Integrated Consent System for Identity Provider Account Creation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Web service providers face significant burdens and expenses in managing user credentials, including high initial and maintenance costs, as well as security risks, due to the need for sophisticated security measures and the tendency of users to reuse credentials across multiple services.

Innovation Solution

An integrated-consent system that integrates account creation and scope-of-consent experiences, allowing users to create an identity provider account and consent to share information with third-party systems on a single display page, reducing the computational resources required and enhancing user experience.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a service provider manages user credentials directly, then authentication security can be maintained, but the burden and expense of acquiring and maintaining software systems and employing security techniques increases significantly

Engineering Contradiction:
Improveauthentication securityVSAvoidsoftware system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an identity provider as an intermediary between the user and the service provider. The identity provider manages user credentials and authentication, while the service provider only needs to verify authentication tokens. This mediator approach maintains security while reducing the complexity and burden on the service provider.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the credential management function from the service provider and places it in a separate identity provider system. The service provider no longer needs to store or manage passwords directly, instead relying on authentication results from the identity provider. This separation reduces the service provider's system complexity and security burden.

Inventive Principle:
Principle #2Taking out (Extraction)

2Adaptability or versatility

If users provide scope-of-consent information during account creation, then information sharing permissions can be established, but the account creation process requires additional steps and computational resources

Engineering Contradiction:
Improveinformation sharing permissionVSAvoidaccount creation time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent combines the scope-of-consent collection process with the authentication flow. Instead of separate steps for account creation and consent collection, the system integrates both functions into a unified process where users provide consent information as part of the initial authentication/account setup sequence. This reduces the perceived time and steps required.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system performs preliminary actions by pre-configuring consent templates and permission structures before the user interaction. When users need to create accounts or access services, the consent framework is already in place, allowing for rapid consent collection without requiring complex real-time processing or multiple sequential steps.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3552135B1Integrated consent system
Publication Date: 2021.04.21 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3552135B1 patent drawingFigure 1
  • EP3552135B1 patent drawingFigure 2
  • EP3552135B1 patent drawingFigure 3

AI summary

A system for creating an account with an identity provider. The system receives a request to create an identity provider account with the identity provider for use in logging onto a third-party system. The system generates one or more display pages for providing an integrated-consent user experience. The integrated-consent user experience includes a display page for collecting both new-account information and scope-of-consent information whereby a user consents to share information with the third-party system. After the user provides the new-account information that includes user credentials for the identity provider account and consents to share account information of the identity provider account with the third-party system, the system creates the identity provider account for the user. When the user subsequently signs in to the third-party system using the user credentials for the identity provider account, the third-party system accesses account information of the identity provider account based on the scope-of-consent information.