Decentralized Identity Management via Managed Service Provider

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in managing complex identity lifecycles and authorization processes due to the complexity of internal identity management, lack of external trusted identifiers, and the need for simplified role and claim set assignments.

Innovation Solution

A managed service provider offers authentication and authorization lifecycle services using verified credentials and decentralized identifiers, enabling external identity management, credential lifecycle management, and standardized claim templates to simplify authorization processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If organizations manage identity internally using centralized platforms, then authentication and authorization can be performed, but the complexity of identity lifecycle management increases and requires specialized skills

Engineering Contradiction:
Improveauthentication securityVSAvoididentity management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts identity management functions from internal organizational systems and relocates them to external managed service providers. The identity provider (IDP) system separates credential verification, authorization decision-making, and lifecycle management from the target organization's internal operations, allowing the organization to maintain authentication security while eliminating the operational complexity of managing these functions internally.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary identity provider system that acts as a mediator between the target organization and users/devices. This IDP system handles authentication requests, credential verification, and authorization decisions, serving as a buffer that reduces the direct complexity burden on the target organization while maintaining secure access control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If standardized authorization roles are implemented, then authorization processes become simpler, but flexibility in defining application-specific roles is reduced

Engineering Contradiction:
Improveauthorization simplicityVSAvoidrole definition flexibility
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic role templates that can be configured and customized by the target organization. The IDP system provides pre-defined standardized role templates for common scenarios, but allows organizations to modify these templates and create custom roles based on their specific application requirements. This dynamic configuration capability enables the system to adapt to different organizational needs while maintaining the simplicity of standardized approaches.

Inventive Principle:
Principle #15Dynamics

3Productivity

If external identity management is implemented, then organizations can relieve internal operations of complexity, but securing trusted identifiers external to the organization becomes difficult

Engineering Contradiction:
Improveoperational efficiencyVSAvoidexternal identifier trust
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements a universal credential structure that can be used across multiple applications and organizations. The verified credential format and decentralized identifier system are designed to be organization-agnostic, allowing the same external IDP system to securely manage identifiers for multiple target organizations. This universality is achieved through standardized claim templates and a portable credential architecture that maintains security while enabling external management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20240348608A1Identity Proofing and Standardized Authorization
Publication Date: 2024.10.17 HOWELL DAVID
  • US20240348608A1 patent drawing
  • US20240348608A1 patent drawing
  • US20240348608A1 patent drawing

AI summary

Identity proofing and standardized authorization that enables a managed service provider, or any external organization, to provide authentication and authorization services to a target organization based on verified credentials connected to decentralized identifiers. The managed service provider issues verified credentials to the target organization's entities and handles entity onboarding, device credential enrollment, device credential re-enrollment, entity offboarding and device credential disablement. The target organization uses the managed service provider's verified credentials as the primary authentication credential to authenticate entities and to access claims carried in the credential. The decentralized nature of the entity identifiers allows for a separation of identity management duties between the managed service and the target organization. Claim templates are also outlined that allow for the inclusion of standardized claims in the verified credential. These claim templates are improved over time based on learning from the ecosystem of organizations that rely on the service provider.