Global Identity Profile Aggregation for Risk Assessment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Previous computer security systems perform limited risk assessments due to reliance on local identity data from individual service providers, lacking the ability to leverage identity data from multiple online service providers, which results in inaccurate risk determination and limited access control.
Innovation Solution
A system that aggregates user identity data from multiple sources into a privately maintained global profile, allowing users to control distribution to trusted risk engines for more comprehensive risk assessments, enabling the use of both local and aggregated identity data for enhanced access control and authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If risk assessments are performed using only local identity data from individual service providers, then the system maintains simplicity and ease of operation, but the measurement precision and reliability of risk assessment deteriorate due to limited data scope
Solution Approach 1:
The patent combines identity data from multiple service providers into a unified risk assessment process. The system merges local identity data from individual service providers with global identity data aggregated from multiple sources, enabling comprehensive risk evaluation that maintains operational simplicity while significantly improving assessment accuracy through expanded data scope.
2Reliability
If identity data is aggregated from multiple service providers into a global profile, then the reliability and measurement precision of risk assessment improves, but the device complexity and data management burden increases
Solution Approach 1:
The patent introduces an identity data collector as an intermediary component that automatically aggregates identity data from multiple service providers and maintains a global profile. This intermediary handles the complexity of data collection, normalization, and storage, allowing the risk assessment system to access comprehensive data without directly managing the complexity of multi-source data integration.
Solution Approach 2:
The system segments the risk assessment architecture into distinct functional components: local risk assessment modules at individual service providers, a centralized identity data collector that aggregates global data, and a risk assessment service that combines both local and global data. This segmentation allows each component to operate independently with well-defined interfaces, reducing overall system complexity while improving reliability.
3Reliability
If users have full control over data distribution to risk engines, then user privacy protection improves, but the ease of operation and automation level deteriorates due to required user interventions
Solution Approach 1:
The patent implements preliminary action by obtaining user consent and authorization before data aggregation and distribution occurs. The system proactively secures user permission through consent mechanisms, then automatically proceeds with data collection and sharing based on the granted authorization. This approach ensures privacy protection through user control while maintaining high automation levels during the actual data processing operations.
Solution Approach 2:
The system incorporates feedback mechanisms that provide users with visibility into what data is being collected, from which sources, and where it is being distributed. Users can review and modify their data sharing preferences based on this feedback, ensuring ongoing control over their privacy settings while allowing the system to operate automatically within the boundaries of user authorization.
Data Source
AI summary
Identity data for a user is aggregated from multiple sources into a global profile, the contents of which is distributed under the control of the user to trusted risk engines. The collected identity data is related to the user's use of online services provided by multiple independent service providers. The collected identity data is aggregated into a private, global profile. The user must authorize the portion(s) of the aggregated identity data that is/are distributed, and one or more trusted risk engines to which the aggregated identity data may distributed. The global profile may be distributed to individual trusted risk engines, further based on requests received from individual ones of the trusted risk engines.


