Secondary Account Access via Authentication Token
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Primary account holders face challenges in sharing digital content with family members without granting full access to their credentials, especially when third-party Identity Providers are involved, leading to undesired access to those accounts.
Innovation Solution
A system and method for managing user account access that generates a secondary account linked to a primary user account, using an authentication token to grant restricted access to devices, without disclosing full primary account credentials or third-party identity information, utilizing technologies like WiFi-Direct, Bluetooth, and NFC for token transfer.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If full access to primary account credentials is granted to family members, then digital content sharing is enabled, but security risk increases and third-party account access is compromised
Solution Approach 1:
The patent segments the primary account credentials into separate components: the primary account holder retains the main credentials while family members receive derived credentials (authentication tokens) that provide only subset access to specific digital content. This segmentation allows content sharing without compromising overall account security or exposing third-party account information.
2Ease of operation
If third-party Identity Providers are used for authentication, then user convenience is improved, but access control precision deteriorates
Solution Approach 1:
The patent introduces an intermediary authentication token that acts as a mediator between the third-party Identity Provider and the digital content. The token is generated by the primary account holder and provides the family member with convenient authentication while simultaneously limiting access to only the authorized digital content, thus maintaining both ease of operation and access control precision.
Data Source
AI summary
A user account access management system includes a computing platform having a hardware processor and a system memory storing a user account access software code. The hardware processor executes the user account access software code to receive, from a first user device, a secondary account profile data for generating a secondary account associated with a primary user account registered with a web based service, and to receive, from a second user device, a sign up request for using the web based service. The hardware processor further executes the user account access software code to transmit an authentication token to one of the first user device and the second user device, receive the authentication token from the other of the first user device and the second user device, and link the secondary account with the second user device based on receiving the authentication code.


