Identity Provider Authenticity Reference Splitting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current single sign-on protocols, such as SAML, face security challenges when transferring confidential information through standard web browsers, as these browsers are protocol-unaware and can compromise security by reacting to predefined messages, making it difficult to ensure secure authentication and identity management.

Innovation Solution

A method and system that utilize two authenticity reference parts, generated and communicated using a communication protocol with a referrer function, to enhance security by ensuring an adversary cannot impersonate a user, even if one authenticity reference part is compromised, using secure functions like XOR or hash functions to protect identity-related information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If single sign-on protocols transfer confidential information through standard web browsers, then ease of operation is improved, but security is worsened due to protocol-unaware browser behavior

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent divides the authentication reference into multiple parts (first authenticity reference part and second authenticity reference part) that are transmitted through different channels. The browser handles the visible authentication flow while the referrer URL secretly carries the first authenticity reference part, separating the confidential data transmission from the user-visible protocol to prevent browser interference.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The referrer URL acts as an intermediary carrier that secretly transports the first authenticity reference part between communication steps without the browser's awareness. This intermediary mechanism allows confidential information to pass through the protocol-unaware browser without being intercepted or corrupted by browser behavior.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple authenticity reference parts are used to enhance security, then security is improved, but device complexity is worsened

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent reuses the existing referrer URL mechanism, which is already a standard component of HTTP communication protocols, to carry the first authenticity reference part. This multi-functional use of the referrer field (both for navigation information and for carrying authentication data) avoids adding new complex infrastructure while enhancing security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7836298B2Secure identity management
Publication Date: 2010.11.16 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US7836298B2 patent drawing
  • US7836298B2 patent drawing
  • US7836298B2 patent drawing

AI summary

The invention relates to a method for providing an identity-related information (IRI) to a requesting entity (50) by means of an identity provider (40). The invention comprises: a first authenticity reference part generation step (IVa), comprising the generation of a first authenticity reference part (art 1) by the identity provider (40); a first authenticity reference communication step (IVb, IVd) between the client application (30) and the identity provider (40) comprising the communication of the first authenticity reference part (art 1); a second authenticity reference part generation step (VI), comprising the generation of a second authenticity reference part (art 2) by the identity provider (40); a second authenticity reference communication step (VIII, IX) between the identity provider (40) and the requesting entity (50) by means of the first communication protocol comprising the communication of the second authenticity reference part (art 2) and in the referrer element the communication of the first authenticity reference part (art 1).