Federated Identity Metadata Resolution for Phishing Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional federated identity verification systems are vulnerable to security risks, particularly phishing attacks, as users must rely on relying parties to direct them to trusted identity providers, which can lead to malicious identity providers stealing identities.
Innovation Solution
Implementing a system where clients independently verify and resolve metadata to identify trusted identity providers, establishing a digital identity representation, and obtaining security tokens through independent verification, using metadata elements that describe the location and security requirements of digital identity representation provisioning services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If relying parties directly direct users to identity providers, then service access efficiency is improved, but security vulnerability to phishing attacks increases
Solution Approach 1:
The patent introduces an identity metadata service as an intermediary between relying parties and identity providers. This service stores and provides identity provider metadata (including endpoints and identifiers) to clients, allowing clients to independently resolve trusted identity providers without relying on direct redirection from potentially malicious relying parties, thus maintaining efficiency while enhancing security
Solution Approach 2:
The system performs preliminary actions by pre-storing identity provider metadata (endpoints, identifiers, trust relationships) in an identity metadata service before any authentication occurs. This allows clients to proactively verify and resolve trusted identity providers independently, preventing phishing attacks before they can occur while maintaining efficient service access
2Adaptability or versatility
If users establish trust relationships with multiple identity providers, then service accessibility is improved, but complexity of managing digital identities increases
Solution Approach 1:
The identity metadata service provides universal functionality by serving multiple purposes: storing identity provider endpoints, verifying trust relationships, resolving identifiers to endpoints, and providing metadata for multiple different identity providers. This single service handles all identity resolution needs across multiple providers, maintaining service accessibility while reducing management complexity
Solution Approach 2:
The system enables self-service by allowing clients to independently query the identity metadata service for trusted identity provider information and resolve identifiers to endpoints autonomously. This eliminates the need for manual configuration or complex user management of multiple identity provider relationships, as the system automatically handles the complexity while maintaining broad service accessibility
Data Source
AI summary
A federated identity provisioning system includes relying parties, identity providers, and clients that obtain tokens from identity providers for access to a relying party's services. When a client contacts a new relying party, the relying party provides information that the client can independently resolve and evaluate for trustworthiness. For example, the relying party provides a generic domain name address. The client can then resolve the domain name address over various, authenticated steps to identity an endpoint for a digital identity provisioning service. The client can further interact with and authenticate the provisioning service (e.g., requiring digital signatures) to establish a trust relationship. Once determining that the client/user trusts the provisioning service, the client/user can then provide information to obtain a digital identity representation. The client can then use the digital identity representation with the corresponding identity provider to obtain one or more tokens that the relying party can validate.


