Federated Identity Unique Digital Identifier Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In federated identity management systems, the use of a single digital identifier for multiple subscribers poses a security risk, as compromised identifiers can facilitate unauthorized access across different systems, highlighting the need for unique identifiers to prevent identity theft and enhance security.
Innovation Solution
The authentication provider issues unique digital identifiers to each subscriber, encrypting them with a subscriber-specific secret key before transmission, ensuring that only an encrypted version is shared, thus maintaining security and preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a single digital identifier is used across multiple subscribers for federated identity management, then ease of operation and user convenience are improved, but security and vulnerability to identity theft worsen
Solution Approach 1:
The patent segments the single digital identifier into multiple subscriber-specific identifiers. Each subscriber receives a unique identifier that is encrypted with their specific secret key, dividing the original identification system into isolated segments that cannot be used across different subscribers, thus resolving the security risk while maintaining operational ease through automated identifier management
Solution Approach 2:
The patent introduces an intermediary authentication service that manages the generation, distribution, and encryption of digital identifiers. This intermediary service acts as a mediator between users and multiple subscribers, automatically handling the complexity of unique identifier assignment and encryption, thereby maintaining user convenience while ensuring security through centralized control
2Ease of operation
If the same user digital identifier is shared across multiple identity services subscribers, then ease of operation is improved, but reliability and security against identity theft worsen
Solution Approach 1:
The patent applies local quality by making each digital identifier unique to a specific subscriber context. The identifier's security properties (encryption with subscriber-specific secret keys) are tailored to each local subscriber environment, ensuring that compromise in one subscriber's system does not affect others, thus improving security reliability while maintaining operational ease through automated management
3Object-affected harmful factors
If encrypted user digital identifiers with subscriber-specific secret keys are issued to each subscriber, then security and protection against identity theft are improved, but device complexity and system complexity worsen
Solution Approach 1:
The authentication service automatically performs the complex tasks of generating unique identifiers, selecting appropriate secret keys, encrypting identifiers with subscriber-specific keys, and managing key distribution. This self-service automation eliminates the need for manual configuration and reduces the perceived complexity for users, while the system handles the cryptographic complexity in the background
Solution Approach 2:
The patent creates a universal authentication service that handles multiple functions: user registration, identifier generation, key management, encryption, and distribution across multiple subscribers. This multi-functional service consolidates the complexity into a single system component, reducing overall system complexity while providing comprehensive security protection
Data Source
AI summary
Federated identity is the means of linking a person's electronic identity and attributes, such that the user can be authenticated with a single sign-on, across multiple systems and organizations. A system and a method is proposed to provide a unique user digital identifier which is different for each security identity services subscriber.
