Identity Attribute Server Mediator for Secure DI Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The integration of digital identity (DI) information from multiple sources creates an exponential N×N computing problem, and there is a risk of unauthorized exposure of personally identifiable information due to the lack of standardization and secure transfer methods across DI providers.

Innovation Solution

A method and system for securely providing identity attributes involve a server computer that receives a request from a relying entity, validates it, identifies the appropriate package and data access token, and transmits a request to a digital identity provider to retrieve the necessary identity attributes, ensuring secure transmission and access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If integration between each individual DI source is implemented, then accessibility of identity information is improved, but system complexity increases exponentially

Engineering Contradiction:
Improveaccessibility of identity informationVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a central server computer as an intermediary between relying entities and multiple digital identity providers. The server receives identity attribute requests from relying entities, validates them, retrieves the appropriate packages and data access tokens, and then obtains the actual identity attributes from the DI providers. This intermediary approach eliminates the need for relying entities to directly integrate with each DI source, thereby reducing the exponential complexity while maintaining broad accessibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The server computer performs multiple functions: it acts as a request validator, a package identifier, a data access token manager, and a communication hub between relying entities and DI providers. This multi-functional design consolidates what would otherwise require numerous separate integration points into a single universal system that handles all identity attribute requests regardless of the underlying DI source.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Loss of information

If multiple entities store and transmit personally identifiable information, then information availability is improved, but security risk increases

Engineering Contradiction:
Improveinformation availabilityVSAvoidsecurity risk
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts personally identifiable information from the relying entities and stores it only in the secure environment of the server computer and DI providers. The relying entities never store or transmit the actual identity attributes, only de-identified request parameters. This extraction of sensitive data from the relying entity environment significantly reduces the security risk while maintaining information availability through the server's secure retrieval mechanism.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent employs data access tokens that are temporary and single-use or limited-use in nature. These tokens are generated for specific requests and expire after use, eliminating the need for long-term storage of authentication credentials and reducing the attack surface for security breaches. The tokens are disposed of after serving their purpose, minimizing the risk of persistent exposure.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS12192362B2Secure data transfer system and method
Publication Date: 2025.01.07 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US12192362B2 patent drawing
  • US12192362B2 patent drawing
  • US12192362B2 patent drawing

AI summary

Disclosed are methods and systems for securely providing identity attributes. A server computer may receive, from a relying entity, a request for identity attributes associated with a target entity, wherein the request for identity attributes includes a session identifier associated with the target entity and an identifier of the relying entity. The server computer may validate the request based on the session identifier. The server computer may identify, based on the identifier of the relying entity, a package defining types of identity attributes for the relying entity and a data access token associated with the package. Based on validating the request, the server computer may transmit, to a digital identity provider, a request for a set of identity attributes corresponding to the package, the request comprising the data access token. The server computer may receive, from the digital identity provider, the set of identity attributes.