Authentication Tool for Secure Multi-Repository Data Distribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional systems for maintaining and updating entity information across multiple data repositories are inefficient and insecure, requiring repetitive authentication and authorization tasks for each repository, which can lead to interception of sensitive information and authenticity issues.

Innovation Solution

An authentication/authorization tool that leverages an authentication token from an official third party and an authorization token from a mobile device to streamline the process of updating entity information across multiple repositories, ensuring efficient, secure, and accurate distribution based on entity preferences.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If the entity accesses each repository individually to update information, then the information can be updated in each repository, but the process is inefficient and requires repetitive authentication tasks

Engineering Contradiction:
Improveefficiency of updating entity informationVSAvoidtime spent on repetitive authentication tasks
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent combines multiple authentication and authorization tasks into a single unified process. The entity performs authentication once with an official third party, and the authentication/authorization tool automatically distributes the authenticated information to multiple repositories based on pre-configured authorization rules, eliminating the need to access each repository individually.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements preliminary authorization configuration where the entity pre-specifies which repositories should receive which types of information and under what conditions. This authorization framework is established in advance, allowing the authentication/authorization tool to automatically distribute information without requiring real-time authorization decisions for each repository update.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the entity repeatedly communicates authentication information to each repository, then each repository can verify the entity's identity, but the information can be intercepted by bad actors

Engineering Contradiction:
Improveauthentication verificationVSAvoidinterception of sensitive information
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an authentication/authorization tool as an intermediary between the entity and multiple repositories. This tool receives authenticated information from an official third party and distributes it to repositories based on authorization rules, eliminating the need for the entity to directly communicate sensitive authentication information to each repository.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a secure copy of the authenticated information in the form of an authentication token generated by the official third party. This token contains the necessary verification data and can be safely distributed to multiple repositories without exposing the original sensitive authentication information, thus preventing interception risks.

Inventive Principle:
Principle #26Copying

3Ease of operation

If anyone with access to credentials can pose as the entity, then authentication is simple, but the authenticity and reliability of information updates is compromised

Engineering Contradiction:
Improvesimplicity of authenticationVSAvoidauthenticity of entity information
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an authentication/authorization tool as an intermediary that works with an official third party to perform authentication. This intermediary layer adds a trusted verification step where the official third party confirms the entity's identity through multiple authentication factors, ensuring that only the legitimate entity can authorize information updates.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary authentication by an official third party before any information updates are permitted. The entity must be authenticated and authorized in advance by the trusted third party, and only then can the authentication/authorization tool distribute information to repositories. This preliminary verification ensures authenticity while maintaining operational simplicity through automation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11252139B2Distributed authentication/authorization tool
Publication Date: 2022.02.15 BANK OF AMERICA CORP
  • US11252139B2 patent drawing
  • US11252139B2 patent drawing
  • US11252139B2 patent drawing

AI summary

An authentication/authorization tool authenticates entity data received from an official third party and authorizes the distribution of the authenticated data based on an authorization token provided by a mobile device of the entity. The tool determines, based on the entity data and an entity preferences database, different portions of the entity data that are of different data types and data repositories that are authorized to receive each data type. The tool receives an authorization token from a mobile device of the entity and uses the authorization token to determine whether data distribution is authorized. Responsive to determining, based on the data authorization token, that distribution of the data is authorized, the tool automatically transmits the data portions to the entity's data repositories to update information stored therein, according to preferences of the entity.