Identity Recognition via Signed Information Documents

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for secure sharing and collaboration of resources across networks, such as public key infrastructures, are complex and not user-friendly, making it difficult to recognize and authenticate entities outside traditional security domains.

Innovation Solution

A system and method for identity recognition and exchange using identity information documents signed by the sender, which separates identity authentication from authorization, allowing selective disclosure and storage of identity information for future recognition and authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If public key infrastructures are used to identify and authenticate entities, then identity recognition capability is improved, but system complexity increases

Engineering Contradiction:
Improveidentity recognition capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the core identity recognition function from the complex public key infrastructure. It uses a simplified approach where entities are identified by their network addresses and cryptographic signatures, removing the need for complex certificate authorities, registration processes, and trust relationship management while maintaining security through digital signatures on identity information documents.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent creates a simplified model of identity recognition that copies only the essential elements needed for authentication. Instead of implementing the full public key infrastructure with certificates and authorities, it uses lightweight identity information documents containing network addresses and cryptographic signatures, which can be verified without complex infrastructure.

Inventive Principle:
Principle #26Copying

2Adaptability or versatility

If traditional security domains with accounts and passwords are used, then authorization control is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveauthorization controlVSAvoiduser convenience
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent segments the traditional security system into two separate functions: identity recognition (authentication) and authorization. Identity recognition is handled through automatic verification of identity information documents using cryptographic signatures, while authorization is managed separately through access control lists and permissions. This segmentation eliminates the need for users to remember passwords while maintaining security through separate authentication and authorization mechanisms.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent replaces the mechanical system of password entry and verification with cryptographic signature verification. Instead of users manually entering and system verifying passwords, the system automatically verifies digital signatures on identity information documents, providing both improved security and user convenience.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If closed security domains are used, then security control is improved, but adaptability to external entities deteriorates

Engineering Contradiction:
Improvesecurity controlVSAvoidability to recognize external entities
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal identity recognition mechanism that works across different security domains and networks. The identity information document format and verification process are domain-agnostic, allowing entities from any network or organization to be recognized and authenticated. This universal approach maintains security through cryptographic verification while enabling collaboration between disparate systems without requiring domain membership.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7822988B2Method and system for identity recognition
Publication Date: 2010.10.26 MICROSOFT TECHNOLOGY LICENSING LLC
  • US7822988B2 patent drawing
  • US7822988B2 patent drawing
  • US7822988B2 patent drawing

AI summary

In accordance with various aspects, the present invention relates to methods and systems for sending an identity information document comprising selecting identity information from a self-identity information store for inclusion in the identity information document. The selected identity information is read from a self-identity information store. The identity information document is generated to include the selected identity information and one or more keys, and signed using a key associated with one of the keys included in the identity information document. The identity information document is then sent to a recipient. Receiving an identity information document comprises receiving a signed identity information document from an originator. A determination is made as to whether identity information in the identity information document is reliable. The identity information is saved in a recognized identity information store if the identity information is determined to be reliable. If the identity information is determined to be unreliable, an identity recognition number retrieved from the sender is compared to an identity recognition number generated by the recipient based on information in the received identity information document. If the identity recognition number is verified, the identity information is saved in the recognized identity information store.