Opaque Identifier Mediator for Secure Cross-System Data Transfer

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional computer systems require users to provide login credentials to transfer data between independently operated systems, which is suboptimal and vulnerable to unauthorized access.

Innovation Solution

A system and method using opaque user identifiers that allow data consolidation across multiple systems without requiring direct login credentials, employing a matching system to authenticate and manage access, ensuring secure data retrieval while preventing unauthorized access even if identifiers are compromised.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional login credentials are used for data transfer between systems, then data transfer functionality is achieved, but security vulnerability increases and unauthorized access risk increases

Engineering Contradiction:
Improvedata transfer securityVSAvoidunauthorized access risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary authentication system that mediates between the user and the data provider system. Instead of directly using login credentials, the system uses an opaque identifier that acts as a mediator - it references the user account without exposing actual credentials, thereby preventing unauthorized access while enabling data transfer.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a copy or reference (opaque identifier) of the user identity that can be used for authentication purposes without exposing the original credentials. This opaque identifier is a simplified representation that enables data transfer functionality while eliminating security vulnerabilities associated with credential exposure.

Inventive Principle:
Principle #26Copying

2Reliability

If opaque user identifiers are used instead of login credentials, then security is improved and unauthorized access is prevented, but system complexity increases

Engineering Contradiction:
Improveaccount securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication process into distinct components: the opaque identifier generation, the identifier storage, and the verification process. This segmentation allows each component to be independently managed and optimized, reducing overall system complexity while maintaining security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The opaque identifier serves multiple functions: it acts as a unique user reference, enables authentication, and prevents credential exposure. This multi-functionality reduces the need for separate mechanisms for each function, thereby simplifying the overall system architecture.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11546316B1System and method for receiving information among computer systems without enabling log ins if the user identifiers are compromised
Publication Date: 2023.01.03 CHARLES SCHWAB & CO INC
  • US11546316B1 patent drawing
  • US11546316B1 patent drawing
  • US11546316B1 patent drawing

AI summary

A system and method allows a matching system to mediate requests for information among different computer systems without storing information that can be used to log into those computer systems.