Identity Assertion System with Distributed Authorization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing need to protect identity information from theft and unauthorized access, particularly in electronic transactions, due to the vulnerability of identity information on portable devices and during internet exchanges, highlights the requirement for secure and controlled identity assertion mechanisms.
Innovation Solution
The use of authorization information provided by an asserting agent to control interactions between a receiving agent and an identity agent, limiting the scope and duration of identity-related interactions based on specific criteria, such as context and purpose, to secure sensitive information and minimize exposure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If extensive identity information is maintained on portable electronic devices to enable full participation in electronic society, then the entity can fully participate in electronic transactions, but the identity information becomes vulnerable to theft when devices are lost
Solution Approach 1:
The patent segments identity information into multiple components stored in different locations (asserting agent, receiving agent, and identity agent). No single device holds all identity information, so loss of one device does not compromise the entire identity. The identity is divided into claim information, authorization information, and verification data distributed across multiple agents.
Solution Approach 2:
The patent introduces an identity agent as an intermediary between the asserting agent and receiving agent. This intermediary controls and mediates the verification process, allowing identity assertion without exposing sensitive identity information to either party. The identity agent acts as a trusted third party that holds the master copy of identity information.
2Productivity
If extensive identity information is transferred over the Internet during electronic transactions, then the entity can complete transactions, but the transferred information is exposed to potential interception and misuse
Solution Approach 1:
The patent extracts sensitive identity information from the transaction flow between asserting and receiving agents. Instead of transferring identity information during transactions, only verification requests and authorization tokens are exchanged. The actual identity data remains securely stored at the identity agent and is never transmitted over the network.
Solution Approach 2:
The patent uses copies of identity information (claim information and authorization information) that are distributed to asserting and receiving agents without transferring the master copy. These copies are sufficient for verification purposes but do not contain the complete sensitive identity data, reducing exposure risk during transactions.
3Reliability
If the identity agent is allowed to interact freely with receiving agents to verify claims, then identity verification can be performed, but the scope of interaction may be too broad and increase security risks
Solution Approach 1:
The patent makes the interaction scope between identity agent and receiving agents dynamic and context-dependent. Authorization information includes contextual parameters that define when and how the identity agent can interact with receiving agents. The scope of interaction changes based on the specific transaction context, entity preferences, and security requirements rather than being fixed or overly permissive.
Data Source
AI summary
The present invention relates to using authorization information provided by an asserting agent to control identity-related interactions between a receiving agent and an identity agent, which acts on behalf of the asserting agent. The authorization information may be provided to the identity agent directly or through the receiving agent. When the asserting agent is asserting the identity of an associated entity to the receiving agent, the asserting agent delivers assertion information, which may but need not include the authorization information, to the receiving agent. The assertion information includes claim information that includes actual claims or identifies available claims. Upon receiving the assertion information, the receiving agent may interact with the identity agent. The identity agent will use the authorization information to control claim-related interactions with the receiving agent.


