Identity Provider Mediator for Client Trust Establishment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems lack effective methods to establish trust between service providers and clients, particularly in online transactions, as they fail to verify the authorization of clients using stolen identity details, leading to potential fraud and security breaches.
Innovation Solution
A method and system utilizing cryptographic protocols to verify the identity of clients by sharing secrets between an identity provider and a service provider, ensuring data authenticity and integrity through signed and encrypted channels, and determining the level of trust based on authentication criteria, preventing fraudulent access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cryptographic protocols and secret sharing between identity provider and service provider are implemented, then security and trust establishment are improved, but system complexity and authentication overhead increase
Solution Approach 1:
The patent introduces an identity provider as an intermediary entity that mediates between the client and service provider. The identity provider generates and manages cryptographic secrets, verifies client identities, and provides authentication certificates to service providers. This intermediary approach centralizes the complexity of cryptographic protocol management and secret distribution, allowing the service provider and client to interact through a standardized authentication interface rather than implementing complex cryptographic protocols directly between them.
Solution Approach 2:
The system performs preliminary authentication and secret sharing actions before the actual service transaction. The identity provider pre-issues cryptographic secrets to authorized clients and pre-establishes trust relationships with service providers. When a client accesses a service, the authentication is already validated through these preliminary actions, reducing the computational overhead during the actual service interaction.
2Reliability
If multiple authentication criteria and identity verification steps are implemented, then fraud prevention is improved, but authentication time and user convenience deteriorate
Solution Approach 1:
The system implements partial authentication by allowing service access based on the level of trust established. For low-risk services or trusted clients, the authentication may be simplified to basic identity verification. For high-risk operations or untrusted clients, more extensive verification steps are triggered. This partial action approach ensures adequate fraud prevention for each specific context without uniformly applying maximum authentication complexity to all transactions.
Solution Approach 2:
The authentication requirements are dynamically adjusted based on parameters such as the service type, transaction value, client trust level, and risk assessment. The system changes the authentication parameters (e.g., requiring additional verification steps only when necessary) rather than maintaining fixed stringent authentication for all cases. This allows the system to adapt the authentication intensity to the actual risk level, reducing unnecessary authentication time for low-risk operations.
Data Source
AI summary
Trust is established between a service provider (20) and a client (10) of the service provider (20). The client (10) is associated with a party that is known by an identity provider (50), and the identity provider (50) is trusted by the service provider (20). The identity provider (50) contacts (70) the party (80) via a predetermined medium, and requests the party to identify itself. The identity provider (50) determines whether the identity of the identifying party (80) corresponds to an identity held by the identity provider (50) for the party and shares a secret (100) with the identifying party (80) in the event that the identity provider (50) has determined that the identity of the identifying party (80) is the same as said identity held by the identity provider (50).


