Federated Smart User Identification with Embedded Entitlements

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional user identification systems are one-dimensional and burdensome for users accessing multiple computing systems, and they face challenges in managing user access and entitlements, particularly when databases are unavailable or vulnerable to unauthorized access.

Innovation Solution

A federated smart user identification system with embedded tiered/hierarchical entitlements, utilizing an encrypted key with multiple key strings that define access to computing systems and entitlement zones, allowing dynamic changes based on security factors and user context, eliminating the need for database storage and enhancing security by concealing user IDs from users.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If user identification is stored in a database, then authorization verification can be performed, but the system becomes vulnerable to unauthorized access and database availability issues

Engineering Contradiction:
Improveauthorization verificationVSAvoidunauthorized access vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the user ID and entitlements from the centralized database and embeds them directly into the federated user ID token stored on the user's device. This eliminates the need to query the database for authorization verification, thereby removing the vulnerability to database hacks and availability issues while maintaining reliable authorization.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The federated user ID acts as an intermediary that carries authorization information between the user and multiple computing systems. Instead of directly accessing the database, systems verify authorization through the federated ID, which contains embedded entitlements. This intermediary approach eliminates direct database exposure while maintaining verification capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If a single federated user ID is implemented across multiple systems, then user burden is reduced and access management is simplified, but the complexity of managing entitlements across diverse systems increases

Engineering Contradiction:
Improveuser access managementVSAvoidentitlement management system
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent segments entitlements into hierarchical zones (e.g., system-level, application-level, data-level) and embeds them as structured components within the federated user ID. This segmentation allows complex entitlements to be organized in a manageable hierarchy that can be easily verified by different systems without increasing overall complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The federated user ID is designed as a universal token that can be used across multiple different computing systems and applications. By embedding standardized entitlement information that can be interpreted by various systems, it provides multi-functional access management without requiring system-specific implementations, thereby simplifying user access while managing complexity through standardization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If user ID and entitlements are concealed from users, then security is enhanced, but user awareness and control over their own access rights are reduced

Engineering Contradiction:
ImprovesecurityVSAvoiduser awareness of entitlements
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent creates a copy of the essential authorization information in the form of the federated user ID, which is stored securely on the user's device. While the actual entitlements remain concealed for security, the user possesses a secure copy that can be used for verification without exposing the underlying authorization data, thus maintaining both security and user control.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11244060B2Federated smart user identification with embedded computing system entitlements
Publication Date: 2022.02.08 BANK OF AMERICA CORP
  • US11244060B2 patent drawing
  • US11244060B2 patent drawing
  • US11244060B2 patent drawing

AI summary

A federated smart user identification (ID) having embedded tiered/hierarchical entitlements. The federated smart user ID comprises an encrypted key having multiple key strings that create sub-zones/barriers within the key. Each key string includes logical code and is attached/associated with at least one of (i) a computing system, service, application or the like, and (ii) an entitlement zone of the system, service, application or the like. Thus, the individual key strings define which systems, services, applications and the like the user has access to and the entitlements/authorizations within those systems, services, applications that the user has. In addition, key strings can dynamically be added to or deleted from the key to thereby change system/service access authorization and/or system/service-level entitlement.