Delegated Credential Authentication for Secure Cross-Device Checkout

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face inefficiencies and security risks when using multiple computing devices for transactions due to differing authentication protocols and insufficient security in device communication channels, particularly in financial transactions involving personally identifiable information.

Innovation Solution

A system that enables seamless checkout and payment operations by transferring the transaction process from a primary device to a trusted secondary device using delegated credentials, establishing an authorized authenticated session to secure electronic communications and minimize exposure of payment credentials and PII.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If users authenticate on multiple devices using different authentication protocols, then users can access services on various devices, but the authentication process becomes inefficient and exposes security risks

Engineering Contradiction:
Improvedevice compatibilityVSAvoidauthentication efficiency
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent introduces a delegated credential mechanism that acts as an intermediary between the user's primary device and secondary devices. The primary device issues delegated credentials that allow authentication on secondary devices without requiring users to manually re-enter credentials or go through different authentication protocols on each device, thus resolving the contradiction between device compatibility and authentication efficiency

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary authentication on the primary device and issues delegated credentials in advance. These pre-issued credentials enable seamless authentication on secondary devices without requiring real-time verification or additional user actions, thereby improving authentication efficiency while maintaining adaptability across multiple devices

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If users submit payment information and personal information on multiple devices, then transactions can be completed on any device, but security risks increase and sensitive data is exposed

Engineering Contradiction:
Improvetransaction capabilityVSAvoiddata security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The delegated credential mechanism serves as a secure intermediary that enables transaction capability on secondary devices without exposing sensitive payment information or personal data. The credentials delegate authentication authority without transmitting actual sensitive data, thus maintaining data security while enabling cross-device transactions

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system extracts the authentication function from sensitive data itself. Instead of transmitting or storing actual payment information and personal data on multiple devices, the system extracts only the necessary authentication capability through delegated credentials, thereby enabling transaction capability while minimizing security risks associated with data exposure

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of operation

If communication channels between electronically connected devices are established for data exchange, then convenience is improved, but the security level is insufficient for financial transactions involving PII

Engineering Contradiction:
Improvedata exchange convenienceVSAvoidcommunication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The delegated credential system introduces a secure mediation layer for data exchange between devices. Instead of relying on potentially insecure direct communication channels, the system uses cryptographically secured delegated credentials as intermediaries that enable authenticated data exchange with appropriate security guarantees for financial transactions

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates secure copies of authentication authority through delegated credentials rather than copying sensitive data itself. These credential copies enable authenticated communication on secondary devices while maintaining security, as the credentials are cryptographically protected and can be revoked or limited in scope

Inventive Principle:
Principle #26Copying

Data Source

PatentUS20260030626A1Multi-channel authentication using delegated credentials
Publication Date: 2026.01.29 SHOPIFY INC
  • US20260030626A1 patent drawing
  • US20260030626A1 patent drawing
  • US20260030626A1 patent drawing

AI summary

Disclosed herein are methods and systems for electronic authentication using delegated credentials to complete checkout and payment operations on a trusted device of a user. A computing system is structured to perform operations comprising receiving transaction information corresponding to an incomplete checkout operation, transmitting at least a subset of transaction information to a customer device, causing the customer device to generate and display a notification comprising a request for user authorization to complete the incomplete checkout operation, receiving customer input indicative of instructions to complete the incomplete checkout operation, and, responsive to receiving customer input, completing the incomplete checkout operation.