Browser Supplement Module for Secure Account Delegation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Account owners without access to delegation features in secure systems often share credentials, introducing security risks and compromising their control over their accounts.

Innovation Solution

A computer-implemented method using browser supplement modules to facilitate secure system account delegation, allowing users to request and manage access without revealing owner credentials, through centralized or decentralized systems that utilize access control, certificates, and single sign-on (SSO) for secure communication and logging.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If account owners share credentials with others, then access sharing is enabled, but security risks increase and account control is compromised

Engineering Contradiction:
Improveaccess sharing capabilityVSAvoidaccount security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a delegation feature as an intermediary mechanism between the account owner and the third party. Instead of directly sharing credentials, the system provides a controlled delegation interface that allows the owner to grant specific access rights to specific users. This intermediary layer prevents direct credential exposure while enabling necessary access sharing, thus resolving the contradiction between adaptability and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If delegation features are implemented, then secure access sharing is enabled, but system complexity increases

Engineering Contradiction:
Improvesecure access controlVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The delegation feature is segmented into distinct functional components: delegation request handling, approval mechanisms, credential protection layers, and access monitoring. By dividing the complex delegation system into manageable segments, each with a specific function, the patent reduces overall system complexity while maintaining secure access control. This modular approach allows the system to achieve reliability without overwhelming architectural complexity.

Inventive Principle:
Principle #1Segmentation

3Device complexity

If no delegation feature is provided, then system complexity remains low, but credential sharing becomes necessary and insecure

Engineering Contradiction:
Improvesystem simplicityVSAvoidsecurity risks from credential sharing
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The delegation feature enables account owners to self-manage access sharing without requiring system administrator intervention or complex credential management protocols. Owners can independently grant, revoke, and monitor delegations through an intuitive interface. This self-service capability eliminates the need for insecure credential sharing while keeping the system relatively simple, as the delegation functionality is built into the existing account management infrastructure.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12126620B2Account delegation via browser supplement module
Publication Date: 2024.10.22 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US12126620B2 patent drawing
  • US12126620B2 patent drawing
  • US12126620B2 patent drawing

AI summary

Account delegation is provided. A request for access to a secure system using an owner's account is received from an applier via a browser supplement module on the applier's computing device. The request is communicated to the account owner via a browser supplement module on the account owner's computing device. Approval of the request is received from the account owner. The secure system is logged into using the account owner's credential. A connection to the applier's computing device is established to act as a proxy for communication between the secure system and the applier's computing device. Further provided herein are a computer system and a computer program product for performing the method.