Account Access Delegation via Temporary Credentials
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing electronic account security systems face challenges in allowing account access and use between linked users without compromising security, as users often share login credentials, leading to risks of fraud and account misuse.
Innovation Solution
Implementing a system that allows a first user to delegate access to a second user's funding source through a service provider account, with set restrictions and authentication, enabling secure account access without sharing credentials directly.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users share login credentials to enable account access for others, then ease of operation is improved, but account security and reliability deteriorate
Solution Approach 1:
The patent segments account access into two distinct components: authentication (verifying the account owner's identity) and authorization (granting the second user access rights). The account owner authenticates once and receives temporary credentials that grant the second user authorized access without exposing the permanent login credentials, thus maintaining security while enabling operation.
Solution Approach 2:
The system introduces an intermediary mechanism (temporary credentials generated by the service provider) that mediates between the account owner and the second user. This intermediary allows the second user to access the account without directly receiving the permanent login credentials, preventing security risks while enabling legitimate access.
2Reliability
If service provider monitors transactions for fraud prevention, then account security is improved, but device complexity and processing overhead increase
Solution Approach 1:
The service provider performs preliminary authentication of the account owner and generates pre-authorized temporary credentials before the second user attempts any transactions. This preliminary action establishes trust and authorization in advance, allowing subsequent transactions to be processed with standard fraud monitoring without requiring complex real-time verification of each transaction's legitimacy.
Data Source
AI summary
System and method for facilitating account access delegation are provided. Login credentials are authenticated for a first account of a first funding source of a first user. A request from the first user to delegate, to a second account of a second user, access to the first funding source is received. A redirected login request from a merchant web application is further received. The redirected login request corresponds to the second account. A determination is made, based on the received request, that the second account is permissioned to use the first funding source. In response to the determination, a login of the first user account is caused on the merchant web application. The logging in of the first user account on the merchant web application causes the first funding source to be applied to an electronic transaction performed on the merchant web application under control of the second user.


