Credential-Based Third-Party Service Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing online services face challenges in securely allowing non-subscribing third parties to access specific services without requiring them to subscribe, especially for one-time transactions or restricted usage scenarios, as current solutions are either cumbersome or lack transaction specificity.
Innovation Solution
A method where an authorizing party can specify a shared service, associate a credential with it, and allow a requesting entity to access the service by verifying the credential, ensuring restricted access based on the authorizing entity's preferences, without the need for the third party to have a pre-existing account.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a third party is required to subscribe to the online service to access it, then access control and service management are simplified, but the convenience and flexibility for one-time or restricted usage are reduced
Solution Approach 1:
The patent introduces a credential as an intermediary mechanism that mediates between the subscribing party and the service provider. The credential contains embedded service specifications and authorization information, allowing the service provider to verify and control third-party access without requiring the third party to subscribe. This resolves the contradiction by enabling convenient third-party access while maintaining service management control through the credential intermediary.
Solution Approach 2:
The patent applies preliminary action by embedding service usage specifications, limits, and authorization information into the credential before it is issued to the third party. The service provider pre-configures the credential with specific service parameters, time limits, and usage restrictions. This allows the service to be automatically controlled and managed based on pre-established rules, eliminating the need for real-time complex management while maintaining control.
2Adaptability or versatility
If a gift card or token is provided to a non-subscribing third party for limited time access, then access is granted without subscription, but the ability to restrict usage to specific transaction types is lost
Solution Approach 1:
The patent applies local quality by encoding specific service type restrictions, time limits, and usage parameters directly into the credential itself. Different portions of the credential contain different types of authorization information - some credentials may authorize only specific transaction types, others may have time-based restrictions. This allows the service to be adapted to specific usage scenarios while maintaining simple verification through the credential, resolving the contradiction between adaptability and ease of operation.
3Ease of operation
If a third party accesses an online service without a pre-existing account, then convenience is improved, but security and authorization verification become more challenging
Solution Approach 1:
The credential serves as a security intermediary that carries authorization information from the subscribing party to the service provider. Instead of requiring the third party to have an account with the service provider (which would compromise convenience), the credential acts as a portable authorization token that the service provider can verify. This maintains security through cryptographic verification while preserving the convenience of no-account access for third parties.
Solution Approach 2:
The system implements feedback by having the service provider verify the credential against the subscribing party's account information and service specifications. The verification process provides feedback on whether the third party is authorized to access the service, ensuring security while maintaining the convenience of third-party access without accounts.
Data Source
AI summary
Systems and methods are provided for authorizing third-party access to a specific service from a service provider. In an example embodiment, a server system identifies a shared service from multiple services provided by the server system. The shared service is specified by an authorizing entity. The server system provides a credential associated with the shared service and the authorizing entity. The server system receives a request to access the shared service from a requesting entity that is separate from the authorizing entity. The server system verifies that the request includes the credential and that the credential is associated with the shared service and the authorizing entity. The server system provides access to the shared service to the requesting entity based on verifying that the request includes the credential. The requesting entity is restricted to accessing the shared service identified by the credential as authorized by the authorizing entity.


