Secure Transaction Permission System for Multi-Shopper Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current access control methods in computer systems do not effectively allow authorized users to perform transactions on behalf of others without compromising the security of sensitive information, particularly in online payment systems where public and protected resources coexist.
Innovation Solution
A method is established where a second shopper is authorized to act on behalf of a first shopper by establishing a permission within a secure computing environment, with restrictions to prevent access to sensitive information, using an online merchant system with increased processing resources for secure communication and token generation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If authentication is required for accessing electronic resources, then security is improved, but accessibility to public resources deteriorates
Solution Approach 1:
The patent applies local quality by differentiating access requirements based on resource type. Public resources are accessible without authentication, while protected resources require authentication. This localized differentiation resolves the contradiction by ensuring security where needed while maintaining accessibility where appropriate.
Solution Approach 2:
The system segments electronic resources into public and protected categories with different access control mechanisms. This segmentation allows the system to simultaneously provide both open accessibility and secure authentication based on the specific resource characteristics.
2Ease of operation
If a second shopper acts on behalf of a first shopper, then transaction convenience is improved, but information security deteriorates
Solution Approach 1:
The patent introduces an intermediary mechanism (permission system with token generation) that mediates between the first shopper and second shopper. The permission establishes authorized representation while the token acts as a secure intermediary that enables the second shopper to access first shopper information without direct exposure, thus maintaining both convenience and security.
Solution Approach 2:
The system extracts sensitive information access from direct user interaction by using tokens as intermediaries. The token contains necessary authentication information but not all sensitive data, allowing the second shopper to perform transactions while extracting only the minimum necessary information security controls are applied.
3Adaptability or versatility
If access control rights are defined individually for each user, then customization is improved, but system complexity deteriorates
Solution Approach 1:
The patent implements a universal permission system that can be applied across different users and resources. Rather than managing individual access control rights for each user, the system uses a multi-functional permission framework that handles various access scenarios through a single mechanism, reducing system complexity while maintaining customization capability.
Data Source
AI summary
Methods, computer program products, and systems are presented and can include for instance: The method can include for example, establishing a permission that authorizes a second shopper to act on behalf of a first shopper, the first shopper having a profile that includes first shopper information stored in a secure computing environment; and performing a transaction based on one or more input of the second shopper, the transaction using content of the first shopper information stored in a secure computing environment, wherein the second shopper is restricted from accessing one or more information item of the first shopper information stored in a secure computing environment.


