Mobile Device Authorization via Partner Account Lists
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems face challenges in securely processing requests for mobile communication devices while providing consumer care agents with necessary access, as they need to manage sensitive information and operations from various entities with different access levels.
Innovation Solution
A system that receives requests from partner systems, executes an authorization procedure based on mobile device and partner system identifiers, and grants access to consumer data or performs operations like updating wallet states or resetting passwords, ensuring secure and restricted access through an enterprise service bus, gateway, and wallet server.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If access to mobile device information and operations is restricted for security reasons, then security and privacy are improved, but consumer care systems and agents cannot access necessary information to provide effective consumer care
Solution Approach 1:
The system segments access rights by creating distinct partner system account lists for different entities (mobile wallet provider, issuers, MNOs) and different levels of personnel within each entity. Each partner system identifier is associated with specific mobile device identifiers in these account lists, enabling fine-grained control over which agents can access which device information and operations.
Solution Approach 2:
The system introduces an intermediary authorization procedure that acts as a mediator between consumer care agents and mobile device information. The authorization procedure checks partner system account lists to determine whether a requesting agent has legitimate access rights, thereby enabling controlled access without compromising security.
2Adaptability or versatility
If multiple entities with different access levels are granted access to mobile device operations, then consumer care capabilities are improved, but system complexity increases due to managing different authorization levels
Solution Approach 1:
The system implements a universal authorization framework that handles multiple entities (mobile wallet providers, issuers, MNOs) and multiple personnel levels through a single consistent mechanism. The authorization procedure universally checks partner system account lists regardless of which entity or personnel level is making the request, simplifying the management of diverse access requirements.
Solution Approach 2:
The system implements authorization checks at the appropriate level of detail without over-complicating the process. The authorization procedure performs only the necessary verification of partner system identifiers against account lists, granting access when authorized without requiring excessive validation steps for routine operations.
3Productivity
If consumer care agents can access and perform operations on mobile devices, then consumer care efficiency is improved, but security risks increase due to potential unauthorized access to sensitive information
Solution Approach 1:
The system performs preliminary authorization verification before allowing consumer care agents to access mobile device information or perform operations. The authorization procedure checks partner system account lists in advance to confirm legitimate access rights, preventing unauthorized access before it can occur and enabling efficient authorized operations.
Data Source
AI summary
Systems, methods, and computer program products are provided for processing a request relating to a mobile device. A request, including a mobile device identifier and a partner system identifier corresponding to the partner system, is received from a partner system via a communication network. An authorization procedure is executed based on the mobile device identifier and the partner system identifier. The authorization procedure includes determining whether a partner system account list, associated with the mobile device identifier, includes the partner system identifier. Authorization of the request is granted if the partner system account list includes the partner system identifier; and is denied if the partner system account list does not include the partner system identifier. A response to the request is transmitted to the partner system via the communication network, based on a result of the authorization procedure.


