Identity Management Connecting Principal Identities to Alias Identities
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Previous identity management systems are inadequate in supporting both single-identity and multiple-identity secure applications, requiring users to log in multiple times and manage separate credentials, due to incompatibilities between single-identity and multiple-identity approaches.
Innovation Solution
An identity management system that connects principal identities to alias identities with different authorization scopes, enabling simultaneous authentication and authorization for both single-identity and multiple-identity secure applications, and providing a unified interface for managing multiple sets of login credentials.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate credential sets are maintained for single-identity and multiple-identity applications, then each application can be authenticated independently, but users must log in multiple times and manage separate credentials
Solution Approach 1:
The principal identity serves multiple functions by acting as a common credential for both single-identity applications and multiple-identity applications. This universal credential eliminates the need for separate login processes, allowing users to access different application types through a single authentication mechanism while maintaining the security and independence requirements of each application type.
2Adaptability or versatility
If multiple alias identities with different authorization scopes are stored in principal database, then comprehensive authorization control is achieved, but credential management complexity increases
Solution Approach 1:
The credential management structure is segmented into distinct components: a principal identity for common authentication and multiple alias identities for application-specific authorization. Each alias identity can be independently managed with its own authorization scope, while the principal identity provides the foundation for all authentication operations. This segmentation allows comprehensive authorization control without overwhelming complexity in the overall management structure.
Solution Approach 2:
The principal identity acts as an intermediary between users and multiple alias identities. It provides a unified access point that simplifies credential management while enabling complex authorization scenarios through the alias identities. The intermediary structure allows users to authenticate once through the principal identity and then access multiple applications through different alias identities without managing multiple separate credential sets.
3Ease of operation
If a unified interface is provided for managing multiple credential sets, then user convenience is enhanced, but system complexity increases
Solution Approach 1:
Multiple credential management functions are merged into a single unified interface that handles both single-identity and multiple-identity applications. The principal identity serves as the common entry point that combines authentication and authorization functions, allowing users to manage multiple credential sets through one interface while the system internally maintains the necessary complexity for secure and flexible credential management.
Data Source
AI summary
A principal database is described in which each entry includes one principal identity, and one or more alias identities that may each have an authorization scope. Principal identity attributes include a principal identifier and login credentials, and alias identity attributes include an authorization scope and login credentials. Responsive to successfully authenticating the user for a first application (a multiple-identity application), based on the alias identity login credentials, an access token containing both the alias identity attributes and the principal identity attributes is transmitted to the first application, causing the first application to grant a scope of access based on the authorization scope. Responsive to a request to authenticate the user for a second application (a single-identity application), the access token is transmitted to the second application without re-authenticating the user, causing the second application to grant a scope of access based on the principal identifier.


