Opaque User Identifier Intermediary for Secure Data Transfer
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network communication between computer systems is suboptimal from a security standpoint, lacking effective measures to ensure secure data transfer without compromising user identifiers.
Innovation Solution
A system and method that utilizes encrypted connections validated by digital certificates, white lists, and black lists of IP addresses to secure data transfer by using an opaque user identifier different from the login identifier, ensuring only approved firms and users can access account data, and authenticating IP addresses to prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional network communication protocols are used for data transfer, then ease of operation is maintained, but security is compromised due to exposure of user identifiers
Solution Approach 1:
The patent introduces an intermediary authentication mechanism that mediates between the data transfer request and the user identifier exposure. The system uses a separate authentication channel with digital certificates and IP address validation to verify identities without exposing user identifiers in the data transfer protocol, thus maintaining both security and ease of operation.
Solution Approach 2:
The patent segments the authentication process from the data transfer process. Authentication is performed separately using digital certificates and IP address validation, while data transfer uses opaque identifiers. This segmentation allows each process to be optimized independently - authentication for security and data transfer for ease of operation.
2Ease of operation
If user identifiers are transmitted in clear text for authentication, then ease of operation is improved, but security is worsened due to potential identifier compromise
Solution Approach 1:
The patent creates a copy of the authentication mechanism that does not rely on transmitting user identifiers. Instead of copying the identifier itself, the system copies the verification function using digital certificates and IP address validation, eliminating the need to transmit sensitive identifier information while maintaining authentication capability.
Solution Approach 2:
The patent introduces an intermediary authentication layer that verifies identities without requiring direct transmission of user identifiers. The intermediary system uses digital certificates and IP address validation to establish trust, allowing authentication to occur without exposing the actual user identifiers that would otherwise need to be transmitted in clear text.
3Reliability
If IP address filtering is implemented to block unauthorized access, then security is improved, but ease of operation is worsened due to restricted communication
Solution Approach 1:
The patent performs preliminary IP address validation and digital certificate verification before establishing data transfer connections. By pre-authorizing trusted IP addresses and certificates, the system automates the security checks, eliminating the need for manual intervention while maintaining both security and ease of operation for authorized users.
Solution Approach 2:
The patent implements self-service authentication where systems automatically validate each other using pre-configured digital certificates and IP address whitelists. This eliminates the need for manual authentication interventions, allowing authorized communication to proceed automatically without user intervention, thus maintaining ease of operation while enforcing security.
Data Source
AI summary
A system and method provides security features for inter-computer communications. A user identifier of the user that cannot be used to log the user in to a data consolidating system is received by a matching system from the data consolidating system. The validity of the user is checked at the matching system and, in response to the checking, the user identifier is converted to a different user identifier and the different user identifier is provided to a data providing system by the matching system. The data providing system provides the data of the user in response, and the matching system forwards the data to the data consolidating system.


