Federated Identity Unique Digital Identifier Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In federated identity management systems, the use of a single digital identifier for multiple subscribers poses a security risk, as compromised identifiers can facilitate unauthorized access across different systems, highlighting the need for unique identifiers to prevent identity theft and enhance security.

Innovation Solution

The authentication provider issues unique digital identifiers to each subscriber, encrypting them with a subscriber-specific secret key before transmission, ensuring that only an encrypted version is shared, thus maintaining security and preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a single digital identifier is used across multiple subscribers for federated identity management, then ease of operation and user convenience are improved, but security and vulnerability to identity theft worsen

Engineering Contradiction:
Improveuser convenienceVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments the single digital identifier into multiple subscriber-specific identifiers. Each subscriber receives a unique identifier that is encrypted with their specific secret key, dividing the original identification system into isolated segments that cannot be used across different subscribers, thus resolving the security risk while maintaining operational ease through automated identifier management

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary authentication service that manages the generation, distribution, and encryption of digital identifiers. This intermediary service acts as a mediator between users and multiple subscribers, automatically handling the complexity of unique identifier assignment and encryption, thereby maintaining user convenience while ensuring security through centralized control

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If the same user digital identifier is shared across multiple identity services subscribers, then ease of operation is improved, but reliability and security against identity theft worsen

Engineering Contradiction:
Improveease of operationVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies local quality by making each digital identifier unique to a specific subscriber context. The identifier's security properties (encryption with subscriber-specific secret keys) are tailored to each local subscriber environment, ensuring that compromise in one subscriber's system does not affect others, thus improving security reliability while maintaining operational ease through automated management

Inventive Principle:
Principle #3Local quality

3Object-affected harmful factors

If encrypted user digital identifiers with subscriber-specific secret keys are issued to each subscriber, then security and protection against identity theft are improved, but device complexity and system complexity worsen

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The authentication service automatically performs the complex tasks of generating unique identifiers, selecting appropriate secret keys, encrypting identifiers with subscriber-specific keys, and managing key distribution. This self-service automation eliminates the need for manual configuration and reduces the perceived complexity for users, while the system handles the cryptographic complexity in the background

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent creates a universal authentication service that handles multiple functions: user registration, identifier generation, key management, encryption, and distribution across multiple subscribers. This multi-functional service consolidates the complexity into a single system component, reducing overall system complexity while providing comprehensive security protection

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9363257B2Secure federated identity service
Publication Date: 2016.06.07 BILLINGS ROGER E
  • US9363257B2 patent drawing

AI summary

Federated identity is the means of linking a person's electronic identity and attributes, such that the user can be authenticated with a single sign-on, across multiple systems and organizations. A system and a method is proposed to provide a unique user digital identifier which is different for each security identity services subscriber.