Mutual Account Association Verification Against Spoofing and Entry Errors
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Establishing trusted relationships between user accounts in account-based systems is challenging due to the risk of transposition errors with non-unique account identifiers and the vulnerability to identity spoofing with user-configurable names, leading to potential data breaches and unintended transactions.
Innovation Solution
A method involving the mutual exchange of account identification data through secure communication channels, using tokens that are encrypted and time-limited, to establish relationships between user accounts without revealing personal information, and incorporating identity verification processes to ensure authenticity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If unique account numbers or account number and sort code combinations are used to identify accounts, then accounts can be uniquely identified, but users are exposed to transposition errors when entering account identifiers
Solution Approach 1:
The patent introduces an intermediary verification mechanism where the system automatically validates the target account identifier by checking if the target user has also added the source user to their contacts. This intermediary check prevents transposition errors because the mutual association requirement ensures that the account identifier is correctly entered and matches the intended recipient.
Solution Approach 2:
The system provides feedback by requiring confirmation from both parties. When user A adds user B to their contacts, the system checks whether user B has also added user A. This feedback loop ensures that account identifiers are correctly matched and prevents transposition errors through automatic validation of the association request.
2Ease of operation
If user configurable display names are used as account identifiers, then users can use easily recognizable identifiers, but the system becomes vulnerable to identity spoofing
Solution Approach 1:
The patent applies preliminary action by requiring users to authenticate and verify their identity before being allowed to use their display name as an account identifier. The system pre-validates the user's identity through authentication mechanisms, ensuring that only legitimate users can register their display names, thereby preventing identity spoofing while maintaining ease of recognition.
Solution Approach 2:
The system introduces an intermediary verification step where the platform itself acts as a trusted mediator that validates the connection between the display name and the authenticated user identity. This intermediary layer ensures that display names are genuinely associated with legitimate user accounts, preventing malicious parties from spoofing identities while allowing users to maintain recognizable identifiers.
3Productivity
If account association is established without identity verification, then the association process is simple and quick, but the system is vulnerable to unauthorized associations and data breaches
Solution Approach 1:
The patent implements self-service by requiring both users to independently add each other to their contacts. This mutual action serves as automatic verification that both parties intend to establish the association, eliminating the need for complex identity verification procedures while maintaining security. The association only completes when both users perform the action, ensuring authorization without slowing down the process.
Solution Approach 2:
The system performs preliminary verification by checking whether both users have added each other to their contacts before finalizing the association. This preliminary check ensures that both parties have authorized the connection, providing security validation without requiring lengthy verification processes, thus maintaining fast association while preventing unauthorized connections.
Data Source
AI summary
Embodiments of the present disclosure comprise methods, apparatus and computer readable instructions for establishing a relationship between user accounts. A first account association request message in relation to a first user account in an account based system is received. A first source account identifier which corresponds to the first user account and a first target account identifier which corresponds to the second user account are identified. A second account association request message in relation to the second user account is received. Based on the second account association request message, a second source account identifier which corresponds to the second user account and a second target account identifier which corresponds to the first user account are identified. Responsive to a determination of whether the source account identifiers and target account identifiers relate to the same user account, a relationship is established between the first user account and the second user account.


