Graduated Authentication Identity Management System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing identity management systems face challenges in providing graduated security levels, supporting third-party web services, and enabling distributed contact management, leading to increased barriers for users and inefficiencies in data exchange.

Innovation Solution

A method and system that allow for selecting security levels for transmitting identity information based on user preferences and homesite policies, enabling differentiated authentication and channel security levels, and facilitating automated data exchange across multiple contact management services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a secure channel is used for transmitting identity information, then security is improved, but the barrier to entry for membersites increases and the login process becomes more complex

Engineering Contradiction:
ImprovesecurityVSAvoidbarrier to entry
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the authentication process into multiple graduated levels (lightweight authentication, authenticated channel, secure channel with digital signatures). Membersites can select the appropriate level based on their security requirements, allowing low-security sites to enter easily while high-security sites maintain strong protection. This segmentation resolves the contradiction by providing a range of options rather than a single mandatory secure channel.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the security parameter from a fixed high-security requirement to a variable parameter that can be adjusted based on the membersite's needs. By introducing graduated authentication levels (lightweight, authenticated, secure), the system allows membersites to select appropriate security parameters, reducing the barrier to entry for those who don't require high security while maintaining options for those who do.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If a secure channel with digital signatures is used for transmitting identity information, then authentication reliability is improved, but the overhead and complexity of the login process increases

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidlogin process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication process is segmented into distinct levels with increasing complexity. The lightweight authentication level provides basic functionality with minimal overhead, while higher levels (authenticated channel, secure channel with digital signatures) are optional and only used when required. This segmentation allows the system to maintain low complexity for basic operations while providing high reliability when needed.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces dynamic selection of authentication levels, allowing the system to adapt the complexity of the login process based on the specific requirements of each membersite and user context. The authentication level is not fixed but can be dynamically adjusted, enabling the system to optimize between reliability and complexity on a case-by-case basis.

Inventive Principle:
Principle #15Dynamics

3Reliability

If third parties are heavily linked to webservice providers for authentication, then authorization reliability is improved, but the adaptability and ease of aggregation across multiple providers decreases

Engineering Contradiction:
Improveauthorization reliabilityVSAvoidaggregation capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal authentication framework where a single authentication mechanism can serve multiple webservice providers and third parties. The graduated authentication levels and standardized protocols allow any authenticated entity to access any service that accepts the same authentication level, eliminating the need for heavy, provider-specific linking and enabling easy aggregation across multiple providers while maintaining authorization reliability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Stability of the object's composition

If contact management services are highly centralized, then data consistency is improved, but the ability to share information across different services and users decreases

Engineering Contradiction:
Improvedata consistencyVSAvoidinformation sharing capability
Core Design Contradiction:
Stability of the object's compositionVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal contact management framework where contact information can be centrally authenticated and then universally shared across multiple distributed services. The standardized authentication and data exchange protocols allow contact data to maintain consistency through centralized verification while enabling broad distribution and sharing across different services and user groups, resolving the contradiction between centralization and distribution.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8527752B2Graduated authentication in an identity management system
Publication Date: 2013.09.03 CALLAHAN CELLULAR LLC
  • US8527752B2 patent drawing
  • US8527752B2 patent drawing
  • US8527752B2 patent drawing

AI summary

A method and system for graduated security in an identity management system utilize differing levels of time sensitivity, channel security and authentication security to provide a multi-dimensional approach to providing the right fit for differing identity requests. The differing levels of security can be selected by user preference, membersite request or homesite policy.