Trust Broker for Cross-Provider User Enrollment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face the inconvenience of having to enroll and authenticate with multiple organizations separately each time they access new services, which is time-consuming and burdensome, especially due to the need to remember different login information.

Innovation Solution

Establishing a trust relationship between two providers allows a user to enroll with a second provider using credentials from a first provider, enabling seamless access to services without the need for additional enrollment, facilitated through key exchange or third-party trust establishment, and allowing authentication when the first provider's service is disrupted.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users enroll with each organization separately, then each organization can authenticate users independently, but the enrollment process becomes time-consuming and users must remember multiple login credentials

Engineering Contradiction:
Improveindependent authentication capabilityVSAvoidenrollment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent introduces a trust broker as an intermediary service that mediates between multiple organizations and users. The trust broker stores credential mappings and enables cross-organization authentication without requiring users to enroll with each organization separately. When a user attempts to access an organization, the trust broker verifies the user's credentials and establishes trust relationships, eliminating redundant enrollment steps while maintaining independent authentication capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The trust broker serves multiple functions: it acts as a credential repository, a trust relationship manager, and an authentication intermediary. By making the authentication system universal across multiple organizations, users can authenticate with any participating organization using a single enrollment process, while the trust broker maintains the ability to enforce organization-specific authentication policies.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If users enroll with each organization separately, then each organization has its own authentication service, but users face the burden of remembering different passwords and login information

Engineering Contradiction:
Improveauthentication securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The trust broker serves as an intermediary that handles credential management centrally. Users provide their credentials to the trust broker once, and the trust broker manages the mapping between user identities and organization-specific authentication requirements. This eliminates the burden of remembering multiple passwords while maintaining security through the trust broker's verification processes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The trust broker creates and manages copies of user credential information across multiple organizations. Instead of users maintaining separate credentials for each organization, the trust broker stores and manages credential copies, allowing users to authenticate with any organization through a single set of credentials while the trust broker ensures proper verification with each organization's authentication system.

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If a trust relationship is established between providers, then users can access multiple providers with single enrollment, but the system requires key exchange or third-party trust establishment

Engineering Contradiction:
Improvecross-provider accessVSAvoidtrust establishment mechanism
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The trust broker acts as a central intermediary that manages trust relationships between multiple providers. Instead of requiring direct key exchange between each pair of providers, the trust broker maintains trust relationships with all providers and mediates authentication requests. This centralization simplifies the trust establishment mechanism while enabling cross-provider access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent merges multiple individual trust relationships into a centralized trust management system. Rather than each provider maintaining separate trust relationships with every other provider, the trust broker consolidates these relationships, allowing users to access multiple providers through a single enrollment while the trust broker manages the underlying complexity of inter-provider trust.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11245684B2User enrollment and authentication across providers having trusted authentication and identity management services
Publication Date: 2022.02.08 VERIZON PATENT & LICENSING INC
  • US11245684B2 patent drawing
  • US11245684B2 patent drawing
  • US11245684B2 patent drawing

AI summary

A provider receives a message from a user device requesting that the provider share user credentials associated with a user of the user device with a second provider when the user is attempting to enroll with or access goods or services associated with the second provider via an application on the user device. The message requests that the provider send the user credentials to the user device. The provider determines whether the user has been authenticated by the provider and whether a trust relationship exists between the provider and the second provider. The provider sends the user credentials to the user device when the user has been authenticated by the provider and when the trust relationship exists between the provider and the second provider. The user device forwards the user credentials to the second provider and the second provider authenticates the user based on the user credentials.