Identity Assertion System with Distributed Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing need to protect identity information from theft and unauthorized access, particularly in electronic transactions, due to the vulnerability of identity information on portable devices and during internet exchanges, highlights the requirement for secure and controlled identity assertion mechanisms.

Innovation Solution

The use of authorization information provided by an asserting agent to control interactions between a receiving agent and an identity agent, limiting the scope and duration of identity-related interactions based on specific criteria, such as context and purpose, to secure sensitive information and minimize exposure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If extensive identity information is maintained on portable electronic devices to enable full participation in electronic society, then the entity can fully participate in electronic transactions, but the identity information becomes vulnerable to theft when devices are lost

Engineering Contradiction:
Improveability to participate in electronic societyVSAvoidvulnerability to identity theft
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments identity information into multiple components stored in different locations (asserting agent, receiving agent, and identity agent). No single device holds all identity information, so loss of one device does not compromise the entire identity. The identity is divided into claim information, authorization information, and verification data distributed across multiple agents.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an identity agent as an intermediary between the asserting agent and receiving agent. This intermediary controls and mediates the verification process, allowing identity assertion without exposing sensitive identity information to either party. The identity agent acts as a trusted third party that holds the master copy of identity information.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If extensive identity information is transferred over the Internet during electronic transactions, then the entity can complete transactions, but the transferred information is exposed to potential interception and misuse

Engineering Contradiction:
Improvetransaction completion capabilityVSAvoidexposure of identity information
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent extracts sensitive identity information from the transaction flow between asserting and receiving agents. Instead of transferring identity information during transactions, only verification requests and authorization tokens are exchanged. The actual identity data remains securely stored at the identity agent and is never transmitted over the network.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent uses copies of identity information (claim information and authorization information) that are distributed to asserting and receiving agents without transferring the master copy. These copies are sufficient for verification purposes but do not contain the complete sensitive identity data, reducing exposure risk during transactions.

Inventive Principle:
Principle #26Copying

3Reliability

If the identity agent is allowed to interact freely with receiving agents to verify claims, then identity verification can be performed, but the scope of interaction may be too broad and increase security risks

Engineering Contradiction:
Improveidentity verification capabilityVSAvoidsecurity risks from broad interaction scope
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent makes the interaction scope between identity agent and receiving agents dynamic and context-dependent. Authorization information includes contextual parameters that define when and how the identity agent can interact with receiving agents. The scope of interaction changes based on the specific transaction context, entity preferences, and security requirements rather than being fixed or overly permissive.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8479272B2Identity assertion
Publication Date: 2013.07.02 AVAYA INC
  • US8479272B2 patent drawing
  • US8479272B2 patent drawing
  • US8479272B2 patent drawing

AI summary

The present invention relates to using authorization information provided by an asserting agent to control identity-related interactions between a receiving agent and an identity agent, which acts on behalf of the asserting agent. The authorization information may be provided to the identity agent directly or through the receiving agent. When the asserting agent is asserting the identity of an associated entity to the receiving agent, the asserting agent delivers assertion information, which may but need not include the authorization information, to the receiving agent. The assertion information includes claim information that includes actual claims or identifies available claims. Upon receiving the assertion information, the receiving agent may interact with the identity agent. The identity agent will use the authorization information to control claim-related interactions with the receiving agent.