Identity Provider Integration for Cookie-Free Device Identification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for obtaining user device identifiers rely on cookies, which can be changed or deleted, leading to privacy and fraud concerns, and require additional identity verification steps.
Innovation Solution
A method and system that utilize a computer to receive a request from a mobile device, obtain a computer address, provide it to the mobile device, route an access request to an identity provider computer, and determine if the identity data matches previously stored data to provide a list of user device identifiers, eliminating the need for cookies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cookies are used to store user device identifiers, then the system can provide user device identifiers upon request, but the cookies can be changed or deleted, making obtaining the list more difficult or impossible
Solution Approach 1:
The patent introduces an identity provider computer as an intermediary between the mobile device and the remote computer. Instead of storing identifiers directly in cookies on the mobile device, the system uses the identity provider as a mediator that maintains the mapping between device identifiers and user identities, eliminating the harmful effect of cookie modification while maintaining availability.
Solution Approach 2:
The patent creates a derivative of the identity data that can be transmitted and verified without requiring the original identity data to be stored in cookies. The derivative serves as a copy that maintains the necessary identification functionality while avoiding the storage vulnerabilities of cookies.
2Reliability
If cookies are used to obtain user device identifiers, then the system can provide identifiers, but privacy and fraud concerns increase due to cookies being obtained from malicious parties
Solution Approach 1:
The identity provider computer acts as a trusted intermediary that manages identity data securely. Instead of relying on cookies that can be obtained from malicious parties, the system uses the identity provider as a mediator that verifies user identity through controlled communication channels, thereby reducing privacy and fraud risks while maintaining reliable identifier provision.
3Reliability
If traditional verification methods are used, then user identity can be verified, but additional verification steps are required (e.g., one-time passwords, username and password login)
Solution Approach 1:
The patent uses a derivative of the identity data that can be transmitted and verified without requiring users to perform additional verification steps. The derivative serves as a condensed representation of user identity that can be validated by the system without demanding extra user actions, thereby reducing verification process complexity while maintaining security.
Solution Approach 2:
The system performs preliminary identity verification through the identity provider before the user needs to access services. By pre-establishing the identity mapping and storing derivatives of identity data, the system eliminates the need for additional verification steps at the point of use, reducing complexity while maintaining reliable verification.
Data Source
AI summary
A method includes a computer receiving a request to conduct an interaction from a mobile device. The computer obtains a computer address and provides the computer address to the mobile device. The mobile device provides an access request to the computer address, and the access request is thereafter routed to an identity provider computer. The identity provider computer identifies identity data associated with the mobile device or a user of the mobile device. The computer obtains the identity data or a derivative of the identity data from the identity provider computer. The computer determines if the identity data or the derivative of the identity data matches previously stored identity data or a previously stored derivative of identity data. If a match is determined, the computer provides a list of user device identifiers to the mobile device.


