Distributed Network Identity Architecture for Single Sign-On
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional identity frameworks in network-based services require users to create multiple accounts and authenticate separately for each service provider, leading to user inconvenience and privacy concerns, while centralized identity methods may compromise privacy and security.
Innovation Solution
A distributed network identity architecture that allows users to store identity information with multiple identity providers, enabling single sign-on, account linking, and service delegation, with enforceable privacy controls and trust chains to manage data access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If users create separate accounts for each service provider, then each service provider can maintain its own customer database and control, but users must repeatedly enter identity information and manage multiple passwords
Solution Approach 1:
The patent segments the centralized identity system into distributed identity providers (IdPs) and service providers (SPs). Each IdP manages specific identity information for users, while SPs access only the portions they need through federated authentication. This segmentation allows users to have their identity information distributed across multiple trusted providers rather than consolidated in a single centralized database, thereby improving security and privacy while maintaining ease of use through single sign-on capabilities.
2Ease of operation
If a centralized authority stores and manages user identity data, then users experience single sign-on convenience, but privacy and security are compromised due to centralized data storage
Solution Approach 1:
The patent implements local quality by allowing different identity providers to store and manage different portions of user identity information based on local trust relationships and security requirements. Each IdP maintains control over its own data with appropriate security measures, rather than all data being stored centrally. This enables single sign-on convenience while distributing security risks and maintaining user privacy through selective data sharing.
3Reliability
If identity information is distributed across multiple providers, then privacy and security are enhanced, but system complexity increases
Solution Approach 1:
The patent implements universality through the Federation of Identity Providers (FedID) architecture, which provides a universal interface and protocol for authentication across multiple distributed identity providers. The FedID acts as a multi-functional intermediary that can work with any compliant IdP and SP, standardizing the authentication process and reducing the complexity that would otherwise arise from implementing custom integration between each pair of providers. This universal framework simplifies the system architecture while maintaining the security benefits of distributed identity management.
4Adaptability or versatility
If service providers access centralized identity data, then they can provide personalized services, but user privacy preferences may be violated through data sharing
Solution Approach 1:
The patent implements dynamics by making the data sharing relationships between identity providers and service providers dynamic and configurable based on user preferences and contextual factors. Users can dynamically control which portions of their identity information are shared with which service providers, and these permissions can be adjusted over time. This dynamic approach enables service providers to access the specific data needed for personalized services while respecting user privacy preferences, as the data sharing arrangement adapts to user choices rather than being static.
Data Source
AI summary
A distributed network identity is provided. An identity provider stores a portion of a user's personal information. A service provider accesses user information from one or more identity providers. System entities such as identity providers and service providers can be linked to enable information sharing and aggregation. User policies and privacy preferences are provided to control how information is shared. A single sign-on architecture is provided where an identity provider is used to facilitate cross-domain authentication and to enhance user convenience. Service delegation features are also provided.


