Service System ID Segmentation for SSO Privacy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing service providing systems face challenges in allowing users to judge the identity of a user across multiple services without previously performing processes like issuing consumer keys and secrets, and in preventing the misuse of user identities.

Innovation Solution

A service providing system that includes a first service providing means and a second service providing means, where the first service provides a first application program and the second service provides a second application program, allowing for the transmission of common IDs and individual IDs between user terminals, enabling identity verification without prior key issuance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a common ID is used across multiple services for Single Sign On, then user convenience is improved, but personal information and privacy information may be disseminated beyond user intent

Engineering Contradiction:
Improveuser convenienceVSAvoidpersonal information dissemination
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments the ID system into two distinct parts: a common ID for authentication across services and individual service-specific IDs for identifying user relationships within each service. This segmentation allows the common ID to be used for convenient Single Sign On while the service-specific IDs prevent unwanted linkage and information dissemination across services, thus resolving the contradiction between convenience and privacy protection.

Inventive Principle:
Principle #1Segmentation

2Object-affected harmful factors

If different IDs are assigned by each service independently, then user privacy is protected, but users cannot judge identity across services and must manage multiple IDs

Engineering Contradiction:
Improveprivacy protectionVSAvoididentity judgment and ID management
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent segments the ID system into a common ID component for cross-service identity recognition and service-specific ID components for individual service identification. This segmentation enables users to judge identity across services through the common ID while maintaining privacy protection through service-specific IDs, eliminating the need to manage completely separate ID systems for each service.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The common ID serves multiple functions: it enables authentication across different services, allows users to judge identity relationships between services, and works in conjunction with service-specific IDs. This multi-functionality resolves the contradiction by providing a universal identifier that doesn't compromise service-specific privacy protection.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If OAuth authority delegation is used, then security is improved by not disclosing user ID and password, but consumer key and secret must be previously transmitted

Engineering Contradiction:
ImprovesecurityVSAvoidkey issuance process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication credentials (user ID and password) from the service-to-service communication process. Instead of transmitting consumer keys and secrets between services, the system uses the common ID for authentication while service-specific IDs handle the identification of user relationships. This extraction eliminates the need for complex key issuance and transmission processes while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9185146B2Service providing system
Publication Date: 2015.11.10 PIECE FUTURE PTE LTD
  • US9185146B2 patent drawing
  • US9185146B2 patent drawing
  • US9185146B2 patent drawing

AI summary

A system 100 includes a first service providing part 110 for providing a first service, and a second service providing part 120 for providing a second service. The first service providing part 110 transmits a first individual ID that is associated with a common ID included in an ID information provision request and that is for identifying a user in the first service, to a user terminal. The second service providing part 120 receives a service ID for identifying the first service, the first individual ID and the common ID from the user terminal, and transmits the service ID and first individual ID having been received with the common ID associated with a second individual ID that is included in an ID information acquisition request and that is for identifying a user in the second service, to a user terminal.