Token-Mediated Account Access for Revocable Third-Party Transactions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems lack secure and efficient methods for accessing user account data and managing transactions without disclosing account credentials, and there is no robust mechanism for revoking access once credentials are shared.

Innovation Solution

The system employs virtualized or simulated instances of software applications that interface with external systems via proprietary APIs, allowing secure data retrieval and transaction management without revealing account credentials, using tokens for authorization and de-authorization, and generating interactive user interfaces for improved human-computer interaction.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If account credentials are shared with service providers for access, then transaction capability is enabled, but security is compromised because credentials cannot be securely revoked

Engineering Contradiction:
Improvetransaction capabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces tokens as intermediary credentials that mediate between users and service providers. Instead of sharing direct account credentials, users receive tokens that enable transaction capabilities while maintaining security control. These tokens can be independently revoked without affecting the underlying account credentials, thus resolving the contradiction between enabling transactions and maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the credential system into multiple independent tokens, each representing a specific permission or access level. This segmentation allows selective revocation of individual tokens while preserving others, enabling fine-grained control over transaction capabilities without compromising overall security. Each token acts as an independent unit that can be managed separately from the main account credentials.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If multiple external systems are accessed directly, then data accessibility is improved, but system complexity increases

Engineering Contradiction:
Improvedata accessibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal token system that can be used across multiple external systems and services. Instead of implementing separate authentication mechanisms for each system, a single token infrastructure provides multi-functional access control. This universal approach enables data accessibility across diverse systems while reducing overall complexity by eliminating the need for multiple separate credential management systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If credentials are shared with third parties, then service functionality is enabled, but control over account access is lost

Engineering Contradiction:
Improveservice functionalityVSAvoidaccess control
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic token management that allows users to adjust access control permissions in real-time. Tokens can be issued with specific validity periods, scope limitations, and conditional permissions. Users can dynamically revoke or modify token permissions without permanently sharing credentials, enabling flexible control over service functionality while maintaining adaptability in access management.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP4395394B1Secure permissioning of access to user accounts, including secure deauthorization of access to user accounts
Publication Date: 2025.10.29 PLAID INC
  • EP4395394B1 patent drawingFigure 1
  • EP4395394B1 patent drawingFigure 2
  • EP4395394B1 patent drawingFigure 3

AI summary

A permissions management system is disclosed for enabling a user to securely authorize a third-party system to access user account data and initiate transactions related to a user account, without disclosing to the third-party system account credentials. The system enables the user to also securely de-authorize the third-party system. For example, records may be automatically generated that securely store account information, including one or more permissions related to the account and/or the third-party. A token associated with a record may be shared with the third-party system, but neither the record itself, nor the user account credentials, may be shared with the third-party. Accordingly, the third-party may request user account data and/or initiate transactions by providing the token, but does not itself know, e.g., the user account credentials. Further, the user may set various permissions related to the token, and may also revoke the token (e.g., de-authorize the third-party), thus providing increased security to the user's account.