Identity Assurance Score for Dynamic Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authorization systems lack a dynamic framework for identity verification, failing to fully capture the changing nature of identity and evolving threats to identity security, which limits their ability to tailor authentication processes based on risk profiles and potential consequences of identity fraud.

Innovation Solution

The implementation of an identity assurance based authorization system that provides dynamic metrics to evaluate the confidence of identity proofing processes, generating an identity assurance score that reflects the level of confidence in a user's identity, allowing systems to adjust authentication levels based on risk profiles and potential consequences.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If static identity verification frameworks are used, then system simplicity is maintained, but the ability to adapt to changing identity nature and evolving threats is compromised

Engineering Contradiction:
Improveadaptability to changing identity natureVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a dynamic identity verification framework that transitions from static to dynamic operations. The system continuously updates identity assurance scores based on real-time data from multiple sources, adjusts verification requirements dynamically, and adapts to changing identity nature and evolving threats. This dynamic approach allows the system to respond to current risk profiles while maintaining operational effectiveness.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes key parameters including identity assurance scores, verification thresholds, and authentication requirements based on risk profiles and threat levels. By continuously monitoring and updating these parameters, the system adapts to changing conditions without requiring complete system redesign, thus improving adaptability while managing complexity through parameter-based adjustments.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If dynamic identity verification frameworks are implemented, then adaptability to changing identity nature is improved, but system complexity increases

Engineering Contradiction:
Improveadaptability to evolving threatsVSAvoidframework complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the complex identity verification system into distinct functional modules: identity assurance scoring, risk profile assessment, verification requirement determination, and authentication execution. This segmentation allows each component to handle specific tasks independently, making the overall complex system more manageable and easier to implement while maintaining high adaptability to evolving threats.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary layer in the form of an identity assurance score that mediates between raw verification data and authentication decisions. This intermediary component simplifies the decision-making process by consolidating complex verification results into a single risk-based metric, thereby reducing framework complexity while preserving adaptability to changing threat landscapes.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If authentication processes are tailored to risk profiles, then security effectiveness is improved, but operational complexity increases

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by tailoring authentication processes to specific risk profiles and scenarios rather than using a uniform approach. Different verification requirements are applied locally based on the specific context, user risk profile, and threat level. This allows high security effectiveness for high-risk scenarios while maintaining simplicity for low-risk cases, thus improving overall security without uniformly increasing operational complexity.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system implements feedback mechanisms that continuously monitor authentication outcomes, risk profiles, and threat indicators. This feedback information is used to dynamically adjust future authentication requirements, improving security effectiveness over time. The feedback loop enables the system to learn from past performance and adapt authentication processes automatically, reducing manual operational complexity while enhancing security.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12328319B2Identity assurance based authorization and authentication systems
Publication Date: 2025.06.10 STRIPE LLC
  • US12328319B2 patent drawing
  • US12328319B2 patent drawing
  • US12328319B2 patent drawing

AI summary

Aspects of the subject technology include a method comprising obtaining an enrollment confidence score and a validation confidence score, and determining an identity assurance score associated with the user account that indicates a level of confidence in an identity of the user. The identity assurance score is determined based at least in part on one or more of the enrollment confidence score or the validation confidence score. The method also comprises receiving, from a service provider, a request for the identity assurance score for the user account, the request corresponding to at least one of an authorization or an authentication of the user account at the service provider, and providing, responsive to the request, the identity assurance score of the user account to the service provider for at least one of the authorization or the authentication of the user account at the service provider.