Opaque User Identifier Intermediary for Secure Data Transfer

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network communication between computer systems is suboptimal from a security standpoint, lacking effective measures to ensure secure data transfer without compromising user identifiers.

Innovation Solution

A system and method that utilizes encrypted connections validated by digital certificates, white lists, and black lists of IP addresses to secure data transfer by using an opaque user identifier different from the login identifier, ensuring only approved firms and users can access account data, and authenticating IP addresses to prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network communication protocols are used for data transfer, then ease of operation is maintained, but security is compromised due to exposure of user identifiers

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary authentication mechanism that mediates between the data transfer request and the user identifier exposure. The system uses a separate authentication channel with digital certificates and IP address validation to verify identities without exposing user identifiers in the data transfer protocol, thus maintaining both security and ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the authentication process from the data transfer process. Authentication is performed separately using digital certificates and IP address validation, while data transfer uses opaque identifiers. This segmentation allows each process to be optimized independently - authentication for security and data transfer for ease of operation.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If user identifiers are transmitted in clear text for authentication, then ease of operation is improved, but security is worsened due to potential identifier compromise

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent creates a copy of the authentication mechanism that does not rely on transmitting user identifiers. Instead of copying the identifier itself, the system copies the verification function using digital certificates and IP address validation, eliminating the need to transmit sensitive identifier information while maintaining authentication capability.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces an intermediary authentication layer that verifies identities without requiring direct transmission of user identifiers. The intermediary system uses digital certificates and IP address validation to establish trust, allowing authentication to occur without exposing the actual user identifiers that would otherwise need to be transmitted in clear text.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If IP address filtering is implemented to block unauthorized access, then security is improved, but ease of operation is worsened due to restricted communication

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent performs preliminary IP address validation and digital certificate verification before establishing data transfer connections. By pre-authorizing trusted IP addresses and certificates, the system automates the security checks, eliminating the need for manual intervention while maintaining both security and ease of operation for authorized users.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements self-service authentication where systems automatically validate each other using pre-configured digital certificates and IP address whitelists. This eliminates the need for manual authentication interventions, allowing authorized communication to proceed automatically without user intervention, thus maintaining ease of operation while enforcing security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10447688B1System for secure communications
Publication Date: 2019.10.15 CHARLES SCHWAB & CO INC
  • US10447688B1 patent drawing
  • US10447688B1 patent drawing
  • US10447688B1 patent drawing

AI summary

A system and method provides security features for inter-computer communications. A user identifier of the user that cannot be used to log the user in to a data consolidating system is received by a matching system from the data consolidating system. The validity of the user is checked at the matching system and, in response to the checking, the user identifier is converted to a different user identifier and the different user identifier is provided to a data providing system by the matching system. The data providing system provides the data of the user in response, and the matching system forwards the data to the data consolidating system.