Federated Smart User Identification with Embedded Entitlements
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional user identification systems are one-dimensional and burdensome for users accessing multiple computing systems, and they face challenges in managing user access and entitlements, particularly when databases are unavailable or vulnerable to unauthorized access.
Innovation Solution
A federated smart user identification system with embedded tiered/hierarchical entitlements, utilizing an encrypted key with multiple key strings that define access to computing systems and entitlement zones, allowing dynamic changes based on security factors and user context, eliminating the need for database storage and enhancing security by concealing user IDs from users.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If user identification is stored in a database, then authorization verification can be performed, but the system becomes vulnerable to unauthorized access and database availability issues
Solution Approach 1:
The patent extracts the user ID and entitlements from the centralized database and embeds them directly into the federated user ID token stored on the user's device. This eliminates the need to query the database for authorization verification, thereby removing the vulnerability to database hacks and availability issues while maintaining reliable authorization.
Solution Approach 2:
The federated user ID acts as an intermediary that carries authorization information between the user and multiple computing systems. Instead of directly accessing the database, systems verify authorization through the federated ID, which contains embedded entitlements. This intermediary approach eliminates direct database exposure while maintaining verification capability.
2Ease of operation
If a single federated user ID is implemented across multiple systems, then user burden is reduced and access management is simplified, but the complexity of managing entitlements across diverse systems increases
Solution Approach 1:
The patent segments entitlements into hierarchical zones (e.g., system-level, application-level, data-level) and embeds them as structured components within the federated user ID. This segmentation allows complex entitlements to be organized in a manageable hierarchy that can be easily verified by different systems without increasing overall complexity.
Solution Approach 2:
The federated user ID is designed as a universal token that can be used across multiple different computing systems and applications. By embedding standardized entitlement information that can be interpreted by various systems, it provides multi-functional access management without requiring system-specific implementations, thereby simplifying user access while managing complexity through standardization.
3Reliability
If user ID and entitlements are concealed from users, then security is enhanced, but user awareness and control over their own access rights are reduced
Solution Approach 1:
The patent creates a copy of the essential authorization information in the form of the federated user ID, which is stored securely on the user's device. While the actual entitlements remain concealed for security, the user possesses a secure copy that can be used for verification without exposing the underlying authorization data, thus maintaining both security and user control.
Data Source
AI summary
A federated smart user identification (ID) having embedded tiered/hierarchical entitlements. The federated smart user ID comprises an encrypted key having multiple key strings that create sub-zones/barriers within the key. Each key string includes logical code and is attached/associated with at least one of (i) a computing system, service, application or the like, and (ii) an entitlement zone of the system, service, application or the like. Thus, the individual key strings define which systems, services, applications and the like the user has access to and the entitlements/authorizations within those systems, services, applications that the user has. In addition, key strings can dynamically be added to or deleted from the key to thereby change system/service access authorization and/or system/service-level entitlement.


