User-Centric Identity Management with Transparent Data Flow

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users are hesitant to utilize identity management technologies due to unfamiliarity with 'behind-the-scenes' procedures and concerns about data exposure to untrusted systems, leading to avoidance of secure information sharing between organizations.

Innovation Solution

Implementing user-centric identity management that provides transparent data flow indications and user control over identity management processes, allowing users to confirm or prevent data exchange between service providers and identity providers, using technologies like SAML, OAuth, and single sign-on for secure authentication and authorization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If identity management technologies are implemented to enable secure information sharing between organizations, then security and data portability are improved, but user trust and adoption deteriorate due to lack of transparency and user control

Engineering Contradiction:
Improvesecure information sharingVSAvoiduser adoption
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system provides real-time feedback to users about data flow between organizations through visual indicators and notifications. Users can see what data is being shared, with whom, and for what purpose, transforming the black-box identity management process into a transparent, user-controlled experience that builds trust while maintaining security

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces an intermediary layer between the identity management system and the user that provides visual representations and control mechanisms. This intermediary translates complex backend processes into user-friendly interfaces, allowing users to understand and control data sharing without compromising the underlying security protocols

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If transparent data flow indications and user control mechanisms are added to identity management systems, then user assurance and adoption are improved, but system complexity increases

Engineering Contradiction:
Improveuser assuranceVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system segments the complex identity management process into distinct, visually representable components: data flow indicators, user control mechanisms, and organizational boundaries. This segmentation allows the complex system to be presented in a simplified, modular way that is easier for users to understand and interact with

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates visual copies or representations of the actual data flow processes through graphical interfaces and indicators. These visual copies simplify the presentation of complex backend operations, allowing users to grasp the essence of data sharing without needing to understand the underlying technical complexity

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11297059B2Facilitating user-centric identity management
Publication Date: 2022.04.05 ADOBE INC
  • US11297059B2 patent drawing
  • US11297059B2 patent drawing
  • US11297059B2 patent drawing

AI summary

Embodiments of the present invention provide systems, methods, and computer storage media for facilitating user-centric identity management. In this regard, various aspects of identity management are designed to be more transparent to users to bolster user assurance with respect to “behind-the-scenes” procedures of identity management. Generally, indications of data flow between service providers, identity providers, and/or user devices can be provided to the user device for presentation to the user. As a result, visual representations of data flow, notifications of data flow, or the like, can be presented to the user to expose various aspects of identity management. In some embodiments, users may be able to control aspects of identity management, for example, by confirming or preventing data flow between providers.