Multi-Level Authorization System for Confidential Data Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security systems in financial institutions do not adequately allow customers to control or monitor the activities of authorized personnel handling their confidential information, leading to potential misuse and unauthorized transactions, which can go undetected even after the service session has expired.

Innovation Solution

Implementing a multi-party and multi-level authorization system that uses a One Time Authorization Token (OTAT) to authenticate both customers and service providers, ensuring that access to confidential information is restricted to authorized personnel only until the service request is completed or the OTAT validity time expires, with features like biometric authentication and differential access levels based on the sensitivity of the information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If authorized personnel are given full access to customer confidential information to process service requests, then service efficiency is improved, but security risk increases due to potential misuse and unauthorized transactions

Engineering Contradiction:
Improveservice efficiencyVSAvoidsecurity risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent segments access control into multiple levels (customer authorization level, service provider execution level, supervisor approval level for high-risk operations) and multiple parties (customer, service provider, supervisor). This segmentation allows efficient service delivery at lower levels while introducing security checkpoints at higher levels, thus resolving the contradiction between service efficiency and security risk.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements real-time feedback mechanisms where customers can monitor and control authorized personnel activities through mobile devices. The system provides continuous feedback on transaction status, authorization validity, and service provider actions, enabling customers to revoke access immediately if misuse is detected, thus maintaining security without compromising service efficiency.

Inventive Principle:
Principle #23Feedback

2Reliability

If customers are given full control and visibility over authorized personnel activities, then security is improved, but system complexity increases due to multiple authorization levels and monitoring mechanisms

Engineering Contradiction:
Improvesecurity controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a mobile device as an intermediary between the customer and the core banking system. The mobile application serves as a mediator that simplifies the user interface while maintaining complex security protocols in the backend. This intermediary layer provides customers with intuitive control and visibility without exposing them to the underlying system complexity, thus improving security control while managing system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements a universal authorization framework that handles multiple service types (cash transactions, account access, information disclosure) through a common multi-level authorization mechanism. This universal approach consolidates what could be separate complex systems into a single streamlined process, reducing overall system complexity while maintaining comprehensive security control across all service types.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If session expiry time is extended to allow completion of service requests, then service completion is improved, but security vulnerability increases due to longer window for unauthorized transactions

Engineering Contradiction:
Improveservice completionVSAvoidsecurity vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic session management where authorization tokens have time-based validity that adjusts based on service completion status. The system dynamically extends or revokes access rights based on real-time monitoring of service progress, customer actions, and transaction status. This dynamic approach allows sufficient time for legitimate service completion while automatically limiting the window for unauthorized transactions, thus resolving the contradiction between service completion and security vulnerability.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary actions by requiring advance customer authorization through the mobile application before service providers can access confidential information or perform transactions. This preliminary authorization step establishes a pre-approved framework within which services can be completed efficiently, while the pre-set expiration and revocation mechanisms automatically close security vulnerabilities once authorization is no longer needed, thus balancing service completion with security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3073671B1System and method enabling multiparty and multi level authorizations for accessing confidential information
Publication Date: 2019.04.03 TATA CONSULTANCY SERVICES LTD
  • EP3073671B1 patent drawingFigure 1
  • EP3073671B1 patent drawingFigure 2
  • EP3073671B1 patent drawingFigure 3

AI summary

Disclosed is a method and system for enabling multi-party and multi level authorizations for accessing confidential information. A first set of access privilege levels, a first set of credentials, a second set of access privilege levels and a second set of credentials are configured corresponding to a plurality of services. A service consumer may be identified using an identifier and thereafter authorized to issue a request for a service based upon authentication of the service consumer using an access privilege level of the first set of access privilege levels and a credential of the first set of credentials. After the authentication, an OTAT is generated. A service provider may be authenticated using the OTAT, an access privilege level of the second set of access privilege levels and a credential of the second set of credentials. The service provider is then authorized to access the confidential information of the service consumer.