Client-Managed Credentials for Secure Third-Party Data Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for first-party service providers to access user data from third-party service providers often compromise security by requiring users to transmit credentials, exposing them to fraud and hacking risks.
Innovation Solution
Implementing a system where users provide credentials directly to third-party service providers via their client devices, allowing the client to serve as a conduit for data access without sharing credentials with the first-party service provider, thereby enhancing security and privacy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users transmit credentials to first-party service providers to access third-party data, then data access functionality is enabled, but security risk increases due to credential exposure to fraud and hacking
Solution Approach 1:
The patent introduces a session-based intermediary mechanism where the client device acts as a mediator between the first-party service provider and third-party service provider. Instead of directly transmitting credentials, the system establishes a temporary session through the client, allowing data access without credential exposure. The client receives instructions from the first-party provider, interacts with the third-party provider using stored credentials locally, and relays data back without the credentials leaving the user's device.
2Adaptability or versatility
If credentials are stored and transmitted through first-party service providers, then data sharing between services is enabled, but privacy protection deteriorates due to credential exposure
Solution Approach 1:
The patent extracts the credential storage and management function from the first-party service provider and relocates it to the user's client device. By taking out the sensitive credential element from the service provider's infrastructure and placing it under user control, the system enables data sharing functionality while preventing credential privacy loss. The client device becomes the secure enclave for credential storage, eliminating the need for providers to handle or transmit sensitive authentication information.
3Productivity
If scraping technologies are used to access third-party data, then data retrieval is achieved, but security vulnerabilities increase due to credential handling requirements
Solution Approach 1:
The patent implements self-service by enabling the client device to autonomously authenticate with third-party service providers using locally stored credentials. The client receives high-level instructions from the first-party provider about what data to retrieve, then independently handles the authentication and data retrieval process without requiring credential transmission to the provider. This self-service approach maintains productivity by automating data retrieval while enhancing reliability by eliminating credential handling vulnerabilities.
Data Source
AI summary
Accessing third-party service provider data on behalf of a first-party service provider without having to provide credentials to a first-party service provider server(s) is described. A credential may be received via a user interface presented by a mobile payment application associated with a service provider, the credential being associated with a user account of a user and a third-party service provider. The mobile payment application may then send the credential to a computing device(s) of the third-party service provider, which causes a session to be established between the mobile payment application and the third-party device(s). The mobile payment application may receive, via the session, user data associated with the user account from the third-party device(s), and may send, without having provided the credential to a computing device(s) of the service provider, at least a portion of the user data to the computing device(s) of the service provider.


