Subtoken Authorization for Secure Payment Pool Transactions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a risk of unauthorized access and transactions when credentials are shared between parties, such as parents and children, as unauthorized individuals can obtain and misuse these credentials, leading to security concerns.
Innovation Solution
The generation and use of subtokens associated with a user's account, where a second credential is derived from a first credential and sent through a delivery channel, requiring the recipient to provide authentication credentials and a delivery channel identifier for transaction authorization, ensuring secure and controlled access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If credentials are shared between parties to enable transactions, then transaction capability is improved, but security is worsened due to risk of unauthorized access
Solution Approach 1:
The patent segments credentials into multiple components: primary credentials held by the first party, secondary credentials generated for the second party, and delivery channel identifiers. This segmentation allows the second party to conduct transactions without obtaining the primary party's actual credentials, thus maintaining security while enabling transaction capability.
Solution Approach 2:
The patent introduces an intermediary credential system where secondary credentials act as a mediator between the primary credentials and the transaction system. The secondary credentials, combined with delivery channel identifiers, enable the second party to access transaction capabilities without directly exposing or using the primary party's sensitive credentials.
2Adaptability or versatility
If secondary credentials are distributed to multiple parties, then transaction flexibility is improved, but credential security is worsened
Solution Approach 1:
The patent applies local quality by making secondary credentials unique to specific delivery channels and parties. Each secondary credential is tied to a specific delivery channel identifier and intended recipient, meaning credentials have different properties and permissions depending on their local context. This prevents unauthorized parties from using credentials outside their intended scope.
Solution Approach 2:
The system performs preliminary actions by generating and distributing secondary credentials in advance through secure delivery channels before actual transactions occur. This allows the second party to be pre-authenticated and authorized for transactions without requiring real-time credential sharing or exposure of primary credentials.
3Ease of operation
If delivery channels are used to transmit credentials, then ease of credential distribution is improved, but risk of credential interception is worsened
Solution Approach 1:
The patent creates secondary credentials that are functional copies or derivatives of the primary credentials rather than the credentials themselves. These secondary credentials replicate the necessary authentication functionality for transactions while being distinct from the original sensitive credentials, allowing safe distribution through delivery channels.
Solution Approach 2:
The patent adds another dimension to credential security by introducing delivery channel identifiers as a separate layer. Instead of relying solely on the secrecy of credentials, the system uses the delivery channel identifier as an additional authentication factor, effectively moving from a one-dimensional credential model to a two-dimensional credential+channel model.
Data Source
AI summary
Embodiments may enable a user to forward authorize a specific amount to a member of their payment pool by distributing a subtoken generated from a token issued to the user. The member of the payment pool may receive the subtoken through a delivery channel (e.g., by e-mail) and may utilize the subtoken during a purchase by providing a corresponding delivery channel identifier (e.g., e-mail address) as an authentication credential. In some embodiments, the subtoken may be time-sensitive and may be valid during a time period designated by the user.


