them based on information from identity providers, eliminating the need for administrator intervention in the DIR creation process while maintaining security through automated validation

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system pre-configures DIR templates and identity provider connections in advance, so that when principals need DIRs, they are automatically generated from pre-established configurations rather than being manually created from scratch

Inventive Principle:
Principle #10Preliminary action

2Manufacturing precision

If administrators manually craft DIRs, then DIRs can be created with specific claims information, but the process is subject to errors and security vulnerabilities

Engineering Contradiction:
ImproveDIR accuracyVSAvoidsecurity vulnerability
Core Design Contradiction:
Manufacturing precisionVSReliability

Solution Approach 1:

The system introduces an automated DIR generation service as an intermediary between principals and identity providers, which validates and sanitizes all DIR content according to security policies, eliminating manual crafting errors and security vulnerabilities

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements automated validation feedback loops that check DIR content against security policies and data schemas before issuance, immediately identifying and correcting errors or security issues rather than allowing them to propagate

Inventive Principle:
Principle #23Feedback

3Ease of operation

If administrators send pointers to DIRs and principals retrieve them, then DIR distribution can be achieved, but the ad-hoc process is labor-intensive and insecure

Engineering Contradiction:
ImproveDIR distribution simplicityVSAvoidsecurity and error-proneness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system separates DIR creation, validation, and distribution into distinct automated stages handled by different system components, allowing each stage to be optimized for security and reliability while maintaining overall process simplicity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The automated DIR generation service provides universal functionality for all principals, handling DIR creation, validation, and distribution through a single standardized process that works for all identity providers and principal types

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Adaptability or versatility

If manual DIR provisioning is used, then administrators have control over DIR creation, but the process is not synchronized with actual data availability

Engineering Contradiction:
ImproveDIR customizationVSAvoidsynchronization delay
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system implements real-time feedback mechanisms that monitor data availability in identity providers and automatically trigger DIR generation or updates when data becomes available, eliminating synchronization delays while maintaining adaptability to different data sources

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system makes the DIR provisioning process dynamic by automatically adjusting generation timing and content based on real-time data availability from identity providers, rather than following static manual schedules

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP2109955B1Provisioning of digital identity representations
Publication Date: 2016.07.20 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP2109955B1 patent drawingFigure 1
  • EP2109955B1 patent drawingFigure 2
  • EP2109955B1 patent drawingFigure 3

AI summary

A system and method for provisioning digital identity representations ("DIRs") uses various techniques and structures to ease administration, increase accuracy, and decrease inconsistencies of a digital-identity provisioning system. A system is provided using a common identity data store for both DIR issuance and identity token issuance, decreasing synchronization issues. Various methods are provided for creating new DIRs, notifying principals of available DIRs, and approving issuance of new DIRs.