Secure Third-Party Data Integration via Intermediary Token Exchange
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional techniques for handling consumer requests for secured information often result in insecure storage or additional authentication steps, disrupting the user experience and violating local regulations by requiring multiple systems to access sensitive data, which complicates the integration of secured information into third-party applications.
Innovation Solution
A telecommunications network server facilitates the integration of sensitive data into third-party applications by verifying user identity and generating access tokens, allowing secure delivery of sensitive data to user devices without storing it on the third-party system, thus reducing the number of systems accessing the data and enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the online service stores a copy of the requested secure information, then the information can be displayed to the consumer, but the security of the information is compromised due to increased access points
Solution Approach 1:
The patent introduces a data provider service as an intermediary between the consumer and the secure information storage system. The data provider service receives authentication credentials from the consumer, verifies them, and then provides the secure information without the online service needing to store or access the actual sensitive data. This mediator approach enables display functionality while maintaining security by eliminating the need for the online service to hold copies of sensitive information.
2Ease of operation
If the consumer is directed to the separate data provider service to view secure information, then the information can be displayed, but additional authentication processes are required which frustrate the consumer
Solution Approach 1:
The patent merges the authentication processes of the online service and the data provider service into a single unified authentication event. When the consumer authenticates with the online service, the authentication credentials are shared with the data provider service through secure token exchange. This allows the consumer to access secure information displayed within the online service interface without undergoing separate authentication at the data provider service, eliminating redundant authentication steps and improving user experience.
3Adaptability or versatility
If multiple systems access the secure information, then the information can be displayed through multiple services, but compliance with local laws and regulations is violated
Solution Approach 1:
The data provider service acts as a compliant intermediary that controls and limits access to secure information. Instead of allowing multiple systems to directly access and store sensitive data, the data provider service receives authenticated requests, retrieves the necessary information, and provides it to authorized services through secure API interfaces. This architecture ensures that only the minimum necessary systems access the data, maintaining regulatory compliance while enabling service integration through standardized interfaces.
Solution Approach 2:
The patent implements a controlled copying mechanism where the data provider service creates temporary copies of secure information only when needed for display, and these copies are immediately deleted after use. The online service receives the information through secure token-based access without permanently storing it. This approach enables the information to be displayed across multiple services while ensuring that no system maintains persistent copies, thereby complying with regulations that limit data retention and access.
Data Source
AI summary
Certain aspects involve facilitating the integration of sensitive data from a data provider into an instance of a web-based, third-party application. For example, a data provider service can receive an authentication API call from a third-party system. The authentication API call can include a user identifier and a request for an access token usable by a web-based interface of the third-party system. The data provider service can generate an access token for the third-party system from which the authentication API call is received. The data provider service can subsequently receive, from the user device, a feature API call including the access token and a feature request for sensitive data. The data provider service can generate output data specific to the user identified by the access token included in the feature API call. The data provider service can provide the output to the user device via the web-based interface.


