Trustee-Based Data Transfer Authorization System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data transfer authorization methods, such as two-factor authentication, can be frustrating and unhelpful for vulnerable individuals like the elderly, as they often require customer involvement, which may not be feasible or reliable, especially when customers are temporarily unable to access their devices or networks.

Innovation Solution

A system and method that allows customers to designate trusted individuals or trustees within a network of trust, enabling third-party authentication for data transfers without requiring customer involvement, thus authorizing data transfers based on trustee confirmation even in the absence of customer authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If two-factor authentication is used for data transfer authorization, then security is improved, but ease of operation deteriorates for vulnerable customers

Engineering Contradiction:
Improveauthentication securityVSAvoidcustomer operation difficulty
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a trustee as an intermediary who performs second-factor authentication on behalf of the customer. The trustee receives authentication requests, verifies the customer's identity through alternative means, and submits authentication responses to the authentication system, thereby eliminating the need for the customer to directly interact with the authentication process while maintaining security

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If customer involvement is required in authentication processes, then authentication reliability is improved, but productivity deteriorates when customers are temporarily unable to access their devices

Engineering Contradiction:
Improveauthentication reliabilityVSAvoiddata transfer completion rate
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary verification by checking whether the customer computing device is associated with a trustee in the system of trust before initiating the authentication process. This preliminary action allows the system to proactively route authentication requests to the appropriate trustee, ensuring that authentication can proceed without requiring customer device access while maintaining security standards

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If third-party authentication is implemented, then ease of operation is improved for vulnerable customers, but device complexity increases

Engineering Contradiction:
Improveauthentication simplicityVSAvoidsystem architecture complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The trustee computing device is designed with multi-functionality, serving both as a standard computing device for the trustee's personal use and as an authentication intermediary for the authentication system. The device can receive authentication requests from the authentication system, perform verification actions, and submit responses, thereby eliminating the need for separate dedicated authentication hardware while maintaining security

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250021634A1System and method for authorizing data transfers
Publication Date: 2025.01.16 THE TORONTO DOMINION BANK
  • US20250021634A1 patent drawing
  • US20250021634A1 patent drawing
  • US20250021634A1 patent drawing

AI summary

Systems and methods for authorizing data transfers are disclosed. Exemplary implementations may: receive a data transfer authorization request based on a data transfer initiated by a customer computing device; when the customer computing device is associated with a system of trust: send a third-party second-factor authentication message to trustee computing device(s) without sending any message to the customer computing device, and authorize the data transfer system to complete the data transfer request in response to receipt of a third-party authentication confirmation from the trustee computing device(s) and in the absence of any authentication confirmation from the customer computing device.