Identity Provider Integration for Cookie-Free Device Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for obtaining user device identifiers rely on cookies, which can be changed or deleted, leading to privacy and fraud concerns, and require additional identity verification steps.

Innovation Solution

A method and system that utilize a computer to receive a request from a mobile device, obtain a computer address, provide it to the mobile device, route an access request to an identity provider computer, and determine if the identity data matches previously stored data to provide a list of user device identifiers, eliminating the need for cookies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cookies are used to store user device identifiers, then the system can provide user device identifiers upon request, but the cookies can be changed or deleted, making obtaining the list more difficult or impossible

Engineering Contradiction:
Improveavailability of user device identifiersVSAvoidcookie modification or deletion
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an identity provider computer as an intermediary between the mobile device and the remote computer. Instead of storing identifiers directly in cookies on the mobile device, the system uses the identity provider as a mediator that maintains the mapping between device identifiers and user identities, eliminating the harmful effect of cookie modification while maintaining availability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a derivative of the identity data that can be transmitted and verified without requiring the original identity data to be stored in cookies. The derivative serves as a copy that maintains the necessary identification functionality while avoiding the storage vulnerabilities of cookies.

Inventive Principle:
Principle #26Copying

2Reliability

If cookies are used to obtain user device identifiers, then the system can provide identifiers, but privacy and fraud concerns increase due to cookies being obtained from malicious parties

Engineering Contradiction:
Improveobtaining user device identifiersVSAvoidprivacy and fraud risks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The identity provider computer acts as a trusted intermediary that manages identity data securely. Instead of relying on cookies that can be obtained from malicious parties, the system uses the identity provider as a mediator that verifies user identity through controlled communication channels, thereby reducing privacy and fraud risks while maintaining reliable identifier provision.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If traditional verification methods are used, then user identity can be verified, but additional verification steps are required (e.g., one-time passwords, username and password login)

Engineering Contradiction:
Improveuser identity verificationVSAvoidverification process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses a derivative of the identity data that can be transmitted and verified without requiring users to perform additional verification steps. The derivative serves as a condensed representation of user identity that can be validated by the system without demanding extra user actions, thereby reducing verification process complexity while maintaining security.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system performs preliminary identity verification through the identity provider before the user needs to access services. By pre-establishing the identity mapping and storing derivatives of identity data, the system eliminates the need for additional verification steps at the point of use, reducing complexity while maintaining reliable verification.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250291892A1Method and system for integrating identity provider
Publication Date: 2025.09.18 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US20250291892A1 patent drawing
  • US20250291892A1 patent drawing
  • US20250291892A1 patent drawing

AI summary

A method includes a computer receiving a request to conduct an interaction from a mobile device. The computer obtains a computer address and provides the computer address to the mobile device. The mobile device provides an access request to the computer address, and the access request is thereafter routed to an identity provider computer. The identity provider computer identifies identity data associated with the mobile device or a user of the mobile device. The computer obtains the identity data or a derivative of the identity data from the identity provider computer. The computer determines if the identity data or the derivative of the identity data matches previously stored identity data or a previously stored derivative of identity data. If a match is determined, the computer provides a list of user device identifiers to the mobile device.