Graduated Authentication Identity Management System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing identity management systems face challenges in providing graduated security levels, supporting third-party web services, and enabling distributed contact management, leading to increased barriers for users and inefficiencies in data exchange.
Innovation Solution
A method and system that allow for selecting security levels for transmitting identity information based on user preferences and homesite policies, enabling differentiated authentication and channel security levels, and facilitating automated data exchange across multiple contact management services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a secure channel is used for transmitting identity information, then security is improved, but the barrier to entry for membersites increases and the login process becomes more complex
Solution Approach 1:
The patent segments the authentication process into multiple graduated levels (lightweight authentication, authenticated channel, secure channel with digital signatures). Membersites can select the appropriate level based on their security requirements, allowing low-security sites to enter easily while high-security sites maintain strong protection. This segmentation resolves the contradiction by providing a range of options rather than a single mandatory secure channel.
Solution Approach 2:
The patent changes the security parameter from a fixed high-security requirement to a variable parameter that can be adjusted based on the membersite's needs. By introducing graduated authentication levels (lightweight, authenticated, secure), the system allows membersites to select appropriate security parameters, reducing the barrier to entry for those who don't require high security while maintaining options for those who do.
2Reliability
If a secure channel with digital signatures is used for transmitting identity information, then authentication reliability is improved, but the overhead and complexity of the login process increases
Solution Approach 1:
The authentication process is segmented into distinct levels with increasing complexity. The lightweight authentication level provides basic functionality with minimal overhead, while higher levels (authenticated channel, secure channel with digital signatures) are optional and only used when required. This segmentation allows the system to maintain low complexity for basic operations while providing high reliability when needed.
Solution Approach 2:
The patent introduces dynamic selection of authentication levels, allowing the system to adapt the complexity of the login process based on the specific requirements of each membersite and user context. The authentication level is not fixed but can be dynamically adjusted, enabling the system to optimize between reliability and complexity on a case-by-case basis.
3Reliability
If third parties are heavily linked to webservice providers for authentication, then authorization reliability is improved, but the adaptability and ease of aggregation across multiple providers decreases
Solution Approach 1:
The patent creates a universal authentication framework where a single authentication mechanism can serve multiple webservice providers and third parties. The graduated authentication levels and standardized protocols allow any authenticated entity to access any service that accepts the same authentication level, eliminating the need for heavy, provider-specific linking and enabling easy aggregation across multiple providers while maintaining authorization reliability.
4Stability of the object's composition
If contact management services are highly centralized, then data consistency is improved, but the ability to share information across different services and users decreases
Solution Approach 1:
The patent implements a universal contact management framework where contact information can be centrally authenticated and then universally shared across multiple distributed services. The standardized authentication and data exchange protocols allow contact data to maintain consistency through centralized verification while enabling broad distribution and sharing across different services and user groups, resolving the contradiction between centralization and distribution.
Data Source
AI summary
A method and system for graduated security in an identity management system utilize differing levels of time sensitivity, channel security and authentication security to provide a multi-dimensional approach to providing the right fit for differing identity requests. The differing levels of security can be selected by user preference, membersite request or homesite policy.


