Account Linking via Access Tokens for Secure Cross-Partition Actions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems face challenges in securely managing access to multiple data partitions with different access controls, requiring multiple applications and devices for executing actions, and lack compliance with privacy regulations like HIPAA and GDPR.
Innovation Solution
Implementing mutual account linking and token-based access control to associate data partitions, allowing a single user input to generate and link accounts, enabling secure execution of actions across systems while adhering to privacy policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple applications and devices are used to execute actions across different data partitions, then access control security is improved, but device complexity and ease of operation deteriorate
Solution Approach 1:
The patent introduces an account association service as an intermediary component that manages connections between multiple data partitions. This service handles account linking, token generation, and access coordination, allowing secure cross-partition operations without requiring users to directly manage multiple applications or devices. The intermediary abstracts the complexity while maintaining security through controlled access mechanisms.
Solution Approach 2:
The patent implements a universal account system that can associate multiple data partitions under a single user account. This multi-functional account structure enables the same account to access different data partitions with appropriate permissions, eliminating the need for separate applications or devices for each partition while maintaining access control security through token-based authentication.
2Reliability
If multiple applications and devices are used to execute actions across different data partitions, then access control security is improved, but ease of operation deteriorates
Solution Approach 1:
The account association service acts as a mediator that simplifies user operations by automatically handling account linking and access token management. Users only need to provide a single user input to trigger the service, which then manages the complex processes of associating accounts, generating tokens, and coordinating access across multiple data partitions, making the system as easy to operate as a single application.
Solution Approach 2:
The system implements self-service mechanisms where the account association service automatically performs account linking, token generation, and access coordination without requiring user intervention for each operation. The service autonomously manages the complexity of cross-partition access while maintaining security, allowing users to simply initiate actions with a single input.
3Manufacturing precision
If data partitions with different access controls are managed separately, then access control precision is improved, but loss of information increases due to inability to execute actions requiring multiple partitions
Solution Approach 1:
The account association service serves as an intermediary that coordinates access across multiple data partitions while preserving access control precision. It generates and manages tokens that encode specific permission levels for each partition, allowing actions requiring multiple partitions to execute successfully while maintaining the precise access control boundaries defined for each partition.
Solution Approach 2:
The patent uses token-based access control where access parameters (permissions, scopes, validity periods) can be dynamically changed and assigned to different tokens. This allows the system to maintain precise access control for each data partition while enabling flexible combination of permissions when executing actions that span multiple partitions, preventing loss of execution capability.
Data Source
AI summary
Techniques for associating accounts in support of communication sessions are described. In an example, a system receives first data indicating a first account. The first data is received based at least in part on input data at a first device. The input data is associated with the first account and indicating a request for an action. The system generates a second account based at least in part on the first data. The system enables generation of an association between the first account and the second account by at least sending a first access token associated with access to the first account and a second access token associated with access to the second account. Based at least in part on the first data, the system determines a third account associated with the action and enables establishment of a communication session with the first device and a second device associated with the third account by at least sending second data that indicates the third account.


