Identity Attribute Exchange Ecosystem Using Segmented Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current identity ecosystems face challenges in differentiating trust values for user attributes obtained from various identity service providers and typically rely on a single provider, which may not store all necessary attributes, leading to limitations in authentication and liability distribution.

Innovation Solution

An identity ecosystem that allows relying parties to aggregate attributes from multiple identity service providers, each authenticating a subset of user attributes with varying levels of assurance, using an authentication broker to establish trust relationships and manage liability, enabling enhanced authentication and transaction security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a single identity service provider is used to authenticate user attributes, then the authentication process is simple and straightforward, but the system cannot provide all necessary attributes and the trust value cannot be differentiated across different attribute sources

Engineering Contradiction:
Improveauthentication process complexityVSAvoidattribute coverage and trust differentiation
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent segments the authentication system into multiple identity service providers, each responsible for specific attributes they can verify. This allows the system to distribute attribute authentication across specialized providers rather than requiring a single provider to handle all attributes, thereby improving attribute coverage and trust differentiation while maintaining manageable complexity through clear division of responsibilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary component that coordinates between multiple identity service providers and the relying party. This intermediary manages the aggregation of attributes from different providers, handles the differentiation of trust values, and orchestrates the authentication process, thereby enabling versatile attribute aggregation without proportionally increasing system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple identity service providers are used to provide different user attributes, then complete authentication information can be obtained, but the system complexity increases and liability distribution becomes challenging

Engineering Contradiction:
Improveattribute aggregation capabilityVSAvoidsystem architecture complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the system into distinct functional components: multiple specialized identity service providers, an intermediary coordinator, and the relying party. This segmentation allows each component to focus on specific tasks, making the overall complex system manageable through clear boundaries and specialized functions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The intermediary serves as a mediator that simplifies the interaction between multiple identity service providers and the relying party. It aggregates attributes from various providers, manages trust value differentiation, and presents a unified interface to the relying party, thereby enabling versatile attribute aggregation while containing system complexity through centralized coordination.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If username and password credentials are shared with third parties, then access to services is granted, but security is compromised and full access permissions are exposed

Engineering Contradiction:
Improveservice access convenienceVSAvoidsecurity and access control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments access permissions into fine-grained attribute-level authorizations rather than all-or-nothing credential sharing. Each identity service provider authenticates specific attributes, and the relying party receives only the attributes needed for specific operations. This segmentation enables convenient service access while maintaining security by limiting exposure to only necessary information.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by allowing different levels of authentication and attribute sharing for different services and resources. Each attribute can be authenticated with appropriate trust levels based on its sensitivity and the specific service requirements. This enables tailored security measures for different data types while maintaining ease of operation for each specific access scenario.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS8931064B2Identity attribute exchange and validation ecosystem
Publication Date: 2015.01.06 BANK OF AMERICA CORP
  • US8931064B2 patent drawing
  • US8931064B2 patent drawing
  • US8931064B2 patent drawing

AI summary

Methods and systems are described herein for performing attribute authentication for use by a relying party in providing access to a resource as requested by a user. Attribute authentication may be performed entirely by a single identity service provider, or by multiple identity service providers each authenticating a subset of a plurality of user attributes, such as name, address, phone, email, and the like. Each attribute may be authenticated with a level of assurance. Levels of assurance may vary from attribute to attribute. Different levels of assurance may be required for different attributes before the relying party may grant access to the user-desired resource. An authentication broker may act as a registry or broker of identity service providers, and may store information usable by relying parties to establish a trust relationship with a particular identity service provider on demand, as needed by a relying party.