Identity Attribute Exchange Ecosystem Using Segmented Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current identity ecosystems face challenges in differentiating trust values for user attributes obtained from various identity service providers and typically rely on a single provider, which may not store all necessary attributes, leading to limitations in authentication and liability distribution.
Innovation Solution
An identity ecosystem that allows relying parties to aggregate attributes from multiple identity service providers, each authenticating a subset of user attributes with varying levels of assurance, using an authentication broker to establish trust relationships and manage liability, enabling enhanced authentication and transaction security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a single identity service provider is used to authenticate user attributes, then the authentication process is simple and straightforward, but the system cannot provide all necessary attributes and the trust value cannot be differentiated across different attribute sources
Solution Approach 1:
The patent segments the authentication system into multiple identity service providers, each responsible for specific attributes they can verify. This allows the system to distribute attribute authentication across specialized providers rather than requiring a single provider to handle all attributes, thereby improving attribute coverage and trust differentiation while maintaining manageable complexity through clear division of responsibilities.
Solution Approach 2:
The patent introduces an intermediary component that coordinates between multiple identity service providers and the relying party. This intermediary manages the aggregation of attributes from different providers, handles the differentiation of trust values, and orchestrates the authentication process, thereby enabling versatile attribute aggregation without proportionally increasing system complexity.
2Adaptability or versatility
If multiple identity service providers are used to provide different user attributes, then complete authentication information can be obtained, but the system complexity increases and liability distribution becomes challenging
Solution Approach 1:
The patent segments the system into distinct functional components: multiple specialized identity service providers, an intermediary coordinator, and the relying party. This segmentation allows each component to focus on specific tasks, making the overall complex system manageable through clear boundaries and specialized functions.
Solution Approach 2:
The intermediary serves as a mediator that simplifies the interaction between multiple identity service providers and the relying party. It aggregates attributes from various providers, manages trust value differentiation, and presents a unified interface to the relying party, thereby enabling versatile attribute aggregation while containing system complexity through centralized coordination.
3Ease of operation
If username and password credentials are shared with third parties, then access to services is granted, but security is compromised and full access permissions are exposed
Solution Approach 1:
The patent segments access permissions into fine-grained attribute-level authorizations rather than all-or-nothing credential sharing. Each identity service provider authenticates specific attributes, and the relying party receives only the attributes needed for specific operations. This segmentation enables convenient service access while maintaining security by limiting exposure to only necessary information.
Solution Approach 2:
The patent applies local quality by allowing different levels of authentication and attribute sharing for different services and resources. Each attribute can be authenticated with appropriate trust levels based on its sensitivity and the specific service requirements. This enables tailored security measures for different data types while maintaining ease of operation for each specific access scenario.
Data Source
AI summary
Methods and systems are described herein for performing attribute authentication for use by a relying party in providing access to a resource as requested by a user. Attribute authentication may be performed entirely by a single identity service provider, or by multiple identity service providers each authenticating a subset of a plurality of user attributes, such as name, address, phone, email, and the like. Each attribute may be authenticated with a level of assurance. Levels of assurance may vary from attribute to attribute. Different levels of assurance may be required for different attributes before the relying party may grant access to the user-desired resource. An authentication broker may act as a registry or broker of identity service providers, and may store information usable by relying parties to establish a trust relationship with a particular identity service provider on demand, as needed by a relying party.


