SSO User ID Linking Verification via Unique Management IDs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In single sign-on (SSO) systems, malicious administrators can incorrectly link user IDs by registering unrelated IDs, leading to potential ID theft and management issues, even with good intentions, due to reliance on email address verification which may result in mistaken consent.
Innovation Solution
A management device that requires unique internal management IDs for verification, prompting users to input these IDs during the linking process, ensuring only genuine users can link their accounts, thereby preventing unauthorized ID linking.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If email address verification is used for user ID linking in SSO, then the linking process is simple and fast, but malicious administrators can incorrectly link unrelated user IDs leading to ID theft
Solution Approach 1:
The patent introduces an intermediary verification step using a notification email sent to the user's registered email address. This intermediary mechanism mediates between the administrator's linking request and the actual ID association, ensuring that only authorized users can confirm the linking operation, thereby preventing malicious or erroneous ID linking while maintaining operational efficiency.
2Ease of operation
If administrators have direct authority to link user IDs, then the operation is convenient and quick, but mistakes or malicious actions can occur without verification
Solution Approach 1:
The patent applies preliminary anti-action by sending a verification email to the user before the ID linking is finalized. This preliminary countermeasure prevents harmful actions (malicious or erroneous linking) by requiring user confirmation in advance, thus neutralizing potential threats before they can cause damage while still allowing legitimate operations to proceed smoothly.
3Device complexity
If no verification mechanism is implemented, then the system is simple and operations are fast, but security vulnerabilities arise allowing unauthorized ID linking
Solution Approach 1:
The patent implements self-service by enabling users to verify and confirm their own ID linking through email notification. Instead of relying on complex administrative verification systems, the user themselves performs the verification by clicking a confirmation link in the email, thus enhancing security through user autonomy while keeping the system structure relatively simple.
Data Source
AI summary
A management device includes a receiving unit that receives a link request to link a user ID of a user from a link origin, and a control unit that, in response the link request, requests the user to input unique information of the link origin, and does not execute a linking of the user ID in a case in which the unique information input from the user is incorrect.


