Token-Mediated Account Access for Revocable Third-Party Transactions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems lack secure and efficient methods for accessing user account data and managing transactions without disclosing account credentials, and there is no robust mechanism for revoking access once credentials are shared.
Innovation Solution
The system employs virtualized or simulated instances of software applications that interface with external systems via proprietary APIs, allowing secure data retrieval and transaction management without revealing account credentials, using tokens for authorization and de-authorization, and generating interactive user interfaces for improved human-computer interaction.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If account credentials are shared with service providers for access, then transaction capability is enabled, but security is compromised because credentials cannot be securely revoked
Solution Approach 1:
The patent introduces tokens as intermediary credentials that mediate between users and service providers. Instead of sharing direct account credentials, users receive tokens that enable transaction capabilities while maintaining security control. These tokens can be independently revoked without affecting the underlying account credentials, thus resolving the contradiction between enabling transactions and maintaining security.
Solution Approach 2:
The patent segments the credential system into multiple independent tokens, each representing a specific permission or access level. This segmentation allows selective revocation of individual tokens while preserving others, enabling fine-grained control over transaction capabilities without compromising overall security. Each token acts as an independent unit that can be managed separately from the main account credentials.
2Adaptability or versatility
If multiple external systems are accessed directly, then data accessibility is improved, but system complexity increases
Solution Approach 1:
The patent creates a universal token system that can be used across multiple external systems and services. Instead of implementing separate authentication mechanisms for each system, a single token infrastructure provides multi-functional access control. This universal approach enables data accessibility across diverse systems while reducing overall complexity by eliminating the need for multiple separate credential management systems.
3Ease of operation
If credentials are shared with third parties, then service functionality is enabled, but control over account access is lost
Solution Approach 1:
The patent implements dynamic token management that allows users to adjust access control permissions in real-time. Tokens can be issued with specific validity periods, scope limitations, and conditional permissions. Users can dynamically revoke or modify token permissions without permanently sharing credentials, enabling flexible control over service functionality while maintaining adaptability in access management.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A permissions management system is disclosed for enabling a user to securely authorize a third-party system to access user account data and initiate transactions related to a user account, without disclosing to the third-party system account credentials. The system enables the user to also securely de-authorize the third-party system. For example, records may be automatically generated that securely store account information, including one or more permissions related to the account and/or the third-party. A token associated with a record may be shared with the third-party system, but neither the record itself, nor the user account credentials, may be shared with the third-party. Accordingly, the third-party may request user account data and/or initiate transactions by providing the token, but does not itself know, e.g., the user account credentials. Further, the user may set various permissions related to the token, and may also revoke the token (e.g., de-authorize the third-party), thus providing increased security to the user's account.