Trusted Identity Provider Selection for Secure Attribute Sharing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current online authentication methods lack security, consistency, and ease of use, as they rely on piecemeal verification by individual companies without validation from trusted sources, leading to vulnerabilities in user identity verification and password management.
Innovation Solution
A system that allows users to select a trusted identity provider, such as a bank, to authenticate and share identity attributes with relying parties, using cryptographic technology and regulated processes to ensure secure and consistent digital identity verification across multiple online platforms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If each company handles authentication piecemeal without trusted source verification, then device complexity is reduced and ease of operation is improved, but security and reliability deteriorate
Solution Approach 1:
The patent introduces a trusted identity provider as an intermediary between users and relying parties. This mediator performs centralized identity verification and attribute validation, resolving the contradiction by maintaining simple user interaction while ensuring secure and reliable authentication through a trusted third party.
2Reliability
If a centralized trusted identity provider system is implemented, then security and reliability of identity verification are improved, but device complexity and system infrastructure complexity increase
Solution Approach 1:
The patent segments the authentication system into distinct functional components: identity providers that handle verification, relying parties that require authentication, and an identity network that facilitates communication. This segmentation allows each component to perform its specialized function independently, reducing overall system complexity while maintaining high reliability.
Solution Approach 2:
The patent creates a universal identity provider system that can serve multiple relying parties across different organizations and industries. This multi-functional approach consolidates authentication capabilities into a shared infrastructure, reducing the need for each company to build and maintain separate complex verification systems.
3Ease of operation
If traditional password-based authentication is used, then ease of operation is maintained, but security deteriorates due to password management vulnerabilities
Solution Approach 1:
The patent replaces the mechanical password-based authentication system with a digital credential system based on cryptographic verification. Instead of relying on users to manage passwords, the system uses machine-readable identity attributes and digital signatures, eliminating password-related security vulnerabilities while maintaining ease of use through automated verification.
Data Source
AI summary
Methods of selecting an identity provider using an identity attribute sharing system may include accessing, by a user device, a page of a relying party. The methods may include receiving, by the user device, a selection to utilize an identity network to share a number of identity attributes with the relying party. The methods may include displaying, by the user device, a plurality of identity providers enrolled for use with the identity attribute sharing system. The methods may include receiving, by the user device, a selection of one of the plurality of identity providers. The methods may include providing access to a page of a selected identity provider.


