Open API Platform Premium Access Control via Production Key
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Service provider companies face challenges in providing secure, controlled access to data while managing billing for developers accessing their systems through open APIs, balancing protection and utilization of financial data.
Innovation Solution
A computer-based method and system that grants premium access to service applications via an open API platform, involving request processing, production key management, and electronic messaging to ensure secure access and billing, with throttling and billing features for service owners.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If access to financial data is restricted to approved users only, then data security and protection are improved, but the potential uses and accessibility of the data are limited
Solution Approach 1:
The patent segments access rights by creating different key types (sandbox keys for testing, production keys for live environments) and different access levels (test access, premium access, standard access). This allows the system to provide targeted access to different user groups while maintaining overall security, resolving the contradiction between restricted access and data usability.
Solution Approach 2:
The patent introduces an intermediary approval mechanism where service owners must explicitly approve production key requests before developers gain access to live financial data. This intermediary layer maintains security by preventing unauthorized access while enabling legitimate uses through the approval process, thus balancing security with data accessibility.
2Productivity
If open API access is provided to developers, then transaction volume and service offerings are increased, but security risks and access control challenges arise
Solution Approach 1:
The patent implements dynamic access control where developers can request and receive different levels of access (test access automatically granted, premium access requiring approval). The system dynamically adjusts access rights based on the developer's needs and the service owner's approval, enabling high transaction volume while maintaining security through flexible, adaptive access management.
Solution Approach 2:
The patent changes the access parameter from binary (approved/not approved) to multi-level (sandbox key, production key with test access, production key with premium access). This parameter change allows the system to accommodate different security requirements and usage scenarios, increasing productivity while managing security risks through differentiated access levels.
3Ease of operation
If premium access with throttling is implemented, then service owner control and billing management are improved, but system complexity increases
Solution Approach 1:
The patent implements preliminary action by requiring service owners to pre-configure throttling parameters and billing rules before developers request premium access. This preliminary setup simplifies ongoing billing management while the system handles the complexity of access control automatically, resolving the contradiction between ease of operation and system complexity.
Data Source
AI summary
A method and system for granting premium access to a service application stored within a service provider (SP) computer system through an open API platform is provided. The method includes receiving a request for premium access to the service application from a developer of a developer application wherein the developer application is configured to request data from the service application, assigning a production key to the developer application, sending an electronic message to a service owner (SO) associated with the service application requesting premium access to the service application, granting premium access to the service application by the SO for the developer application, updating the production key at the open API platform to include premium access to the service application, and notifying the developer of the granting of the premium access to the service application for the developer application.


