Identity Mapping Security via Dual Digital Signatures

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In heterogeneous domains, users authenticated in one domain often need to re-authenticate to access resources in another domain, leading to security gaps due to unverified identity mapping information, which can be exploited by malicious attacks.

Innovation Solution

Digitally signing identity mapping information by both the user and the identity management system, using public/private cryptography and twofold encryption, allows for verification of integrity and increased security, ensuring that only authorized parties can access and modify the data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If identity mapping information is stored in a database for enabling cross-domain access, then user convenience and system interoperability are improved, but security is worsened because the stored information cannot be verified at runtime and may be exploited by malicious attacks

Engineering Contradiction:
Improvecross-domain access convenienceVSAvoididentity mapping security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by having the user digitally sign the identity mapping information before it is stored in the database. This signature is created in advance using the user's private key, so that when the mapping information is later retrieved and used for cross-domain access, its integrity can be verified without requiring the user to be present or to re-authenticate. This resolves the contradiction by pre-establishing verification capability that maintains both convenience and security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces digital signatures as an intermediary mechanism between the user and the stored identity mapping information. The signature acts as a mediator that carries verification information without requiring the user's direct involvement during runtime. The mapping information is signed by the user, then further signed by the identity management system, creating a chain of trust that allows verification without compromising either security or operational convenience.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If identity mapping information is automatically trusted and stored without verification, then system complexity is reduced and operation is simplified, but security gaps are created that can be exploited by malicious attacks

Engineering Contradiction:
Improveverification system complexityVSAvoidmalicious attack vulnerability
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces digital signatures as an intermediary mechanism that provides verification without significantly increasing system complexity. The signature verification process is automated and integrated into the existing identity management workflow, adding minimal computational overhead while effectively preventing malicious attacks by ensuring the integrity of stored mapping information.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces manual or complex verification mechanisms with cryptographic digital signatures. Instead of requiring complex runtime verification protocols or user involvement, the system uses mathematical cryptography to provide automatic, efficient, and secure verification of identity mapping information, reducing complexity while enhancing security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If digital signatures are implemented for identity mapping information, then security and integrity verification are improved, but computational overhead and processing time increase

Engineering Contradiction:
Improvemapping information integrityVSAvoidsignature verification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by performing the computationally intensive digital signature creation process in advance, during the initial setup or identity management phase, rather than during runtime when cross-domain access is required. The signature is created once and stored with the mapping information, so that during access operations, only verification is needed, which is faster and less resource-intensive.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent merges the creation of digital signatures with the identity management processes that already occur during user authentication and domain access setup. By combining the signing operation with existing identity verification and mapping establishment procedures, the patent avoids adding separate, time-consuming steps while still providing comprehensive security verification.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8555075B2Methods and system for storing and retrieving identity mapping information
Publication Date: 2013.10.08 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US8555075B2 patent drawing
  • US8555075B2 patent drawing
  • US8555075B2 patent drawing

AI summary

System and method for storing identity mapping information in an identity management system to enable a user authenticated at a first domain to access a second domain. The method may include digitally signing the identity mapping information by the user; providing the mapping information to an identity management system; and storing the user-signed mapping information after being further digitally signed by the identity management system.