Opaque Identifier Mediator for Secure Cross-System Data Consolidation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional computer systems require users to share login credentials to transfer data between independently operated systems, which is suboptimal and vulnerable to unauthorized access.

Innovation Solution

A system and method using opaque user identifiers that allow data consolidation across multiple systems without exposing actual login credentials, employing a matching system to authenticate and manage data retrieval securely.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If users share login credentials to transfer data between independently operated systems, then data consolidation is achieved, but security is compromised and unauthorized access becomes possible

Engineering Contradiction:
Improvedata consolidation capabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an intermediary authentication system that mediates between data provider systems and data consumer systems. Instead of directly sharing credentials, the intermediary verifies identities and establishes secure connections, allowing data consolidation while preventing unauthorized access. The intermediary acts as a trusted third party that enables cross-system data access without exposing login credentials.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the authentication process into separate components: credential verification, identity confirmation, and data access authorization. By dividing the authentication mechanism into distinct stages performed by different system components, the patent enables data consolidation across systems while maintaining security through layered verification rather than direct credential sharing.

Inventive Principle:
Principle #1Segmentation

2Reliability

If opaque user identifiers are used to prevent credential exposure, then security is improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal authentication framework where a single opaque identifier system serves multiple functions: user identification, credential protection, and cross-system authorization. This multi-functional approach maintains security while reducing overall system complexity by consolidating authentication logic into a standardized protocol that works across different data provider and consumer systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses opaque identifiers as secure copies of user identities that can be transmitted between systems without exposing actual credentials. These identifier copies enable authentication and data access while maintaining security, as the opaque identifiers can be replicated and shared without compromising the original login information.

Inventive Principle:
Principle #26Copying

3Ease of operation

If conventional login credential sharing is used, then ease of operation is maintained, but vulnerability to theft and unauthorized access increases

Engineering Contradiction:
Improveoperational simplicityVSAvoidvulnerability to theft
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements temporary, session-based authentication tokens that are valid only for specific time periods and purposes. These short-lived credentials replace permanent login information, maintaining ease of operation for legitimate users while significantly reducing vulnerability to theft, as stolen tokens become useless after their expiration or upon successful authentication.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The patent converts the potential harm of credential exposure into a benefit by using opaque identifiers that are designed to be safe even if compromised. The system transforms the security risk into a protective mechanism where the identifier structure itself prevents unauthorized access, as the opaque format makes it impossible to use stolen identifiers for actual logins.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentUS12088575B2Systems and method for receiving information among computer systems without enabling log ins if the user identifiers are compromised
Publication Date: 2024.09.10 CHARLES SCHWAB & CO INC
  • US12088575B2 patent drawing
  • US12088575B2 patent drawing
  • US12088575B2 patent drawing

AI summary

A system and method allows a matching system to mediate requests for information among different computer systems without storing information that can be used to log into those computer systems.