Integrated Consent System for Identity Provider Account Creation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Web service providers face significant burdens and expenses in managing user credentials, including high initial and maintenance costs, as well as security risks, due to the need for sophisticated security measures and the tendency of users to reuse credentials across multiple services.
Innovation Solution
An integrated-consent system that integrates account creation and scope-of-consent experiences, allowing users to create an identity provider account and consent to share information with third-party systems on a single display page, reducing the computational resources required and enhancing user experience.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a service provider manages user credentials directly, then authentication security can be maintained, but the burden and expense of acquiring and maintaining software systems and employing security techniques increases significantly
Solution Approach 1:
The patent introduces an identity provider as an intermediary between the user and the service provider. The identity provider manages user credentials and authentication, while the service provider only needs to verify authentication tokens. This mediator approach maintains security while reducing the complexity and burden on the service provider.
Solution Approach 2:
The patent extracts the credential management function from the service provider and places it in a separate identity provider system. The service provider no longer needs to store or manage passwords directly, instead relying on authentication results from the identity provider. This separation reduces the service provider's system complexity and security burden.
2Adaptability or versatility
If users provide scope-of-consent information during account creation, then information sharing permissions can be established, but the account creation process requires additional steps and computational resources
Solution Approach 1:
The patent combines the scope-of-consent collection process with the authentication flow. Instead of separate steps for account creation and consent collection, the system integrates both functions into a unified process where users provide consent information as part of the initial authentication/account setup sequence. This reduces the perceived time and steps required.
Solution Approach 2:
The system performs preliminary actions by pre-configuring consent templates and permission structures before the user interaction. When users need to create accounts or access services, the consent framework is already in place, allowing for rapid consent collection without requiring complex real-time processing or multiple sequential steps.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A system for creating an account with an identity provider. The system receives a request to create an identity provider account with the identity provider for use in logging onto a third-party system. The system generates one or more display pages for providing an integrated-consent user experience. The integrated-consent user experience includes a display page for collecting both new-account information and scope-of-consent information whereby a user consents to share information with the third-party system. After the user provides the new-account information that includes user credentials for the identity provider account and consents to share account information of the identity provider account with the third-party system, the system creates the identity provider account for the user. When the user subsequently signs in to the third-party system using the user credentials for the identity provider account, the third-party system accesses account information of the identity provider account based on the scope-of-consent information.