Self-Issued OpenID Provider Authorization with Extended Verifiable Attributes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Standard parameter-centric verification in Self-Issued OpenID Provider (SIOP) based authentication is limiting, failing to provide secure, frictionless, and adaptive authentication and authorization methods.
Innovation Solution
The system introduces additional verifiable attributes in SIOP requests, including device identifiers, organization identifiers, and user identifiers, which are validated using paired devices and identity wallets, allowing access to relying party applications with or without user consent based on predefined policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If standard parameter-centric verification is used in SIOP authentication, then the authentication process is simple to implement, but the authentication and authorization methods lack adaptability and security
Solution Approach 1:
The system dynamically adjusts the authentication process by validating multiple types of attributes (device identifiers, organization identifiers, user identifiers) based on the specific context and risk assessment. The authentication flow adapts its complexity by conditionally requiring user consent or proceeding automatically based on predefined policies, making the system flexible rather than static
Solution Approach 2:
The patent extends the standard SIOP parameter set by introducing additional verifiable attributes including device identifiers, organization identifiers, and user identifiers. This parameter expansion enables more granular control and adaptability in authentication scenarios without fundamentally changing the core protocol structure
2Reliability
If additional verifiable attributes are validated in SIOP requests, then the security and trust assessment are improved, but the authentication process becomes more complex
Solution Approach 1:
The system performs preliminary validation of device identifiers, organization identifiers, and user identifiers against paired devices and predefined policies before the actual authentication decision. This preliminary action filters out invalid requests early and prepares the context for the final authentication step, making the overall process more reliable without proportionally increasing complexity
Solution Approach 2:
The patent introduces an intermediary validation layer that sits between the standard SIOP protocol and the authentication decision. This intermediary validates the extended attributes and translates them into trust assessments, allowing the core authentication mechanism to remain relatively simple while gaining enhanced security through the additional validation layer
3Reliability
If user consent is required for all authentication requests, then the security control is improved, but the authentication friction increases
Solution Approach 1:
The system dynamically determines whether user consent is required based on the validation results of device identifiers, organization identifiers, and user identifiers. When attributes match paired devices and satisfy predefined policies, authentication proceeds automatically without user intervention. When validation fails or policies require it, user consent is prompted, creating a dynamic rather than static consent model
Solution Approach 2:
The system provides self-service authentication for trusted devices and contexts by automatically validating attributes and making authentication decisions without requiring user intervention. This self-service capability reduces friction for routine authenticated while maintaining security through attribute validation, reserving user consent requests for exceptional cases
Data Source
Figure 1A
Figure 1B
Figure 2
AI summary
A system (100) or method (200, 300) for self-issued OpenID provider (SIOP) authorization to a relying party application (204) can include a mobile device (206) having validation attributes, one or more processors and memory operatively coupled to the one or more processors, where the memory includes computer instructions which when executed by the one or more processors causes the one or more processors to perform certain operations. The operations can include fetching (302) an SIOP request with the validation attributes, validating (304) the validation attributes, requesting (306) user claims from a holder, receiving (308) user claims from the holder, and allowing (314) access to the relying party application upon validating a predetermined number of validation attributes according to a policy (108).