Trusted Identity Provider Selection for Secure Attribute Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current online authentication methods lack security, consistency, and ease of use, as they rely on piecemeal verification by individual companies without validation from trusted sources, leading to vulnerabilities in user identity verification and password management.

Innovation Solution

A system that allows users to select a trusted identity provider, such as a bank, to authenticate and share identity attributes with relying parties, using cryptographic technology and regulated processes to ensure secure and consistent digital identity verification across multiple online platforms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If each company handles authentication piecemeal without trusted source verification, then device complexity is reduced and ease of operation is improved, but security and reliability deteriorate

Engineering Contradiction:
Improveauthentication processVSAvoididentity verification
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a trusted identity provider as an intermediary between users and relying parties. This mediator performs centralized identity verification and attribute validation, resolving the contradiction by maintaining simple user interaction while ensuring secure and reliable authentication through a trusted third party.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a centralized trusted identity provider system is implemented, then security and reliability of identity verification are improved, but device complexity and system infrastructure complexity increase

Engineering Contradiction:
Improveidentity verificationVSAvoidauthentication system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication system into distinct functional components: identity providers that handle verification, relying parties that require authentication, and an identity network that facilitates communication. This segmentation allows each component to perform its specialized function independently, reducing overall system complexity while maintaining high reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal identity provider system that can serve multiple relying parties across different organizations and industries. This multi-functional approach consolidates authentication capabilities into a shared infrastructure, reducing the need for each company to build and maintain separate complex verification systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If traditional password-based authentication is used, then ease of operation is maintained, but security deteriorates due to password management vulnerabilities

Engineering Contradiction:
Improvelogin processVSAvoidpassword security risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent replaces the mechanical password-based authentication system with a digital credential system based on cryptographic verification. Instead of relying on users to manage passwords, the system uses machine-readable identity attributes and digital signatures, eliminating password-related security vulnerabilities while maintaining ease of use through automated verification.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS20230075915A1Identity provider selection for identity attribute sharing process
Publication Date: 2023.03.09 EARLY WARNING SERVICES LLC
  • US20230075915A1 patent drawing
  • US20230075915A1 patent drawing
  • US20230075915A1 patent drawing

AI summary

Methods of selecting an identity provider using an identity attribute sharing system may include accessing, by a user device, a page of a relying party. The methods may include receiving, by the user device, a selection to utilize an identity network to share a number of identity attributes with the relying party. The methods may include displaying, by the user device, a plurality of identity providers enrolled for use with the identity attribute sharing system. The methods may include receiving, by the user device, a selection of one of the plurality of identity providers. The methods may include providing access to a page of a selected identity provider.