Privacy-Preserving Assertion System for Account Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional methods for verifying account authenticity are inadequate in preventing man-in-the-middle attacks and expose account information, leading to potential fraud and high-friction experiences for users.
Innovation Solution
A system and method for validating accounts using assertions, where a server computer processes requests from relying entities to determine an assertions model, retrieves a package of assertions based on the account identifier's hash, and transmits these assertions securely, without exposing sensitive information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional verification methods (depositing trivial amount and requesting confirmation) are used, then account authenticity can be verified, but account information is exposed leading to potential fraud and security risks
Solution Approach 1:
The patent extracts only the essential verification information (account number confirmation) from the complete account data, allowing verification to proceed without exposing sensitive account details. The system separates the verification function from the data exposure risk by requesting only minimal necessary information.
Solution Approach 2:
The patent introduces an intermediary verification mechanism where the system acts as a mediator between the payer and payee. Instead of direct information exchange that exposes account details, the intermediary system facilitates verification through controlled information disclosure, preventing direct exposure of sensitive account information while maintaining verification reliability.
2Measurement precision
If complete account information is transmitted for verification, then verification accuracy is improved, but security risks and fraud potential increase
Solution Approach 1:
The patent applies local quality by providing different levels of information access to different entities. The verifying system receives only the specific account number needed for verification, while the full account details remain protected. This localized information disclosure maintains verification accuracy for the specific purpose while preventing broader security risks.
Solution Approach 2:
The patent extracts only the essential verification element (account number) from the complete account information set, allowing accurate verification to proceed without transmitting or exposing the full account details that would create security vulnerabilities and fraud risks.
3Reliability
If users provide complete personal information for identity verification, then verification completeness is improved, but user privacy and risk of identity fraud increase
Solution Approach 1:
The patent extracts only the specific identity information necessary for verification purposes from the user's complete personal data set. This allows verification completeness to be achieved for the specific transaction while preventing loss of broader privacy information that would create identity fraud risks.
Solution Approach 2:
The patent introduces an intermediary verification system that handles identity verification without requiring users to directly expose complete personal information. The intermediary processes verification using minimal necessary data, protecting user privacy while maintaining verification reliability.
Data Source
AI summary
Disclosed are methods and systems for enabling a package of assertions to be provided to a relying entity seeking to interact with an account. A server computer may receive, from a relying entity, a request for assertions, wherein the request for assertions includes an identifier of the relying entity and a hash of an identifier of an account. The server computer may determine an assertions model based on the identifier of the relying entity. The server computer may retrieve a package of assertions associated with the account based on the assertions model and the hash of the identifier of the account. The server computer may transmit the package of assertions to the relying entity.


