Trust Link Formation for Cross-Network Identity Sharing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for sharing trust between authorization realms in compute networks are inefficient and complex, requiring manual reconfiguration of numerous devices and lacking scalability, especially during mergers or new business relationships.
Innovation Solution
Implementing Remote Token Minting (RTM), Dynamic Transitive Issuer Trust (DTIT), and authorization realm blending techniques that establish trust links between Identity Provider (IDP) devices, allowing client devices to communicate without direct connection to every IDP in the merged realm.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual reconfiguration methods are used to establish trust between authorization realms, then trust sharing can be achieved, but the process becomes inefficient and complex with high operational costs
Solution Approach 1:
The patent introduces an intermediary mechanism where a client device in the first authorization realm can communicate with a service in the second authorization realm through a mediator that handles the trust verification. This allows trust to be established without manually reconfiguring every device, as the intermediary manages the cross-realm authentication process automatically.
Solution Approach 2:
The patent segments the trust management process by allowing individual client devices to be authorized to act on behalf of services across authorization realms without requiring global reconfiguration. This segmentation enables selective trust establishment rather than system-wide manual configuration.
2Reliability
If direct connection to every IDP is required for trust establishment, then security can be maintained, but latency increases and scalability is reduced
Solution Approach 1:
The patent implements preliminary action by having client devices pre-established authorization relationships with services in other authorization realms. Once authorized, the client device can directly communicate with services across realms without real-time IDP intervention, reducing latency while maintaining security through prior verification.
3Reliability
If manual reconfiguration is performed for every new business relationship or merger, then trust can be established, but productivity decreases and operational costs increase
Solution Approach 1:
The patent enables self-service by allowing client devices to autonomously establish trust relationships with services in other authorization realms through pre-configured authorization. This eliminates the need for manual reconfiguration operations, enabling rapid network merges and new business relationships without operational intervention.
Data Source
AI summary
Methods, apparatus, systems, and articles of manufacture are disclosed. An example apparatus to share trust between networks includes trust link former circuitry to form trust with an identity provider (IDP) device separate from the apparatus; interface circuitry to obtain credentials from a client device, the client device and the apparatus connected in a network that does not include the IDP device; and mint requester circuitry to cause the IDP device to mint a token based on the credentials, wherein the interface circuitry further to: obtain the token from the IDP device; and forward the token to the client device.


