Client-Managed Credentials for Secure Third-Party Data Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for first-party service providers to access user data from third-party service providers often compromise security by requiring users to transmit credentials, exposing them to fraud and hacking risks.

Innovation Solution

Implementing a system where users provide credentials directly to third-party service providers via their client devices, allowing the client to serve as a conduit for data access without sharing credentials with the first-party service provider, thereby enhancing security and privacy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users transmit credentials to first-party service providers to access third-party data, then data access functionality is enabled, but security risk increases due to credential exposure to fraud and hacking

Engineering Contradiction:
Improvedata access functionalityVSAvoidcredential theft risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a session-based intermediary mechanism where the client device acts as a mediator between the first-party service provider and third-party service provider. Instead of directly transmitting credentials, the system establishes a temporary session through the client, allowing data access without credential exposure. The client receives instructions from the first-party provider, interacts with the third-party provider using stored credentials locally, and relays data back without the credentials leaving the user's device.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If credentials are stored and transmitted through first-party service providers, then data sharing between services is enabled, but privacy protection deteriorates due to credential exposure

Engineering Contradiction:
Improvedata sharing capabilityVSAvoidcredential privacy
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent extracts the credential storage and management function from the first-party service provider and relocates it to the user's client device. By taking out the sensitive credential element from the service provider's infrastructure and placing it under user control, the system enables data sharing functionality while preventing credential privacy loss. The client device becomes the secure enclave for credential storage, eliminating the need for providers to handle or transmit sensitive authentication information.

Inventive Principle:
Principle #2Taking out (Extraction)

3Productivity

If scraping technologies are used to access third-party data, then data retrieval is achieved, but security vulnerabilities increase due to credential handling requirements

Engineering Contradiction:
Improvedata retrieval efficiencyVSAvoidsystem security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements self-service by enabling the client device to autonomously authenticate with third-party service providers using locally stored credentials. The client receives high-level instructions from the first-party provider about what data to retrieve, then independently handles the authentication and data retrieval process without requiring credential transmission to the provider. This self-service approach maintains productivity by automating data retrieval while enhancing reliability by eliminating credential handling vulnerabilities.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20230043318A1Client-provisioned credentials for accessing third-party data
Publication Date: 2023.02.09 BLOCK INC
  • US20230043318A1 patent drawing
  • US20230043318A1 patent drawing
  • US20230043318A1 patent drawing

AI summary

Accessing third-party service provider data on behalf of a first-party service provider without having to provide credentials to a first-party service provider server(s) is described. A credential may be received via a user interface presented by a mobile payment application associated with a service provider, the credential being associated with a user account of a user and a third-party service provider. The mobile payment application may then send the credential to a computing device(s) of the third-party service provider, which causes a session to be established between the mobile payment application and the third-party device(s). The mobile payment application may receive, via the session, user data associated with the user account from the third-party device(s), and may send, without having provided the credential to a computing device(s) of the service provider, at least a portion of the user data to the computing device(s) of the service provider.