Identity Provider Validation Service for Federated Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing identity management systems face challenges in securely managing multiple online identities, leading to vulnerabilities due to the reuse of usernames and passwords and inadequate strong authentication, resulting in a growing number of identity theft cases, and there is a need for a more flexible and reliable method to assess and validate the assurance levels of identity providers in identity federation.
Innovation Solution
A method is introduced where a service computer receives an identity assertion with an indication of the provider and assurance level, accessing a store to verify if the identity provider is trusted to issue assertions at various assurance levels, and only accepts the assertion if trusted, enabling a more fine-grained and adaptable federated user identity scheme by incorporating an Identity Provider Validation Service to discriminate between assurance levels.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If identity federation is used to reduce the number of online identities, then user convenience is improved, but security is worsened due to reliance on potentially untrusted identity providers
Solution Approach 1:
The patent introduces an Identity Provider Validation Service as an intermediary between service providers and identity providers. This validator service assesses and validates identity providers before they can issue assertions, creating a trusted intermediary layer that maintains security while preserving the convenience of identity federation.
Solution Approach 2:
The system performs preliminary validation of identity providers through the Identity Provider Validation Service before they are allowed to issue identity assertions. This advance assessment ensures that only trusted identity providers can participate in the federation, preventing security issues before they occur.
2Reliability
If a centralized validation service is introduced to assess identity providers, then security is improved, but system complexity is worsened
Solution Approach 1:
The Identity Provider Validation Service performs multiple functions: it assesses identity providers, validates assertions, maintains trust relationships, and provides a centralized registry. By consolidating these functions into a single multi-functional service, the patent reduces overall system complexity compared to having separate mechanisms for each function.
3Measurement precision
If assurance levels are differentiated and validated, then measurement precision is improved, but device complexity is worsened due to additional validation layers
Solution Approach 1:
The patent applies different assurance levels and validation criteria to different identity providers and assertions based on their specific characteristics. Rather than applying a uniform validation process, the system tailors the validation depth and criteria to the local context of each identity provider, improving precision while managing complexity.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
In providing identity management in distributed systems, it is known to provide a user with a single sign-on to accounts with different service providers with whom the user interacts by communicating with the service providers' computers. Such a single sign-on is provided by having the user authenticate himself to an identity provider computer, and thereafter relying on that identity provider computer to issue identity assertions on his behalf. An identity provider validation service is proposed with which service providers can interact on receiving an identity assertion on behalf of a user. This allows the service provider to rely only on the identity provider validation service rather than having to rely on the numerous identity providers who might issue identity assertion on behalf of one of their users. Furthermore, the identity assertions include a level of assurance indication, and the identity provider validation service indicates whether each identity provider can be trusted to properly issue an identity assertion claiming that level of assurance. This provides a more fine-grained and adaptable identity management than has hitherto been provided.