Account Migration via Ephemeral Credentials

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Many individuals are excluded from participating in electronic commerce due to lack of appropriate computing devices or technology expertise, limiting their access to benefits such as convenience and lower prices.

Innovation Solution

A system that allows users to transition from assisted user accounts to self-managed accounts, maintaining security and associating previous data, by authenticating users and requesting new credentials, while ensuring access to communication channels and personalization information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users are provided with assisted accounts for easy access to electronic commerce, then ease of operation is improved, but device complexity and system complexity increase

Engineering Contradiction:
Improveease of operationVSAvoiddevice complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The account system is segmented into two distinct types: assisted accounts for users needing help and self-managed accounts for independent users. This segmentation allows the system to provide specialized functionality to each user type without increasing overall system complexity, as each account type follows a clear, defined structure with specific permissions and features.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system enables dynamic transition of accounts from assisted to self-managed status. Users can evolve their account type as their technical expertise develops, moving from assisted to self-managed accounts. This dynamic adaptation allows the system to maintain simplicity for beginners while providing independence for more skilled users, resolving the contradiction between ease of operation and device complexity.

Inventive Principle:
Principle #15Dynamics

2Ease of operation

If users transition to self-managed accounts for independence, then ease of operation is improved, but security risks increase

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

Before allowing users to transition to self-managed accounts, the system performs preliminary verification steps. It confirms the user has access to their communication channel (phone number or email) by sending and verifying a code. This preliminary action ensures security is established before independence is granted, allowing users to operate independently while maintaining security through verified authentication mechanisms.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If new credentials are requested from users during transition, then security is improved, but loss of time increases

Engineering Contradiction:
ImprovesecurityVSAvoidtime
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system uses an intermediary verification mechanism in the form of a time-limited code sent to the user's communication channel. This intermediary code serves as a secure bridge between the assisted and self-managed account states. The code verification process is streamlined and time-efficient, maintaining security requirements while minimizing the time users need to spend on the transition process.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10713655B1Migrating user accounts from assisted to self-managed
Publication Date: 2020.07.14 AMAZON TECH INC
  • US10713655B1 patent drawing
  • US10713655B1 patent drawing
  • US10713655B1 patent drawing

AI summary

Disclosed are various embodiments for transitioning user accounts from an assisted status to a self-managed status. In one embodiment, a service receives an authentication request from a client device, where the authentication request specifies a unique user identifier corresponding to a communication channel. The service then determines that the unique user identifier corresponds to an assisted user account but the client device is not logged in under an assisting user account. The service generates an ephemeral security credential and sends the ephemeral security credential to the communication channel. The service then creates a self-managed user account having the unique user identifier in response to receiving the ephemeral security credential from the client device.