Transient Identifier Token for Consent-Based Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The unauthorized use of stolen social security numbers for identity theft is a growing problem, with existing measures failing to prevent repeated victimization and providing inadequate protection during financial transactions, as static social security numbers are often compromised and reused by malicious third parties.

Innovation Solution

A consent-based authorization system generates a one-time, transient identifier token that is randomly created and valid for a defined duration, which is used as a secure extension to the social security number during transactions, allowing users to control access and minimize the risk of identity theft by requiring validation for each transaction.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If a static social security number is used for transactions, then the transaction process is simple and efficient, but the risk of identity theft increases as the number becomes compromised and reused by malicious third parties

Engineering Contradiction:
Improvetransaction efficiencyVSAvoididentity theft risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent transforms the static social security number into a dynamic identifier by generating transient tokens that change with each transaction. The token includes a time-component that causes it to expire after a defined duration, ensuring that even if intercepted, the token cannot be reused. This dynamic approach maintains transaction efficiency while eliminating the risk associated with static identifiers.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent employs disposable transient tokens that are generated for each transaction and become invalid after use or expiration. These tokens are computationally inexpensive to generate but provide strong security because they cannot be reused. The token is discarded after serving its single purpose, preventing malicious reuse while maintaining simple transaction processes.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

2Ease of operation

If existing validation measures are implemented by providers, then services can be delivered to subscribers, but the measures are insufficient to protect against malicious third parties

Engineering Contradiction:
Improveservice delivery capabilityVSAvoididentity protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a consent-based authorization system as an intermediary between the subscriber and the service provider. This intermediary validates whether the subscriber has authorized the specific transaction before allowing it to proceed. The system acts as a mediator that ensures both service delivery and identity protection by requiring explicit consent for each transaction involving sensitive data.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements a feedback mechanism where the authorization system continuously monitors and validates transactions against the subscriber's consent preferences. The system provides real-time feedback by blocking unauthorized transactions and allowing only those that have been explicitly approved by the subscriber, thereby enhancing both service delivery and identity protection.

Inventive Principle:
Principle #23Feedback

3Reliability

If a one-time transient identifier token is generated for each transaction, then identity theft risk is reduced, but the system complexity increases

Engineering Contradiction:
Improveidentity protectionVSAvoidauthorization system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal authorization system that can be integrated into multiple different transaction types and service providers through a common interface. The consent-based authorization mechanism works across various contexts (financial transactions, data access, service subscriptions) using the same fundamental principles, reducing the perceived complexity by providing a unified approach rather than requiring separate solutions for each scenario.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12199980B2Consent-based authorization system
Publication Date: 2025.01.14 IDENTITY REEL LLC
  • US12199980B2 patent drawing
  • US12199980B2 patent drawing
  • US12199980B2 patent drawing

AI summary

The subject matter of this specification can be implemented in, among other things, methods, systems, and computer-readable storage media. A method can include receiving a first request to retrieve an identifier token associated with a user account. The method can further include generating a first alphanumeric sequence associated with the user account and performing a randomization procedure on the first alphanumeric sequence to generate a second alphanumeric sequence. The method can further include generating the identifier token for a subscriber associated with the user account to provide to a second device. The method can further include receiving, from a third device, a second request including a second identifier token having a third alphanumeric sequence, the second request being associated with performing an action using sensitive data associated with the user account. The method can further include sending data including the second request to the third device.