JIISN Framework Granular Identity Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication and authorization schemes provide an all-or-nothing approach, failing to offer granular control over user identity information, leading to increased vulnerability to online fraud and misuse of personal data across various sectors.

Innovation Solution

A computer-implemented method utilizing a Joint Identity and Information Service Network (JIISN) framework for consumer-based access control, which includes receiving identity requests, configuring user-selected policies for notification and authorization, and employing a JIISN policy engine and user remote mobile control systems for real-time verification and authorization, utilizing multi-factor authentication to secure identity services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional authentication schemes are used, then user verification is simplified, but granular control over identity information is lost

Engineering Contradiction:
Improveuser verificationVSAvoidgranular control over identity information
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent segments identity information into discrete, controllable units that can be individually authorized. Users can grant or deny access to specific identity attributes (e.g., name, SSN, address) separately, enabling granular control while maintaining simplified verification processes through the structured framework.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements dynamic authorization where users can modify their identity information access permissions in real-time. The authorization framework allows users to grant, revoke, or adjust permissions for different entities and identity attributes, providing adaptability while maintaining operational simplicity through automated policy enforcement.

Inventive Principle:
Principle #15Dynamics

2Device complexity

If all-or-nothing authentication is implemented, then system complexity is reduced, but security against fraud is weakened

Engineering Contradiction:
Improveauthentication systemVSAvoidsecurity against fraud
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent divides identity information into segmented, independently controllable attributes. This segmentation allows the system to provide fine-grained security control without increasing overall system complexity, as each attribute can be managed through standardized authorization mechanisms rather than requiring complex custom solutions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes the parameter of authorization from binary (all-or-nothing) to granular (attribute-level). This parameter change enables enhanced security against fraud by allowing selective disclosure of identity information, while the underlying framework maintains manageable complexity through consistent authorization patterns.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If real-time authorization notification is implemented, then fraud detection is improved, but processing time increases

Engineering Contradiction:
Improvefraud detectionVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by notifying users in advance of identity information requests. Users receive notifications before authorization is granted, allowing them to review and approve or deny access proactively. This preliminary notification enhances fraud detection while the automated system handles the actual authorization process efficiently.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system incorporates feedback mechanisms where users receive real-time notifications about identity information requests and can provide authorization decisions. This feedback loop improves fraud detection by involving users in the authorization process, while automated notification systems and policy engines minimize processing time delays.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11562455B1Method and system for identity verification and authorization of request by checking against an active user directory of identity service entities selected by an identity information owner
Publication Date: 2023.01.24 SECUREAUTH CORP
  • US11562455B1 patent drawing
  • US11562455B1 patent drawing
  • US11562455B1 patent drawing

AI summary

A computer implemented system and method for a consumer based access control for identity information. The method and system involve receiving at an identity organization a request for registration and verification of the identity information and configuring a specific user selected policy for notification and authorization of such identity requests of a desired (or intended) identity service (or plurality of services) associated with the targeted user identification. Next, processing the request in a Joint Identity Information Service Network (JIISN) server framework for the detection and verification of a request against an active directory of users or organizations who have opted in for notification; computing the required action based on the configuration of the policies in one of the group consisting of: a JISN policy engine and a user remote mobile control system; communicating with a real time authorization server (e.g., eGuardian™) which in part identifies the registered authorizing party including delivering notification for the identity services requested by the user based on the JISN policy engine setting through the agency or organization Identity System Service (e.g., It'sMe™ service) and alternatively user mobile rules; automatic rejection (or lock down of the Identity or data), automatic approval or real time authorization delivering the request authorization through a secure communication network back to a joint identity network service comprised of a plurality of government or private identity and credit report services; and determining if a user is to be verified using a second or multi factor authenticating service.