Credential-Less Account Linking Across Financial Applications
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems require users to repeatedly provide authentication credentials for each new application or service, creating a barrier to adopting new financial applications and services due to the complexity and inconvenience of the authentication process.
Innovation Solution
A system and method for credential-less authentication that allows a user to initially provide credentials to an account-linking service, enabling seamless access to linked accounts across multiple applications without the need for repeated credential entry, using alternative authentication mechanisms such as one-time passcodes and device verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional authentication credentials are used for each application, then security is maintained, but user convenience and ease of operation deteriorate due to repeated credential entry
Solution Approach 1:
The patent introduces an account-linking service as an intermediary between users and financial institutions. This service stores authentication credentials securely and provides them to applications without exposing them to users or applications directly. The intermediary resolves the contradiction by enabling convenient access through automated credential provision while maintaining security through centralized, controlled credential management and encryption.
Solution Approach 2:
The system enables self-service authentication where the account-linking service automatically provides credentials to applications without requiring user intervention for each authentication event. Users perform initial setup and verification, then the system handles subsequent authentications autonomously, improving ease of operation while maintaining security through automated credential distribution and revocation capabilities.
2Speed
If authentication credentials are stored locally in applications, then access speed is improved, but security deteriorates due to increased vulnerability to breaches
Solution Approach 1:
The account-linking service acts as a secure intermediary that holds authentication credentials centrally rather than distributing them locally to multiple applications. This eliminates the security vulnerability of local storage while maintaining fast authentication speeds through efficient credential retrieval and provision to authorized applications via secure communication channels.
Solution Approach 2:
The patent replaces the mechanical approach of local credential storage in each application with a centralized credential management system using secure communication protocols and encrypted credential transmission. This substitution maintains authentication speed through optimized credential delivery while eliminating the security risks associated with local storage vulnerabilities.
3Reliability
If multiple authentication methods are implemented for different applications, then security is enhanced, but device complexity and ease of operation worsen
Solution Approach 1:
The account-linking service provides a universal authentication mechanism that works across multiple applications and financial institutions through a standardized interface. Instead of implementing different authentication methods for each application, the system uses a single unified approach where the account-linking service manages credentials for all applications, reducing device complexity while maintaining security through consistent credential management practices.
Solution Approach 2:
The patent merges multiple authentication processes into a single unified system. The account-linking service consolidates credential management for multiple applications and financial institutions into one centralized service, eliminating the need for separate authentication implementations in each application and reducing overall system complexity while maintaining security through unified credential protection.
4Reliability
If users manually set up authentication for each application, then security control is maintained, but time consumption and productivity worsen
Solution Approach 1:
The system performs preliminary authentication setup through the account-linking service before applications need to access financial accounts. Users complete initial verification and credential provisioning once through the account-linking service, and subsequent application authentications occur automatically without requiring repeated user action. This preliminary action maintains user control while dramatically improving setup efficiency and reducing time consumption.
Solution Approach 2:
The account-linking service enables self-service authentication where users perform initial setup and verification, then the system automatically handles credential provision to applications without requiring repeated user intervention. This maintains user control over the authentication process while improving productivity by eliminating repetitive manual setup tasks for each application.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A system and method for linking to accounts using credential-less authentication that includes: within a first application context at an account-linking computing service: receiving a request to establish an account link, establishing the account link to a user account of an account service using user credentials, and receiving user identifying information of the first application context and storing the user identifying information in association with the account link; and within a second application context at the account-linking computing service: receiving user identifying information of the second application context, searching and identifying a candidate account link using the user identifying information of the second application context, verifying eligibility for access to the account link, and permitting access to the account link upon successful verification of eligibility.