User-to-User Delegation in Federated Identity Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing federated identity management environments primarily focus on user-to-machine or machine-to-machine delegation, lacking a comprehensive framework for user-to-user delegation that integrates with various access control models, particularly in web-based environments.
Innovation Solution
A new delegation framework that enables user-to-user delegation services within a federated identity management environment, where the identity provider acts as the delegation authority, managing delegations and ensuring compliance with access control policies across different access control models, including discretionary and role-based models, through SAML 2.0 and XACML standards.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If user-to-user delegation is implemented in federated identity management environments, then delegation functionality and user control over resources are improved, but system complexity and integration requirements with access control models increase
Solution Approach 1:
The patent introduces a Delegation Service as an intermediary component that mediates between users and service providers. This service handles delegation requests, generates delegation assertions, and manages the delegation lifecycle, thereby reducing the complexity burden on individual service providers while enabling comprehensive user-to-user delegation functionality across the federated environment.
Solution Approach 2:
The Delegation Service is designed as a universal component that works with multiple access control models (RBAC, ABAC, PBAC) and supports various delegation scenarios. By creating a multi-functional service that can adapt to different access control frameworks, the system achieves broad delegation functionality without proportionally increasing complexity at each service provider endpoint.
2Reliability
If delegation is integrated with access control models, then authorization control and security are improved, but implementation complexity and policy management overhead increase
Solution Approach 1:
The patent segments the authorization control functionality into distinct components: the Delegation Service handles delegation-specific logic (creating and managing delegation assertions), while existing access control engines (RBAC, ABAC, PBAC) continue to handle their respective authorization policies. This segmentation allows delegation to be integrated with access control models without requiring complete redesign of the authorization architecture, thereby improving control reliability while managing implementation complexity.
3Ease of operation
If service providers implement their own delegation management, then local control and flexibility are improved, but overall system consistency and security standards deteriorate
Solution Approach 1:
The centralized Delegation Service acts as an intermediary that maintains system consistency and security standards while allowing service providers to retain local control over their delegation policies. The service provider can configure their delegation requirements and policies locally, but the Delegation Service ensures that all delegations adhere to federated identity management standards and security requirements, thereby balancing local flexibility with overall system consistency.
Data Source
Figure 1
Figure 2~3
Figure 4~5
AI summary
Method for providing user-to-user delegation service in federated identity environment, characterized in that it comprises a delegation or assignment step wherein a delegator specifies said delegation at an identity provider for delegating a privilege or task to a delegatee to be performed at a service provider.