Credential Storage Manager for Delegated Account Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face challenges in securely allowing users to delegate account usage without sharing authentication credentials or sensitive account data, risking exposure and potential fraud.

Innovation Solution

A credential storage manager (CSM) is implemented to facilitate delegated account usage by securely storing and managing credentials, allowing users to grant access with terms and conditions, and enforcing limitations on account usage through device fingerprinting and two-factor authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a user shares authentication credentials with another user to allow account usage, then the delegated user can access and use the account, but the authentication credentials and sensitive account data are exposed to potential fraud and theft

Engineering Contradiction:
Improveaccount access delegationVSAvoidcredential exposure and fraud risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the authentication process into multiple independent components: device fingerprinting, one-time passcodes, and time-limited session tokens. Instead of sharing complete credentials, the system divides authentication into discrete, controlled steps where the delegating user provides only a one-time passcode generated from their device fingerprint, while the delegated user's device is authenticated through a separate token-based mechanism. This segmentation prevents full credential exposure while enabling account access delegation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary authentication mechanism that mediates between the delegating user and the delegated user. The system uses a one-time passcode generated from the delegating user's device fingerprint as an intermediary credential, and a time-limited session token as another intermediary layer. These intermediaries transfer authentication authority without exposing the actual account credentials, creating a secure bridge between the two users while maintaining credential security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If a user stores sensitive account information in an online account for transaction processing, then the user can conveniently process transactions, but the sensitive information becomes vulnerable to exposure and abuse if the account is accessed by unauthorized users

Engineering Contradiction:
Improvetransaction processing convenienceVSAvoidsensitive information security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by pre-registering the delegating user's device fingerprint and pre-generating one-time passcodes before any actual account access occurs. The system performs preliminary authentication setup where the delegating user's device characteristics are captured and stored securely, and one-time passcodes are generated in advance for each delegation session. This preliminary preparation enables secure delegated access without requiring the delegating user to be present during each transaction, maintaining both convenience and security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the parameter of authentication from static credentials (passwords, PINs) to dynamic parameters including device fingerprints, one-time passcodes, and time-limited session tokens. The authentication mechanism transitions from using fixed credential values to using parameters that change with each authentication event and are tied to specific device characteristics. This parameter transformation maintains transaction processing convenience while significantly improving the reliability of sensitive information security.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If a user allows another user to utilize their account for specific services, then the delegated user can access account features, but the delegating user loses control over account usage and cannot prevent misuse

Engineering Contradiction:
Improvedelegated account usageVSAvoidaccount usage control
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent applies dynamics by making the authentication credentials time-limited and session-specific rather than permanent. The one-time passcodes expire after a single use, and session tokens have defined validity periods. The delegating user can dynamically control account usage by generating new passcodes, revoking session tokens, or setting time limits on delegation. This dynamic approach maintains ease of operation for delegated users while preserving the delegating user's ongoing control over account usage through the ability to revoke or modify access parameters at any time.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12309151B2Credential storage manager for protecting credential security during delegated account use
Publication Date: 2025.05.20 PAYPAL INC
  • US12309151B2 patent drawing
  • US12309151B2 patent drawing
  • US12309151B2 patent drawing

AI summary

There are provided systems and methods for a credential storage manager for protecting credential security during delegated account use. A first user that controls the account may delegate usage of the account to a second user through a credential manager of a transaction process that manages sensitive authentication information and delegates account usage. The credential manager may automatically fill authentication information for use of the account by the second user. A device fingerprint of a device of the second user may be used to provide risk prevention and access the account. The credential manager may prevent revealing of the credentials and navigation to sensitive data or processes with the account. Two-factor authentication may be performed by receiving a code in a message received by a device of the first user, scraping the code from the message, and entering the code to a device of the second user.