Centralized Identity Management Server for Multi-Entity Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing identity assurance systems lack a centralized and secure method to manage and authenticate identities across multiple entities, leading to inefficiencies and increased computational burdens on individual devices.

Innovation Solution

An identity management server device that centrally manages identities by establishing, authenticating, and authorizing access for individuals across multiple entities, reducing the need for direct communication between entities and offloading identity authentication functions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a centralized identity management server is implemented, then identity management efficiency and security are improved, but device complexity increases

Engineering Contradiction:
Improveidentity management securityVSAvoidsystem structure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a centralized identity management server as an intermediary between users and multiple service providers. This server handles all identity authentication and management operations, eliminating the need for direct communication between users and multiple service provider identity systems. The server acts as a mediator that receives authentication requests, verifies identities against stored credentials, and returns authentication results, thereby centralizing security management while simplifying the overall system architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If multiple entities directly communicate for identity authentication, then communication overhead increases, but using a centralized server reduces communication efficiency

Engineering Contradiction:
Improveidentity authentication efficiencyVSAvoidauthentication time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent merges multiple service provider identity systems into a single centralized identity management server. Instead of having separate authentication systems at each service provider, all identity verification operations are consolidated at one location. This consolidation eliminates redundant authentication processes and allows the system to leverage previously performed authentication results, significantly improving authentication efficiency and reducing the time required for identity verification across multiple entities.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If each entity stores identity information locally, then data security is improved, but computational resources and storage capacity are consumed

Engineering Contradiction:
Improveidentity data securityVSAvoidcomputational resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts identity information storage and management functions from individual service providers and consolidates them at a centralized identity management server. Each service provider no longer needs to store or process sensitive identity data locally, as all authentication requests are handled by the centralized server that maintains the authoritative identity database. This extraction eliminates redundant storage and computational overhead at distributed locations while maintaining security through centralized control.

Inventive Principle:
Principle #2Taking out (Extraction)

4Measurement precision

If knowledge-based authentication is used, then identity verification capability is improved, but vulnerability to attacks increases

Engineering Contradiction:
Improveidentity verification accuracyVSAvoidauthentication attack vulnerability
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary authentication actions by verifying user identities against stored credentials in the centralized database before granting access to services. The system performs authentication challenges in advance, such as requiring users to provide security answers or verify biometric data, and stores the results. This preliminary verification ensures that only authenticated users can access services, preventing unauthorized access attempts and reducing vulnerability to attacks by establishing identity assurance before any sensitive operations occur.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11336634B2Identity management via a centralized identity management server device
Publication Date: 2022.05.17 VERIZON PATENT & LICENSING INC
  • US11336634B2 patent drawing
  • US11336634B2 patent drawing
  • US11336634B2 patent drawing

AI summary

A device can establish an identity for an individual by communicating with a first set of devices. The first set of devices can include a user device, a first server device associated with a certificate authority, or a second server device associated with an identity provider. The device can authenticate the identity of the individual by communicating with a second set of devices. The second set of devices can include the user device, or a third server device associated with a first service provider. The device can authorize the identity of the individual to be used by one or more service providers by communicating with a third set of devices. The third set of devices can include the user device, the third server device, or a fourth server device associated with a second service provider.