Identity Management System Policy Change Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face challenges in controlling the release of personal and financial information due to site policies that can be changed without notification, often exploited by malicious sites for unauthorized data usage.
Innovation Solution
An identity management system that allows users to manage and monitor site policies, using an identity provider with modules like policy analyzer and change detector to evaluate and alert users to policy changes, enabling controlled access to identity information based on user preferences.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If site policies allow automatic modification without notification, then site operation convenience is improved, but user control over identity information release is worsened
Solution Approach 1:
The system implements feedback by notifying users when site policies change and allowing users to respond to these changes. The policy change notification mechanism ensures users are informed of modifications to their identity information access rights, enabling them to maintain control despite automated policy updates.
Solution Approach 2:
The system performs preliminary action by establishing user preferences and control settings before policy changes occur. Users can pre-configure their identity information release preferences, and the system uses these pre-established controls to automatically respond to policy changes by blocking information release when unfavorable modifications are detected.
2Reliability
If users are notified of all policy changes, then user awareness and control are improved, but system complexity and notification overhead are worsened
Solution Approach 1:
The system applies local quality by tailoring notification content to individual user preferences and priorities. Rather than uniformly notifying all users about all policy changes, the system customizes notifications based on each user's specific identity information release preferences and control settings, reducing unnecessary notifications while maintaining awareness for critical changes.
Data Source
AI summary
Controlling identity disclosures is disclosed. A difference between a site policy as received at a first time and the site policy as received at a second time is detected through at least partially automated processing. The existence of the difference is indicated before disclosing to a relying party associated with the site policy, at or subsequent to the second time, an identity information.


