Identity Management System with Honey Token Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face challenges in making informed trust decisions when providing personal information online due to phishing scams, inappropriate data leaks by legitimate sites, and loss of control over information submission and usage, despite existing authentication tools and digital certificates.

Innovation Solution

An identity management system that includes a software agent integrated with browsers, which provides reputation information about sites, facilitates the use of 'honey tokens' to detect misuse, and allows users to select credentials based on site policies and trust levels, ensuring secure and transparent information sharing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users manually enter personal information into third party sites, then users have full control and visibility over information submission, but users are vulnerable to phishing scams and cannot easily verify site trustworthiness

Engineering Contradiction:
Improvetrustworthiness verificationVSAvoidinformation verification process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary system that acts as a mediator between users and third-party sites. This intermediary collects reputation information from multiple sources, evaluates site trustworthiness, and presents this information to users through a user interface. The intermediary resolves the contradiction by providing reliable trust verification without requiring users to manually complexly verify site authenticity themselves.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary actions by proactively gathering reputation information about sites before users interact with them. The intermediary continuously monitors and evaluates site trustworthiness in advance, so when users encounter a site, the reputation assessment is already available. This eliminates the need for users to perform complex verification actions at the moment of interaction.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If users use authentication tools as intermediaries, then authentication is facilitated, but users have less control and visibility over when and what information is submitted

Engineering Contradiction:
Improveauthentication processVSAvoiduser control over information
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent implements feedback mechanisms where the intermediary provides users with real-time information about what data will be submitted to which sites, based on the site's reputation and privacy policy. Users receive feedback about the authentication process and can see exactly what information will be shared. This feedback loop maintains user control while still facilitating automated authentication.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system dynamically adjusts the authentication process based on site reputation and user preferences. Rather than a static authentication mechanism, the intermediary adapts the information submission process in real-time, allowing users to modify their information sharing choices based on the reputation information provided. This dynamic approach maintains ease of operation while preserving user control.

Inventive Principle:
Principle #15Dynamics

3Adaptability or versatility

If sites collect personal information for service provision, then service functionality is improved, but sites may inappropriately leak or misuse user information

Engineering Contradiction:
Improveservice functionalityVSAvoidinformation leakage risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The intermediary provides feedback to users about site privacy policies and actual information handling practices. By monitoring and evaluating site behavior against stated policies, the system informs users about potential information leakage risks. This feedback enables users to make informed decisions about which sites to trust with their personal information while still allowing sites to provide their services.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The intermediary acts as a mediator that verifies site compliance with privacy policies before and during information sharing. It evaluates whether sites appropriately handle user information according to their stated policies and reputation records. This mediation allows service functionality to proceed while providing a safety mechanism against information leakage and misuse.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Object-affected harmful factors

If attackers obtain digital certificates for phishing sites, then phishing effectiveness increases, but the complexity of detecting phishing sites increases

Engineering Contradiction:
Improvephishing effectivenessVSAvoidphishing site detection
Core Design Contradiction:
Object-affected harmful factorsVSDifficulty of detecting and measuring

Solution Approach 1:

The patent segments the trust evaluation process into multiple independent reputation factors rather than relying on a single certificate check. The intermediary evaluates sites based on multiple dimensions including privacy policy compliance, historical behavior, user reports, and information handling practices. This segmentation allows detection of phishing sites even when they possess valid certificates, as the multi-factor evaluation reveals inconsistencies in their overall reputation profile.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8887273B1Evaluating relying parties
Publication Date: 2014.11.11 CA TECH INC
  • US8887273B1 patent drawing
  • US8887273B1 patent drawing
  • US8887273B1 patent drawing

AI summary

Determining reputation information is disclosed. A honey token is included in an online identity data. The honey token is to monitor for misuse of all or part of the online identity data. Optionally, information associated with at least one use of the honey token is aggregated with other reputation information.