Inter-System Account Identifiers for Privacy Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional computer systems face challenges in sharing user accounts and user account data across multiple independent systems, leading to issues with privacy and security, especially when personal information is exposed or when multiple systems use a common identifier.

Innovation Solution

The generation and use of inter-system account identifiers, which are unique to each external system and map to an internal account, allowing data association without exposing the internal account identifier, thereby addressing privacy concerns and preventing data correlation across compromised systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional systems use common account identifiers across multiple systems, then system integration and data sharing are simplified, but privacy and security are compromised due to exposure of internal account identifiers and potential data correlation across compromised systems

Engineering Contradiction:
Improvesystem integrationVSAvoidprivacy exposure
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces inter-system account identifiers as intermediary elements that enable communication and data sharing between external systems and the internal system without exposing internal account identifiers. These intermediaries act as secure proxies that mask the true internal identifiers while still allowing functional integration and data association across system boundaries.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If internal account identifiers are shared across systems, then data association between systems is direct and simple, but security is worsened as compromised systems can correlate data from multiple sources

Engineering Contradiction:
Improvedata associationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the account identification function into multiple distinct identifier types: internal account identifiers for internal system use, and inter-system account identifiers for external system communication. This segmentation allows each identifier type to serve its specific purpose independently, enabling straightforward data association through inter-system identifiers while protecting internal identifiers from exposure and correlation attacks.

Inventive Principle:
Principle #1Segmentation

3Reliability

If unique internal account identifiers are used in each system, then security and privacy are maintained, but system interoperability and the ability to share user accounts across systems is lost

Engineering Contradiction:
Improveprivacy protectionVSAvoidcross-system identification
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates inter-system account identifiers that serve multiple functions: they uniquely identify accounts across different external systems, enable data association between systems, and simultaneously protect internal account identifiers. These multi-functional identifiers allow the system to maintain privacy protection while gaining cross-system interoperability capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11870763B2Systems and methods for inter-system account identification
Publication Date: 2024.01.09 ATLASSIAN PTY LTD
  • US11870763B2 patent drawing
  • US11870763B2 patent drawing
  • US11870763B2 patent drawing

AI summary

Systems and methods for identifying and transacting with accounts across multiple external systems using inter-system account identifiers, without exposing internal account identifiers of an originating system, are disclosed. An example method, executed by the originating system, includes generating a first and a second inter-system account identifier based on a first and a second request, respectively, received at the originating system from a first and a second external system, respectively, that provide different services to an internal account of the originating system. The first and second inter-system account identifiers are communicated to the first and the second external system, respectively. When a data communication including the first inter-system account identifier and payload data is received from the first external system, the first internal account is retrieved using the first inter-system account identifier, the payload data is associated with the first internal account, and stored in an originating system data store.