Identity Provider Validation Service for Federated Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing identity management systems face challenges in securely managing multiple online identities, leading to vulnerabilities due to the reuse of usernames and passwords and inadequate strong authentication, resulting in a growing number of identity theft cases, and there is a need for a more flexible and reliable method to assess and validate the assurance levels of identity providers in identity federation.

Innovation Solution

A method is introduced where a service computer receives an identity assertion with an indication of the provider and assurance level, accessing a store to verify if the identity provider is trusted to issue assertions at various assurance levels, and only accepts the assertion if trusted, enabling a more fine-grained and adaptable federated user identity scheme by incorporating an Identity Provider Validation Service to discriminate between assurance levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If identity federation is used to reduce the number of online identities, then user convenience is improved, but security is worsened due to reliance on potentially untrusted identity providers

Engineering Contradiction:
Improveuser convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an Identity Provider Validation Service as an intermediary between service providers and identity providers. This validator service assesses and validates identity providers before they can issue assertions, creating a trusted intermediary layer that maintains security while preserving the convenience of identity federation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary validation of identity providers through the Identity Provider Validation Service before they are allowed to issue identity assertions. This advance assessment ensures that only trusted identity providers can participate in the federation, preventing security issues before they occur.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If a centralized validation service is introduced to assess identity providers, then security is improved, but system complexity is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The Identity Provider Validation Service performs multiple functions: it assesses identity providers, validates assertions, maintains trust relationships, and provides a centralized registry. By consolidating these functions into a single multi-functional service, the patent reduces overall system complexity compared to having separate mechanisms for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If assurance levels are differentiated and validated, then measurement precision is improved, but device complexity is worsened due to additional validation layers

Engineering Contradiction:
Improveassurance level discriminationVSAvoidvalidation complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies different assurance levels and validation criteria to different identity providers and assertions based on their specific characteristics. Rather than applying a uniform validation process, the system tailors the validation depth and criteria to the local context of each identity provider, improving precision while managing complexity.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP2258095B1Identity management
Publication Date: 2019.04.03 BRITISH TELECOM PLC
  • EP2258095B1 patent drawingFigure 1
  • EP2258095B1 patent drawingFigure 2
  • EP2258095B1 patent drawingFigure 3

AI summary

In providing identity management in distributed systems, it is known to provide a user with a single sign-on to accounts with different service providers with whom the user interacts by communicating with the service providers' computers. Such a single sign-on is provided by having the user authenticate himself to an identity provider computer, and thereafter relying on that identity provider computer to issue identity assertions on his behalf. An identity provider validation service is proposed with which service providers can interact on receiving an identity assertion on behalf of a user. This allows the service provider to rely only on the identity provider validation service rather than having to rely on the numerous identity providers who might issue identity assertion on behalf of one of their users. Furthermore, the identity assertions include a level of assurance indication, and the identity provider validation service indicates whether each identity provider can be trusted to properly issue an identity assertion claiming that level of assurance. This provides a more fine-grained and adaptable identity management than has hitherto been provided.