Cross-Domain Identity Authentication Mediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Centralized identity management systems are inflexible and cannot seamlessly integrate with decentralized identity systems, limiting the use of decentralized identities in legacy systems without significant modifications.

Innovation Solution

Implementing a method that allows decentralized identities to authenticate on behalf of centralized identities and vice versa, enabling authentication across decentralized and centralized domains by registering delegations and interacting with the respective identity systems to grant access to resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If centralized identity management systems are used, then security and reliability are improved, but adaptability to decentralized identity systems deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidadaptability to decentralized identity systems
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a mediation layer that enables centralized identity systems to interact with decentralized identity systems through standardized protocols. This intermediary mechanism allows the centralized system to maintain its security architecture while adapting to decentralized identities by translating between different identity paradigms without requiring fundamental system changes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements a universal authentication framework that can handle both centralized and decentralized identities through a common interface. This multi-functional approach allows the centralized identity system to serve multiple purposes: authenticating traditional centralized identities while also recognizing and integrating decentralized identifiers, thereby improving adaptability without compromising core security functions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If decentralized identity systems are implemented, then adaptability and flexibility are improved, but integration with legacy centralized systems deteriorates

Engineering Contradiction:
ImproveflexibilityVSAvoidintegration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a mediation layer that enables centralized identity systems to interact with decentralized identity systems through standardized protocols. This intermediary mechanism allows the centralized system to maintain its security architecture while adapting to decentralized identities by translating between different identity paradigms without requiring fundamental system changes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent establishes pre-configured delegation relationships and trust frameworks between centralized and decentralized identity systems before actual authentication occurs. By setting up these preliminary connections and protocols in advance, the system reduces integration complexity during operational use, as the pathways for cross-system authentication are already established and validated.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If centralized identity systems require modifications to support decentralized identities, then interoperability is improved, but system complexity and modification requirements increase

Engineering Contradiction:
ImproveinteroperabilityVSAvoidsystem modification requirements
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a mediation layer that enables centralized identity systems to interact with decentralized identity systems through standardized protocols. This intermediary mechanism allows the centralized system to maintain its security architecture while adapting to decentralized identities by translating between different identity paradigms without requiring fundamental system changes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements a gradual integration approach where only specific components of the centralized identity system are modified to support decentralized identities, rather than requiring complete system overhaul. This partial action strategy allows interoperability to be achieved with minimal modifications to the core centralized system architecture.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11329968B2Authentication across decentralized and centralized identities
Publication Date: 2022.05.10 MICROSOFT TECHNOLOGY LICENSING LLC
  • US11329968B2 patent drawing
  • US11329968B2 patent drawing
  • US11329968B2 patent drawing

AI summary

Permitting a decentralized identity to authenticate on behalf of a centralized identity to a centralized identity system, and/or permitting a centralized identity to authenticate on behalf of a decentralized identity to a decentralized identity system. Thus, the principles described herein permit authentication across decentralized and centralized domains. The identity system receives and registers a delegation for the first identity to authentic as the second identity, where one of the identities is a decentralized identity and one is a centralized identity. Thereafter, when the identity system receives a communication from the first identity to access a resource owned by the second identity, the identity system accesses the registration to determine that the first identity is authorized to authenticate as the second identity, authenticates the first identity as the second identity, and grants the first identity access to the resource owned by the second identity.