Identity Hub Segmentation for Multi-Region Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face challenges in managing digital identities across multiple regions through various identity providers while enforcing region-specific policies, leading to complexities in authentication, authorization, and fraud detection.

Innovation Solution

A cloud-based identity and access management hub (IAMH) is implemented, coupled with secondary hubs in different regions, which communicates with multiple identity providers to enforce policies, provide biometric authentication, fraud scoring, and document verification, offering value-added services like tokenization and identity proofing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a cloud-based identity and access management hub with secondary hubs is implemented to manage digital identities across multiple regions, then policy enforcement capability and fraud detection are improved, but system complexity increases

Engineering Contradiction:
Improvepolicy enforcement capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides the identity and access management functionality into a cloud-based central hub and multiple regional secondary hubs. Each secondary hub handles specific regional policies and identity providers, allowing distributed policy enforcement while maintaining centralized coordination. This segmentation enables reliable multi-region policy enforcement without requiring a single monolithic system, thus managing complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The cloud-based identity and access management hub acts as an intermediary between regional secondary hubs and identity providers. It coordinates authentication requests, manages digital identity data, and enforces policies across regions by mediating between local hub operations and central policy requirements. This intermediary role enables complex policy enforcement while keeping individual hub components relatively simple.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple identity providers are integrated through a centralized hub, then digital identity management coverage is improved, but authentication and authorization complexity increases

Engineering Contradiction:
Improvedigital identity management coverageVSAvoidauthentication and authorization complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The identity and access management hub provides universal functionality by supporting multiple identity providers and various authentication methods (biometric, document verification, fraud scoring) through a single platform. The hub can authenticate users against different identity providers using standardized processes, enabling broad digital identity management coverage without requiring separate systems for each provider, thus managing authentication complexity through unified multi-functional architecture.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The hub serves as an intermediary layer between diverse identity providers and relying parties, translating between different identity provider formats and standardized authentication flows. It manages the complexity of multi-provider integration by mediating authentication requests, normalizing data formats, and coordinating verification processes across multiple providers through a single coordinated interface.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If biometric authentication, fraud scoring, and document verification services are added, then security and fraud mitigation are improved, but processing time and operational complexity increase

Engineering Contradiction:
Improvefraud mitigation capabilityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary fraud scoring and risk assessment during the authentication process by analyzing device fingerprints, behavioral patterns, and request characteristics before completing full verification. Fraud scoring is conducted in advance based on available data, allowing the system to prioritize or expedite low-risk authentications while applying more thorough verification (biometric, document) only when necessary. This preliminary action reduces overall processing time while maintaining strong fraud mitigation for high-risk cases.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication system applies verification methods proportionally to risk levels rather than requiring all verification types for every user. For low-risk authentications, the system may use simplified processes (partial action), while high-risk cases receive comprehensive verification including biometric and document checks. This selective application of verification depth maintains strong fraud mitigation capability while avoiding unnecessary processing time for low-risk users.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP3756125B1Systems and methods for managing digital identities associated with users
Publication Date: 2024.03.20 MASTERCARD INT INC
  • EP3756125B1 patent drawingFigure 1
  • EP3756125B1 patent drawingFigure 2
  • EP3756125B1 patent drawingFigure 3

AI summary

Systems and methods are provided for managing digital identities in multiple regions, through multiple identity providers, while providing for policy enforcement in connection with the digital identities. One exemplary method includes receiving, at an identity and access management hub (LAMH) in a first region, a request related to a digital identity from a secondary hub disposed in a second region and checking a policy associated with the digital identity. In response, the LAMH solicits at least one claim from a user, at a relying party application and/or website, based on the request and provides the at least one claim to a value-added service associated with the LAMH for verification of the at least one claim. The LAMH then transmits a result of the verification to the relying party associated with the request and provides a token, in response to the request, to a secure resource associated with the relying party.