Subtoken Authorization for Secure Payment Pool Transactions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a risk of unauthorized access and transactions when credentials are shared between parties, such as parents and children, as unauthorized individuals can obtain and misuse these credentials, leading to security concerns.

Innovation Solution

The generation and use of subtokens associated with a user's account, where a second credential is derived from a first credential and sent through a delivery channel, requiring the recipient to provide authentication credentials and a delivery channel identifier for transaction authorization, ensuring secure and controlled access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If credentials are shared between parties to enable transactions, then transaction capability is improved, but security is worsened due to risk of unauthorized access

Engineering Contradiction:
Improvetransaction capabilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments credentials into multiple components: primary credentials held by the first party, secondary credentials generated for the second party, and delivery channel identifiers. This segmentation allows the second party to conduct transactions without obtaining the primary party's actual credentials, thus maintaining security while enabling transaction capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary credential system where secondary credentials act as a mediator between the primary credentials and the transaction system. The secondary credentials, combined with delivery channel identifiers, enable the second party to access transaction capabilities without directly exposing or using the primary party's sensitive credentials.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If secondary credentials are distributed to multiple parties, then transaction flexibility is improved, but credential security is worsened

Engineering Contradiction:
Improvetransaction flexibilityVSAvoidcredential security risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by making secondary credentials unique to specific delivery channels and parties. Each secondary credential is tied to a specific delivery channel identifier and intended recipient, meaning credentials have different properties and permissions depending on their local context. This prevents unauthorized parties from using credentials outside their intended scope.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system performs preliminary actions by generating and distributing secondary credentials in advance through secure delivery channels before actual transactions occur. This allows the second party to be pre-authenticated and authorized for transactions without requiring real-time credential sharing or exposure of primary credentials.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If delivery channels are used to transmit credentials, then ease of credential distribution is improved, but risk of credential interception is worsened

Engineering Contradiction:
Improvecredential distributionVSAvoidcredential interception risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent creates secondary credentials that are functional copies or derivatives of the primary credentials rather than the credentials themselves. These secondary credentials replicate the necessary authentication functionality for transactions while being distinct from the original sensitive credentials, allowing safe distribution through delivery channels.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent adds another dimension to credential security by introducing delivery channel identifiers as a separate layer. Instead of relying solely on the secrecy of credentials, the system uses the delivery channel identifier as an additional authentication factor, effectively moving from a one-dimensional credential model to a two-dimensional credential+channel model.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS11170379B2Peer forward authorization of digital requests
Publication Date: 2021.11.09 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US11170379B2 patent drawing
  • US11170379B2 patent drawing
  • US11170379B2 patent drawing

AI summary

Embodiments may enable a user to forward authorize a specific amount to a member of their payment pool by distributing a subtoken generated from a token issued to the user. The member of the payment pool may receive the subtoken through a delivery channel (e.g., by e-mail) and may utilize the subtoken during a purchase by providing a corresponding delivery channel identifier (e.g., e-mail address) as an authentication credential. In some embodiments, the subtoken may be time-sensitive and may be valid during a time period designated by the user.