Temporary Alternate Identifier for Secure Identity Binding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing identity transfer methods in computing applications, such as video game streaming, are vulnerable to impersonation attacks due to the use of publicly known service identifiers, and existing solutions like OAUTH are technically complex and limited in scenarios of use.
Innovation Solution
A secure identity transfer system using a temporary alternate identifier generated by an identity interface, which is temporarily associated with the user's service identifier, allowing secure transfer of identity from one service to another, while protecting against impersonation by being valid only for a limited period.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a user's service identifier is transferred from one service to another resource, then the user can be identified across services (improving adaptability), but the service identifier becomes vulnerable to impersonation attacks (worsening security)
Solution Approach 1:
The patent introduces a temporary alternate identifier as an intermediary between the user's service identifier and the resource. This temporary identifier is generated by the service, provided to the user for resource access, and automatically invalidated after use or expiration. The intermediary protects the original service identifier from direct exposure to the resource, preventing impersonation attacks while enabling identity transfer.
2Object-affected harmful factors
If a temporary alternate identifier is generated and provided to the user, then security against impersonation is improved, but the system complexity increases (worsening device complexity)
Solution Approach 1:
The patent implements a disposable temporary identifier system where each temporary alternate identifier is generated for a single use or limited time period, then automatically invalidated. This approach enhances security by ensuring that even if a temporary identifier is compromised, the damage is limited. The system manages complexity by using simple generation and invalidation logic rather than complex long-term credential management.
Data Source
AI summary
A first request is received for generation of a temporary alternate identifier for a user, wherein the user is identified within a service using a user service identifier, and wherein the temporary alternate identifier assists in binding the user service identifier with a resource identifier that identifies the user within a resource. The temporary alternate identifier is then generated and associated with the user service identifier. The temporary alternate identifier is then provided the user, and the temporary alternate identifier is also provided by the user to the resource. A second request is received, from the resource, for validation of the temporary alternate identifier. The user resource identifier is also received from the resource, for example as part of the second request. The user service identifier is then bound with the user resource identifier. Additionally, an indication is provided, to the resource, that the temporary alternate identifier is valid.


