Identity Management Connecting Principal Identities to Alias Identities

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Previous identity management systems are inadequate in supporting both single-identity and multiple-identity secure applications, requiring users to log in multiple times and manage separate credentials, due to incompatibilities between single-identity and multiple-identity approaches.

Innovation Solution

An identity management system that connects principal identities to alias identities with different authorization scopes, enabling simultaneous authentication and authorization for both single-identity and multiple-identity secure applications, and providing a unified interface for managing multiple sets of login credentials.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate credential sets are maintained for single-identity and multiple-identity applications, then each application can be authenticated independently, but users must log in multiple times and manage separate credentials

Engineering Contradiction:
Improveauthentication independenceVSAvoiduser login convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The principal identity serves multiple functions by acting as a common credential for both single-identity applications and multiple-identity applications. This universal credential eliminates the need for separate login processes, allowing users to access different application types through a single authentication mechanism while maintaining the security and independence requirements of each application type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If multiple alias identities with different authorization scopes are stored in principal database, then comprehensive authorization control is achieved, but credential management complexity increases

Engineering Contradiction:
Improveauthorization scope flexibilityVSAvoidcredential management structure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The credential management structure is segmented into distinct components: a principal identity for common authentication and multiple alias identities for application-specific authorization. Each alias identity can be independently managed with its own authorization scope, while the principal identity provides the foundation for all authentication operations. This segmentation allows comprehensive authorization control without overwhelming complexity in the overall management structure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The principal identity acts as an intermediary between users and multiple alias identities. It provides a unified access point that simplifies credential management while enabling complex authorization scenarios through the alias identities. The intermediary structure allows users to authenticate once through the principal identity and then access multiple applications through different alias identities without managing multiple separate credential sets.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If a unified interface is provided for managing multiple credential sets, then user convenience is enhanced, but system complexity increases

Engineering Contradiction:
Improvecredential management convenienceVSAvoididentity management system structure
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

Multiple credential management functions are merged into a single unified interface that handles both single-identity and multiple-identity applications. The principal identity serves as the common entry point that combines authentication and authorization functions, allowing users to manage multiple credential sets through one interface while the system internally maintains the necessary complexity for secure and flexible credential management.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11962593B2Identity management connecting principal identities to alias identities having authorization scopes
Publication Date: 2024.04.16 CITRIX SYSTEMS INC
  • US11962593B2 patent drawing
  • US11962593B2 patent drawing
  • US11962593B2 patent drawing

AI summary

A principal database is described in which each entry includes one principal identity, and one or more alias identities that may each have an authorization scope. Principal identity attributes include a principal identifier and login credentials, and alias identity attributes include an authorization scope and login credentials. Responsive to successfully authenticating the user for a first application (a multiple-identity application), based on the alias identity login credentials, an access token containing both the alias identity attributes and the principal identity attributes is transmitted to the first application, causing the first application to grant a scope of access based on the authorization scope. Responsive to a request to authenticate the user for a second application (a single-identity application), the access token is transmitted to the second application without re-authenticating the user, causing the second application to grant a scope of access based on the principal identifier.