Unified Digital Identity Management System Abstraction Layer

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital identity management systems lack a unified approach, leading to complexity in interfacing and managing different types of digital identities across application programs, which complicates authentication, authorization, and encryption processes, especially in networked environments.

Innovation Solution

A common digital identity management system (DIMS) with an Application Programming Interface (API) layer abstracts multiple digital identity types, managing their lifecycles and providing a unified interface for authentication, authorization, and encryption, allowing seamless integration and management of digital identities across various applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If each application program manages digital identities independently using different techniques, then each application can implement its own security model, but the complexity of interfacing between application programs increases significantly

Engineering Contradiction:
Improveapplication-specific security modelVSAvoidinterface complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a common digital identity management system that acts as an intermediary layer between application programs and digital identity data. This mediator provides standardized interfaces while allowing applications to maintain their own security models, thus reducing interface complexity without sacrificing adaptability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a universal digital identity management system that can handle multiple types of digital identities (certificates, tokens, keys, assertions, credentials) through a single unified interface, eliminating the need for separate interface implementations for each identity type while maintaining application-specific security requirements

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If digital identities are stored in different locations with different protection methods, then each application can optimize security for its specific needs, but the difficulty of accessing data from prescribed locations increases

Engineering Contradiction:
Improvesecurity protectionVSAvoiddata access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The common digital identity management system serves as a mediator that centralizes access to digital identities stored in various locations with different protection methods. Applications interact with this single interface, which handles the complexity of locating and accessing protected data, thus maintaining high security while improving ease of operation

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the digital identity management functionality into distinct layers: storage and protection mechanisms remain separate and optimized for specific security needs, while a unified access layer provides simplified interfaces. This segmentation allows each component to be optimized independently without compromising overall system usability

Inventive Principle:
Principle #1Segmentation

3Reliability

If application programs must be aware of protection methods and prove validity at different locations, then security can be enforced at each access point, but the complexity of authentication and authorization processes increases

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The common digital identity management system acts as an intermediary that centralizes authentication and authorization logic. Applications no longer need to implement complex validity proofing at multiple locations; instead, the mediator system handles these operations uniformly, maintaining security while reducing process complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent merges分散ed authentication and authorization operations into a single unified process through the common digital identity management system. This consolidation maintains security enforcement while eliminating redundant validation steps across different access points, thereby reducing overall process complexity

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8151332B2Digital identity management
Publication Date: 2012.04.03 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8151332B2 patent drawing
  • US8151332B2 patent drawing
  • US8151332B2 patent drawing

AI summary

One aspect relates to a process and associated device for managing digital ID lifecycles for application programs, and abstracting application programs for multiple types of credentials through a common Digital Identity Management System (DIMS) and Application Programming Interface (API) layer.