Federated Identity Metadata Resolution for Phishing Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional federated identity verification systems are vulnerable to security risks, particularly phishing attacks, as users must rely on relying parties to direct them to trusted identity providers, which can lead to malicious identity providers stealing identities.

Innovation Solution

Implementing a system where clients independently verify and resolve metadata to identify trusted identity providers, establishing a digital identity representation, and obtaining security tokens through independent verification, using metadata elements that describe the location and security requirements of digital identity representation provisioning services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If relying parties directly direct users to identity providers, then service access efficiency is improved, but security vulnerability to phishing attacks increases

Engineering Contradiction:
Improveservice access efficiencyVSAvoidphishing attack risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an identity metadata service as an intermediary between relying parties and identity providers. This service stores and provides identity provider metadata (including endpoints and identifiers) to clients, allowing clients to independently resolve trusted identity providers without relying on direct redirection from potentially malicious relying parties, thus maintaining efficiency while enhancing security

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary actions by pre-storing identity provider metadata (endpoints, identifiers, trust relationships) in an identity metadata service before any authentication occurs. This allows clients to proactively verify and resolve trusted identity providers independently, preventing phishing attacks before they can occur while maintaining efficient service access

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If users establish trust relationships with multiple identity providers, then service accessibility is improved, but complexity of managing digital identities increases

Engineering Contradiction:
Improveservice accessibilityVSAvoididentity management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The identity metadata service provides universal functionality by serving multiple purposes: storing identity provider endpoints, verifying trust relationships, resolving identifiers to endpoints, and providing metadata for multiple different identity providers. This single service handles all identity resolution needs across multiple providers, maintaining service accessibility while reducing management complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system enables self-service by allowing clients to independently query the identity metadata service for trusted identity provider information and resolve identifiers to endpoints autonomously. This eliminates the need for manual configuration or complex user management of multiple identity provider relationships, as the system automatically handles the complexity while maintaining broad service accessibility

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8074258B2Obtaining digital identities or tokens through independent endpoint resolution
Publication Date: 2011.12.06 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8074258B2 patent drawing
  • US8074258B2 patent drawing
  • US8074258B2 patent drawing

AI summary

A federated identity provisioning system includes relying parties, identity providers, and clients that obtain tokens from identity providers for access to a relying party's services. When a client contacts a new relying party, the relying party provides information that the client can independently resolve and evaluate for trustworthiness. For example, the relying party provides a generic domain name address. The client can then resolve the domain name address over various, authenticated steps to identity an endpoint for a digital identity provisioning service. The client can further interact with and authenticate the provisioning service (e.g., requiring digital signatures) to establish a trust relationship. Once determining that the client/user trusts the provisioning service, the client/user can then provide information to obtain a digital identity representation. The client can then use the digital identity representation with the corresponding identity provider to obtain one or more tokens that the relying party can validate.