Open API Platform Premium Access Control via Production Key

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Service provider companies face challenges in providing secure, controlled access to data while managing billing for developers accessing their systems through open APIs, balancing protection and utilization of financial data.

Innovation Solution

A computer-based method and system that grants premium access to service applications via an open API platform, involving request processing, production key management, and electronic messaging to ensure secure access and billing, with throttling and billing features for service owners.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access to financial data is restricted to approved users only, then data security and protection are improved, but the potential uses and accessibility of the data are limited

Engineering Contradiction:
Improvedata securityVSAvoiddata accessibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments access rights by creating different key types (sandbox keys for testing, production keys for live environments) and different access levels (test access, premium access, standard access). This allows the system to provide targeted access to different user groups while maintaining overall security, resolving the contradiction between restricted access and data usability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary approval mechanism where service owners must explicitly approve production key requests before developers gain access to live financial data. This intermediary layer maintains security by preventing unauthorized access while enabling legitimate uses through the approval process, thus balancing security with data accessibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If open API access is provided to developers, then transaction volume and service offerings are increased, but security risks and access control challenges arise

Engineering Contradiction:
Improvetransaction volumeVSAvoidsecurity risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic access control where developers can request and receive different levels of access (test access automatically granted, premium access requiring approval). The system dynamically adjusts access rights based on the developer's needs and the service owner's approval, enabling high transaction volume while maintaining security through flexible, adaptive access management.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the access parameter from binary (approved/not approved) to multi-level (sandbox key, production key with test access, production key with premium access). This parameter change allows the system to accommodate different security requirements and usage scenarios, increasing productivity while managing security risks through differentiated access levels.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If premium access with throttling is implemented, then service owner control and billing management are improved, but system complexity increases

Engineering Contradiction:
Improvebilling managementVSAvoidaccess control system complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by requiring service owners to pre-configure throttling parameters and billing rules before developers request premium access. This preliminary setup simplifies ongoing billing management while the system handles the complexity of access control automatically, resolving the contradiction between ease of operation and system complexity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8832858B2Access to application programming interface systems and methods
Publication Date: 2014.09.09 MASTERCARD INT INC
  • US8832858B2 patent drawing
  • US8832858B2 patent drawing
  • US8832858B2 patent drawing

AI summary

A method and system for granting premium access to a service application stored within a service provider (SP) computer system through an open API platform is provided. The method includes receiving a request for premium access to the service application from a developer of a developer application wherein the developer application is configured to request data from the service application, assigning a production key to the developer application, sending an electronic message to a service owner (SO) associated with the service application requesting premium access to the service application, granting premium access to the service application by the SO for the developer application, updating the production key at the open API platform to include premium access to the service application, and notifying the developer of the granting of the premium access to the service application for the developer application.