Federated Identity Management via Identifier Masking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing identity management systems in e-business fail to effectively share user personalization information and mask user identities across different service providers, leading to privacy concerns and monopolistic risks for service providers like telecommunication and banking.

Innovation Solution

A system and method that disassociates a user's first identifier from messages and associates them with a second identifier, allowing for the sharing of personalization information and authentication, while masking the user's identity, and enabling session management across different service providers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If centralized identity management is implemented across different service providers, then single sign-on capability is improved, but service providers become dependent on external identity providers creating monopolistic risks

Engineering Contradiction:
Improvesingle sign-on capabilityVSAvoiddependency on external providers
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces an identity provider as an intermediary that issues federated identifiers and authentication tokens, enabling single sign-on across service providers without direct dependency between them. The identity provider mediates authentication while service providers maintain operational independence through standardized interfaces.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a universal identity management system where a single identity provider serves multiple service providers through standardized federation protocols. This allows one identity provider to authenticate users across diverse services without custom integration for each provider, achieving multi-functionality.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If user identity is shared across multiple applications for single sign-on, then authentication convenience is improved, but user privacy is compromised as all applications know the user identity

Engineering Contradiction:
Improveauthentication convenienceVSAvoiduser privacy exposure
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent creates a federated identifier that is a functional copy of the user identity for authentication purposes, but is not the actual user identity. This copy allows applications to verify authentication status without exposing the real user identity, enabling convenient single sign-on while preserving privacy.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The identity provider acts as an intermediary that translates between user identity and federated identifiers. It issues authentication tokens that prove identity without revealing it, mediating between the need for authentication and the need for privacy protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If personalization information is stored locally by each service provider, then user preferences are preserved, but information cannot be shared across different providers

Engineering Contradiction:
Improveuser preference preservationVSAvoidinformation sharing capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal personalization information storage mechanism where user preferences are stored in a standardized format accessible across service providers. The identity provider manages this information universally, allowing any federated service to access and use the same personalization data without redundant storage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Adaptability or versatility

If federated identity management is implemented, then distributed single sign-on is enabled, but no mechanism exists for masking user identity or sharing personalization information

Engineering Contradiction:
Improvedistributed single sign-onVSAvoidlack of identity masking and personalization sharing
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent uses federated identifiers as copies of user identity that enable authentication without exposing the real identity. This copying mechanism provides identity masking while maintaining the functionality of distributed single sign-on across federated service providers.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The identity provider serves as an intermediary that enables both identity masking and personalization information sharing. It manages the translation between user identity and federated identifiers, and simultaneously manages personalization information storage and retrieval for federated services.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8051472B2Method and apparatus for personalization and identity management
Publication Date: 2011.11.01 ORACLE INT CORP
  • US8051472B2 patent drawing
  • US8051472B2 patent drawing
  • US8051472B2 patent drawing

AI summary

Methods and systems are disclosed for personalization and identity management. In one embodiment, the method comprises receiving, from an access provider, a message for a service provider, the message associated with a first identifier of a user of the access provider. A second identifier is obtained, the first identifier is disassociated from the message, and the second identifier is associated with the message. The message associated with the second identifier is then sent to the service provider.