Access Data Orchestration for Secure Cross-Brand Resource Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing storage applications face issues with unauthorized transactions due to fraudulent resource providers, hacking risks, and interoperability challenges, particularly in electric charging systems where access data is not easily shared across different brands, and resource providers lack control over transactions.

Innovation Solution

An orchestrator computer receives and processes data packets containing access data, generating authorization request messages with resource provider identifiers and values, which are transmitted to external computers for authorization processing, ensuring secure and controlled transactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If access data is passed to resource provider for transaction authorization, then transaction functionality is enabled, but security risk increases due to fraudulent resource providers and hacking attacks

Engineering Contradiction:
Improvetransaction functionalityVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an orchestrator computer as an intermediary between the storage application server and the resource provider. The orchestrator receives access data from the storage application server, processes authorization requests from the resource provider, and returns authorization results without exposing the access data to the resource provider. This mediator architecture enables transaction functionality while preventing security risks by ensuring resource providers never actually possess the access data.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If resource provider stores and processes access data for authorization, then transaction control is enabled, but compliance burden increases due to PCI-DSS requirements

Engineering Contradiction:
Improvetransaction controlVSAvoidcompliance burden
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The orchestrator computer serves as a mediator that handles the complex compliance requirements. By routing all access data through the orchestrator rather than allowing resource providers to store and process it directly, the system maintains transaction control capabilities while significantly reducing the compliance burden on resource providers. The orchestrator, as a centralized controlled entity, can implement security measures more efficiently than distributed resource providers.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If access data is stored centrally in storage application server, then security management is improved, but interoperability is reduced between different brands and organizations

Engineering Contradiction:
Improvesecurity managementVSAvoidinteroperability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The orchestrator computer implements a universal interface that accepts authorization requests from resource providers of any brand or organization while maintaining centralized security management. The system uses standardized data structures and communication protocols that enable different brands to interoperate through the common orchestrator platform, allowing the storage application server to maintain centralized control over access data while enabling broad interoperability across diverse ecosystems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250307813A1Efficient and privacy preserving resource interaction
Publication Date: 2025.10.02 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US20250307813A1 patent drawing
  • US20250307813A1 patent drawing
  • US20250307813A1 patent drawing

AI summary

A method is disclosed. The method includes receiving, from a storage application server, a data packet comprising access data. The method also includes receiving, from a transport computer, a request for the data packet, after the transport computer receives a message comprising a value and a resource provider identifier from a resource provider computer. The method further includes transmitting, to the transport computer, a response comprising the data packet. The transport computer is programmed to receive the data packet, generate an authorization request message comprising the access data, the resource provider identifier, and the value, and transmit the authorization request message to an external computer for authorization processing.