Account Access Delegation via Temporary Credentials

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing electronic account security systems face challenges in allowing account access and use between linked users without compromising security, as users often share login credentials, leading to risks of fraud and account misuse.

Innovation Solution

Implementing a system that allows a first user to delegate access to a second user's funding source through a service provider account, with set restrictions and authentication, enabling secure account access without sharing credentials directly.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users share login credentials to enable account access for others, then ease of operation is improved, but account security and reliability deteriorate

Engineering Contradiction:
Improveaccount accessVSAvoidaccount security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments account access into two distinct components: authentication (verifying the account owner's identity) and authorization (granting the second user access rights). The account owner authenticates once and receives temporary credentials that grant the second user authorized access without exposing the permanent login credentials, thus maintaining security while enabling operation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary mechanism (temporary credentials generated by the service provider) that mediates between the account owner and the second user. This intermediary allows the second user to access the account without directly receiving the permanent login credentials, preventing security risks while enabling legitimate access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If service provider monitors transactions for fraud prevention, then account security is improved, but device complexity and processing overhead increase

Engineering Contradiction:
Improvefraud preventionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The service provider performs preliminary authentication of the account owner and generates pre-authorized temporary credentials before the second user attempts any transactions. This preliminary action establishes trust and authorization in advance, allowing subsequent transactions to be processed with standard fraud monitoring without requiring complex real-time verification of each transaction's legitimacy.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11966923B2Systems and methods facilitating account access delegation
Publication Date: 2024.04.23 PAYPAL INC
  • US11966923B2 patent drawing
  • US11966923B2 patent drawing
  • US11966923B2 patent drawing

AI summary

System and method for facilitating account access delegation are provided. Login credentials are authenticated for a first account of a first funding source of a first user. A request from the first user to delegate, to a second account of a second user, access to the first funding source is received. A redirected login request from a merchant web application is further received. The redirected login request corresponds to the second account. A determination is made, based on the received request, that the second account is permissioned to use the first funding source. In response to the determination, a login of the first user account is caused on the merchant web application. The logging in of the first user account on the merchant web application causes the first funding source to be applied to an electronic transaction performed on the merchant web application under control of the second user.