Universal ID Association Server for Cross-Domain Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional user authentication systems require users to create multiple domain-specific identities and credentials for each online provider, leading to fragmented user profiles and lack of seamless network interactions, as existing universal network ID solutions fail to effectively associate these identities across different secure domains.

Innovation Solution

A system and method that associates a universal network identification with one or more domain-specific identities using an ID association server, which facilitates seamless network interactions by linking domain-specific IDs with a domain transcendent ID, ensuring that personally identifiable information is not shared across secure domains, and enabling sharing of transaction information while maintaining security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If users create multiple domain-specific identities for each online provider, then security and domain-specific authentication are improved, but user profile fragmentation and operational complexity increase

Engineering Contradiction:
Improvedomain-specific authentication securityVSAvoiduser profile management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a universal network ID as an intermediary that mediates between users and multiple domain-specific providers. This universal ID serves as a central identifier that can be recognized across different secure domains, eliminating the need for users to manage multiple separate identities while maintaining domain-specific security requirements through the intermediary layer

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If a universal network ID is implemented through multiple trusted third-party identity providers, then cross-domain authentication capability is improved, but user profile fragmentation and lack of coordination increase

Engineering Contradiction:
Improvecross-domain authentication capabilityVSAvoididentity provider coordination
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal network ID system that performs multiple functions: it serves as a unique identifier across all domains, enables authentication with any trusted third-party identity provider, and maintains user profile coherence. This single universal ID structure is designed to work universally with any identity provider without requiring complex coordination mechanisms between providers

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Object-affected harmful factors

If domain-specific identities are maintained separately without association, then security and information protection are improved, but network interaction seamlessness and information sharing capability deteriorate

Engineering Contradiction:
Improveinformation protectionVSAvoidnetwork interaction seamlessness
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent creates a copied or replicated representation of the user's universal network ID within each domain-specific context. Instead of sharing the actual domain-specific credentials or sensitive information, the system uses copies or references of the universal ID that enable recognition and association across domains while maintaining the security boundaries of each domain

Inventive Principle:
Principle #26Copying

Data Source

PatentEP2463800B1System and method for associating a universal user identification and a domain specific user identification
Publication Date: 2018.03.07 DISNEY ENTERPRISES INC
  • EP2463800B1 patent drawingFigure 1
  • EP2463800B1 patent drawingFigure 2
  • EP2463800B1 patent drawingFigure 3

AI summary

There is presented a system and method for associating a domain transcendent identification (ID) of a user and a domain specific ID of the user, the system comprising an ID association server accessible by a plurality of secure domains over a network. The system also includes an ID associator application that when executed by ID association server is configured to receive a domain specific ID that associates the user to the secure domain, enter the domain specific ID in a domain transcendent ID record created for the user, generate a unique data associated with the domain transcendent ID record and identify a network location for submission of the unique data, send the unique data and the network location to the user, and associate the domain transcendent ID and the domain specific ID.