Resource Gateway for Secure Account Anonymity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Identity and Access Management (IAM) systems face challenges in securely authenticating client applications accessing protected resources without redundant user administration, particularly in ensuring the anonymity of sensitive account information and preventing malicious attacks.

Innovation Solution

An electronic device and method that utilize a machine-readable optical label encoding transaction details, an access token, and multiple layers of authentication to securely transfer data between accounts, with a mobile security service acting as an intermediary between client applications and protected resources, ensuring secure authentication and authorization while preserving account anonymity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If IAM systems implement open industry standards for interoperability, then user authentication and authorization across autonomous security domains is enabled, but security vulnerabilities and malicious attacks increase

Engineering Contradiction:
ImproveinteroperabilityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a resource gateway as an intermediary component between client applications and protected resources. The gateway validates access requests, verifies client credentials, and manages authentication tokens, thereby enabling interoperability while filtering out malicious attacks before they reach the protected resources.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the authentication and authorization process into distinct components: client application authentication, resource gateway validation, and protected resource access control. This segmentation allows each component to specialize in specific security functions, improving both interoperability and security against malicious attacks.

Inventive Principle:
Principle #1Segmentation

2Speed

If client applications directly access protected resources, then access speed is improved, but security control and authentication verification deteriorate

Engineering Contradiction:
Improveaccess speedVSAvoidsecurity control
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The resource gateway performs preliminary authentication and validation of client applications before they access protected resources. By pre-verifying credentials and establishing security contexts in advance, the system maintains fast access speeds while ensuring robust security control through upfront verification.

Inventive Principle:
Principle #10Preliminary action

3Device complexity

If user credentials are stored and processed centrally, then authentication management is simplified, but the risk of data breaches and unauthorized access increases

Engineering Contradiction:
Improveauthentication managementVSAvoiddata breach risk
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts sensitive credential verification logic from centralized storage and relocates it to the resource gateway. The gateway handles authentication token validation and credential verification locally, reducing the attack surface for centralized credential databases while maintaining simplified authentication management through standardized token-based processes.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11582219B2Methods and systems for controlling access to a protected resource
Publication Date: 2023.02.14 THE TORONTO DOMINION BANK
  • US11582219B2 patent drawing
  • US11582219B2 patent drawing
  • US11582219B2 patent drawing

AI summary

An electronic device is disclosed. The electronic device includes a memory, a camera module, a communications module, and a processor that is configured to: receive, from the camera module, image data associated with a machine-readable optical label, the optical label encoding transaction details of a transfer of data to a recipient account, wherein the transaction details do not indicate an identity of the recipient account; receive a user input indicating authorization to initiate a transfer of data, via a protected resource, from an account associated with the user to the recipient account; and in response to receiving the user input, generate a request for initiating the transfer of data based on the transaction details, the request including an access token for use in authenticating the user on requests to access the protected resource.