Identity Status Control for Proactive Use Authorization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current identity protection systems are inadequate in preventing misuse of identity information, as they are reactive and lack proactive control over identity use, leading to ongoing financial and emotional harm from identity theft, and are not applicable beyond financial transactions.
Innovation Solution
A method that allows an entity to set and manage the status of their identity, defining permitted use scopes, requesting authorization through a service provider with insufficient information to enable use, and returning to the original status after use, ensuring control over identity use and protection from misuse.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional monitoring systems are used to detect unusual identity use, then identity theft can be detected after it occurs, but the damage has already been done and the system is reactive rather than proactive
Solution Approach 1:
The patent implements preliminary action by requiring identity owners to pre-register their intent to use their identity with a service provider before actual use. The system maintains a record of authorized uses in advance, so when a transaction occurs, the system can immediately verify it against pre-registered intent rather than detecting misuse after the fact. This transforms the system from reactive monitoring to proactive prevention.
Solution Approach 2:
The patent applies preliminary anti-action by establishing a default state where identity use is restricted unless pre-authorized. The service provider maintains a deny-by-default posture, only allowing transactions that have been previously registered as intended uses. This pre-established countermeasure prevents unauthorized use before it can cause harm, rather than merely detecting and responding to harm after occurrence.
2Measurement precision
If full identity information is required to authorize transactions, then identity verification is thorough, but the risk of fraud increases if the information is compromised
Solution Approach 1:
The patent extracts only the essential elements needed for verification from complete identity information. Instead of requiring or storing full identity details, the system uses a service provider that holds the master record and compares transaction requests against pre-registered intent. This extracts the verification function from the sensitive data itself, allowing accurate verification without exposing comprehensive identity information that could be exploited for fraud.
Solution Approach 2:
The service provider acts as an intermediary between the identity owner and transaction processors. Rather than requiring identity information to flow directly between parties, the service provider mediates verification by comparing transaction requests against pre-registered intent. This intermediary layer protects identity information from direct exposure while maintaining verification accuracy, as the service provider can confirm authorization without revealing sensitive details.
3Reliability
If identity owners manually control each use of their identity, then security is enhanced, but the complexity of managing identity permissions increases significantly
Solution Approach 1:
The patent reduces complexity by implementing preliminary action where identity owners register their intent to use identity in advance with the service provider. Instead of manually controlling each individual transaction, the owner performs a single pre-registration action that authorizes future uses matching that intent. The service provider then automatically handles verification of subsequent transactions against the pre-registered intent, eliminating the need for complex real-time manual controls while maintaining security.
Solution Approach 2:
The system enables self-service by allowing identity owners to pre-register their own intent and usage parameters with the service provider. The service provider then automatically manages the verification process by comparing transaction requests against the pre-registered intent without requiring ongoing manual intervention from the identity owner. This self-service approach simplifies management while maintaining control, as the system automatically enforces the owner's predefined preferences.
Data Source
AI summary
A method of protecting use of an entity's identity is provided. The method comprises setting a status of the identity to a first state, the first state defining a scope of permitted use of the identity, changing, in advance of an intended use of the identity, the status to a second state defining a scope of permitted use of the identity that is different from the first state, requesting use of the identity after the changing; and returning, after the requesting, the state back to the first state.


