Identity Information Management via Contract Detail and IdP Selector
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for managing identity information in web services often result in users having little control over their personal data, leading to potential identity information leakage due to excessive information sharing and lack of clear agreements on data provision and consumption.
Innovation Solution
An identity information management apparatus and method that involves a contract detail manager, an IdP selector, and an information provider to facilitate a sharing contract between users and identity providers (IdPs) and consumers (IdCs), allowing users to select and control the flow of their identity information based on predefined sharing contracts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If users provide all personal information to websites during registration, then websites can obtain complete user data, but users lose control over their personal information and face identity information leakage risks
Solution Approach 1:
The patent segments personal information into different categories (identity information, profile information, contact information, etc.) and allows users to selectively provide only the necessary portions to each service provider based on the specific service requirements, rather than providing all information at once. This is achieved through the information provision management module that presents categorized information selection interfaces to users.
Solution Approach 2:
The patent implements dynamic control where users can adjust their information sharing preferences at any time. The information provision management module allows users to modify which information categories are shared with which service providers, enabling flexible and adaptive control over personal information flow based on changing user needs and service requirements.
2Adaptability or versatility
If websites obtain extensive user personal information, then service functionality is enhanced, but the risk of identity information leakage increases
Solution Approach 1:
The patent extracts only the specific personal information categories that are necessary for each service function, rather than collecting all user information. The information provision management module analyzes service requirements and selectively retrieves only the needed information types from user profiles, minimizing the overall exposure of personal data while maintaining service functionality.
Solution Approach 2:
The patent applies different information sharing policies to different service providers based on their specific needs. Each service provider receives only the information categories relevant to their service, with customized permission levels. This localized approach ensures that each entity receives appropriate information without unnecessary exposure to unrelated personal data.
3Device complexity
If users must accept website-set agreements on information deletion and holding period, then website management is simplified, but users have no right to control their personal information
Solution Approach 1:
The patent introduces an information provision management module as an intermediary between users and service providers. This module manages information sharing agreements, deletion policies, and holding periods according to user preferences rather than website defaults. It automatically negotiates and enforces information lifecycle management rules, reducing management complexity for websites while granting users full control over their personal information.
4Loss of time
If clear agreements on information provision and consumption are not made, then service setup is faster, but identity information leakage problems cannot be solved
Solution Approach 1:
The patent establishes information sharing agreements, permission settings, and deletion policies in advance through the information provision management module, before actual information exchange occurs. Users pre-configure which information categories can be shared with which service providers and under what conditions. This preliminary setup automates subsequent information flow management, ensuring both rapid service deployment and robust information protection without requiring lengthy negotiations later.
Data Source
AI summary
Provided are an apparatus and method for managing identity information. The apparatus includes a contract detail manager managing details of an identity information sharing contract made between a user and an identity provider (IdP) wanting to provide identity information about the user, and details of an identity information sharing contract made between the user and an identity consumer (IdC) wanting to be provided with the identity information about the user, an IdP selector selecting an IdP capable of providing the identity information about the user based on the details of the sharing contract when a request for the identity information about the user is input from the IdC, and an information provider obtaining information according to the identity information request from the selected IdP, and providing the obtained information to the IdC. The apparatus and method can solve a problem that all of a user's identity information is provided to an IdC according to the user's comprehensive agreement.


