Identity Management System Using Profile Data Mining for Familiar Claims Provider Selection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing identity management systems are often cumbersome or non-intuitive for users, leading to mistrust and poor adoption, while also potentially allowing companies to track individuals' online activities, compromising privacy.

Innovation Solution

The system mines profile data to identify familiar claims providers and presents a candidate set of both user-familiar and relying-party-allowed claims providers, enabling users to select suitable claims without revealing unnecessary information, thereby maintaining privacy and improving user experience.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If secure identity management systems are implemented, then security and reliability are improved, but user experience and ease of operation deteriorate due to cumbersome processes

Engineering Contradiction:
ImprovesecurityVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically mines profile data from multiple sources (social media, browsing history, purchase history) to generate candidate claims providers without requiring user input. The user simply selects from pre-generated options, making the secure identity verification process self-service and intuitive.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by proactively gathering profile data and identifying familiar claims providers before the user needs to authenticate. This pre-computation eliminates the need for users to manually search for or configure security settings during the authentication process.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If traditional identity management systems are used, then security is maintained, but privacy is compromised due to tracking of user activities

Engineering Contradiction:
ImprovesecurityVSAvoidprivacy
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system applies local quality by allowing different claims providers to be selected for different contexts or services. Users can grant fine-grained control over which aspects of their identity are verified by which providers, enabling security for specific services while maintaining privacy in other areas.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system segments the identity verification process into multiple independent claims providers, each handling specific types of claims. This segmentation allows users to selectively engage only the necessary providers for each service, preventing comprehensive tracking while maintaining security where needed.

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If comprehensive profile data is collected, then accuracy of identifying familiar claims providers is improved, but processing time and system complexity increase

Engineering Contradiction:
ImproveaccuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system uses partial action by collecting only the specific profile data elements needed to identify familiar claims providers (such as browsing history related to specific services or social media connections), rather than comprehensively analyzing all user data. This selective approach maintains accuracy while reducing processing time.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9571491B2Discovery of familiar claims providers
Publication Date: 2017.02.14 MICROSOFT TECHNOLOGY LICENSING LLC
  • US9571491B2 patent drawing
  • US9571491B2 patent drawing
  • US9571491B2 patent drawing

AI summary

Aspects of the subject matter described herein relate to identity technology. In aspects, profile data is mined to determine claims providers with which a user may be familiar. These familiar claims providers are used in conjunction with claims providers that are allowed by a relying party to determine a candidate set of claims providers that are both familiar to the user and allowed by the relying party. This candidate set of claims providers is then displayed to a user so that the user may select one or more of the claims providers to obtain claims to provide to the relying party.