User-to-User Delegation in Federated Identity Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing federated identity management environments primarily focus on user-to-machine or machine-to-machine delegation, lacking a comprehensive framework for user-to-user delegation that integrates with various access control models, particularly in web-based environments.

Innovation Solution

A new delegation framework that enables user-to-user delegation services within a federated identity management environment, where the identity provider acts as the delegation authority, managing delegations and ensuring compliance with access control policies across different access control models, including discretionary and role-based models, through SAML 2.0 and XACML standards.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If user-to-user delegation is implemented in federated identity management environments, then delegation functionality and user control over resources are improved, but system complexity and integration requirements with access control models increase

Engineering Contradiction:
Improvedelegation functionalityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a Delegation Service as an intermediary component that mediates between users and service providers. This service handles delegation requests, generates delegation assertions, and manages the delegation lifecycle, thereby reducing the complexity burden on individual service providers while enabling comprehensive user-to-user delegation functionality across the federated environment.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The Delegation Service is designed as a universal component that works with multiple access control models (RBAC, ABAC, PBAC) and supports various delegation scenarios. By creating a multi-functional service that can adapt to different access control frameworks, the system achieves broad delegation functionality without proportionally increasing complexity at each service provider endpoint.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If delegation is integrated with access control models, then authorization control and security are improved, but implementation complexity and policy management overhead increase

Engineering Contradiction:
Improveauthorization controlVSAvoidimplementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authorization control functionality into distinct components: the Delegation Service handles delegation-specific logic (creating and managing delegation assertions), while existing access control engines (RBAC, ABAC, PBAC) continue to handle their respective authorization policies. This segmentation allows delegation to be integrated with access control models without requiring complete redesign of the authorization architecture, thereby improving control reliability while managing implementation complexity.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If service providers implement their own delegation management, then local control and flexibility are improved, but overall system consistency and security standards deteriorate

Engineering Contradiction:
Improvelocal controlVSAvoidsystem consistency
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The centralized Delegation Service acts as an intermediary that maintains system consistency and security standards while allowing service providers to retain local control over their delegation policies. The service provider can configure their delegation requirements and policies locally, but the Delegation Service ensures that all delegations adhere to federated identity management standards and security requirements, thereby balancing local flexibility with overall system consistency.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2689372B1User to user delegation service in a federated identity management environment
Publication Date: 2019.11.27 THALES DIS FRANCE SA
  • EP2689372B1 patent drawingFigure 1
  • EP2689372B1 patent drawingFigure 2~3
  • EP2689372B1 patent drawingFigure 4~5

AI summary

Method for providing user-to-user delegation service in federated identity environment, characterized in that it comprises a delegation or assignment step wherein a delegator specifies said delegation at an identity provider for delegating a privilege or task to a delegatee to be performed at a service provider.