Distributed Network Identity Architecture for Single Sign-On

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional identity frameworks in network-based services require users to create multiple accounts and authenticate separately for each service provider, leading to user inconvenience and privacy concerns, while centralized identity methods may compromise privacy and security.

Innovation Solution

A distributed network identity architecture that allows users to store identity information with multiple identity providers, enabling single sign-on, account linking, and service delegation, with enforceable privacy controls and trust chains to manage data access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If users create separate accounts for each service provider, then each service provider can maintain its own customer database and control, but users must repeatedly enter identity information and manage multiple passwords

Engineering Contradiction:
Improveservice provider controlVSAvoiduser convenience
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent segments the centralized identity system into distributed identity providers (IdPs) and service providers (SPs). Each IdP manages specific identity information for users, while SPs access only the portions they need through federated authentication. This segmentation allows users to have their identity information distributed across multiple trusted providers rather than consolidated in a single centralized database, thereby improving security and privacy while maintaining ease of use through single sign-on capabilities.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If a centralized authority stores and manages user identity data, then users experience single sign-on convenience, but privacy and security are compromised due to centralized data storage

Engineering Contradiction:
Improvesingle sign-on convenienceVSAvoidprivacy and security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements local quality by allowing different identity providers to store and manage different portions of user identity information based on local trust relationships and security requirements. Each IdP maintains control over its own data with appropriate security measures, rather than all data being stored centrally. This enables single sign-on convenience while distributing security risks and maintaining user privacy through selective data sharing.

Inventive Principle:
Principle #3Local quality

3Reliability

If identity information is distributed across multiple providers, then privacy and security are enhanced, but system complexity increases

Engineering Contradiction:
Improveprivacy and securityVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements universality through the Federation of Identity Providers (FedID) architecture, which provides a universal interface and protocol for authentication across multiple distributed identity providers. The FedID acts as a multi-functional intermediary that can work with any compliant IdP and SP, standardizing the authentication process and reducing the complexity that would otherwise arise from implementing custom integration between each pair of providers. This universal framework simplifies the system architecture while maintaining the security benefits of distributed identity management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Adaptability or versatility

If service providers access centralized identity data, then they can provide personalized services, but user privacy preferences may be violated through data sharing

Engineering Contradiction:
Improvepersonalized service capabilityVSAvoidprivacy violation risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamics by making the data sharing relationships between identity providers and service providers dynamic and configurable based on user preferences and contextual factors. Users can dynamically control which portions of their identity information are shared with which service providers, and these permissions can be adjusted over time. This dynamic approach enables service providers to access the specific data needed for personalized services while respecting user privacy preferences, as the data sharing arrangement adapts to user choices rather than being static.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS7610390B2Distributed network identity
Publication Date: 2009.10.27 ORACLE AMERICAN INC
  • US7610390B2 patent drawing
  • US7610390B2 patent drawing
  • US7610390B2 patent drawing

AI summary

A distributed network identity is provided. An identity provider stores a portion of a user's personal information. A service provider accesses user information from one or more identity providers. System entities such as identity providers and service providers can be linked to enable information sharing and aggregation. User policies and privacy preferences are provided to control how information is shared. A single sign-on architecture is provided where an identity provider is used to facilitate cross-domain authentication and to enhance user convenience. Service delegation features are also provided.