Identity SIP Application Server as SAML Bridge for IMS Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Identity theft is a significant threat due to compromised online credentials, with malicious actors hijacking identities and causing substantial financial losses, as existing security measures often fail to detect unauthorized access in a timely manner, especially in IP multimedia subsystem (IMS) and non-IMS networks.

Innovation Solution

A system and method utilizing an identity session initiation protocol (SIP) application server configured as a security assertion markup language (SAML) bridge, allowing SIP-enabled and non-SIP-enabled devices to attach to telecommunications service provider networks, processing credentials to identify subscribers and notify them of login attempts, thereby enabling real-time authentication and authorization management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security systems are used to detect unauthorized access, then system complexity is reduced, but detection speed and accuracy deteriorate, allowing thieves to mimic usage patterns without triggering alarms

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements continuous monitoring of credential usage patterns and provides real-time feedback by comparing actual usage against established patterns. When deviations are detected (such as unauthorized login attempts or anomalous transaction patterns), the system immediately triggers alerts and can automatically block further access, creating a closed-loop security mechanism that learns and adapts to user behavior

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary actions by establishing baseline usage patterns for each credential set before unauthorized access occurs. It pre-configures alert thresholds and automatic response protocols so that when anomalies are detected, the system can react immediately without requiring complex real-time analysis, thereby improving detection speed while managing complexity

Inventive Principle:
Principle #10Preliminary action

2Reliability

If real-time notification systems are implemented to alert subscribers of login attempts, then identity theft protection is improved, but network latency increases

Engineering Contradiction:
Improveidentity theft protectionVSAvoidnotification latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system pre-configures notification routes and alert protocols for each subscriber, establishing communication channels in advance. When unauthorized access is detected, pre-formatted alerts are immediately pushed through established channels (SMS, email, push notifications) without requiring complex real-time message generation or routing decisions, thereby minimizing notification latency while maintaining robust security protection

Inventive Principle:
Principle #10Preliminary action

3Difficulty of detecting and measuring

If comprehensive credential monitoring is implemented across all devices, then security detection capability is improved, but processing time and system resources increase

Engineering Contradiction:
Improvedetection capabilityVSAvoidprocessing time
Core Design Contradiction:
Difficulty of detecting and measuringVSLoss of time

Solution Approach 1:

The system applies different monitoring intensities to different credential sets based on their risk profiles and usage patterns. High-value credentials (such as those associated with significant financial accounts) receive enhanced monitoring with detailed pattern analysis, while lower-risk credentials receive standard monitoring. This localized approach to security monitoring improves detection capability for critical credentials while reducing overall processing time and resource consumption across the entire system

Inventive Principle:
Principle #3Local quality

4Ease of operation

If multi-device authorization is supported to allow flexible access, then ease of operation is improved, but security vulnerability increases

Engineering Contradiction:
Improveauthorization flexibilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system implements continuous feedback monitoring for each authorized device, tracking usage patterns, locations, and access times. When a device exhibits anomalous behavior or attempts to access credentials outside established parameters, the system immediately revokes authorization and alerts the credential owner. This dynamic authorization approach maintains ease of operation for legitimate multi-device access while automatically responding to security threats

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11595816B2System and method to support identity theft protection as part of a distributed service oriented ecosystem
Publication Date: 2023.02.28 WORKDAY INC
  • US11595816B2 patent drawing
  • US11595816B2 patent drawing
  • US11595816B2 patent drawing

AI summary

A system and method to support identity theft protection and, in particular, to a system and method for supporting identity theft protection as part of a distributed service oriented ecosystem in Internet protocol (IP) multimedia subsystem (IMS) and non-IMS networks. The system includes an identity session initiation protocol (SIP) application server configured to act as a security assertion markup language (SAML) bridge, which allows an SIP enabled device or a non-SIP enabled device to attach to a telecommunications service provider network. A user may accept or reject an authorization request using the SIP enabled device or non-SIP enabled device.