User-Regulated Account Linking for Business Entitlement Objects

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face challenges in balancing security and usability when managing access to features controlled by business entitlement objects (BEOs), as they often require either increased operational costs or compromised security due to the need for manual validation and restrictive linking conditions.

Innovation Solution

The implementation of user-regulated linking, where primary users define secondary user conditions allowing secondary users to link their accounts to BEOs, enabling self-regulation of access while minimizing provider involvement and optimizing security and usability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual validation and restrictive linking conditions are implemented to improve security, then security is improved, but operational cost increases and usability deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidusability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables users to autonomously link their accounts to BEOs by having them generate and share cryptographic keys directly with potential secondary users. This self-service mechanism eliminates the need for provider-mediated validation, allowing users to independently manage access while maintaining security through cryptographic verification. The primary user controls which secondary users can access the BEO by managing key distribution, thus improving usability without compromising security.

Inventive Principle:
Principle #25Self-service

2Reliability

If manual validation and restrictive linking conditions are implemented to improve security, then security is improved, but operational cost increases

Engineering Contradiction:
ImprovesecurityVSAvoidoperational cost
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent replaces the mechanical system of manual provider validation with a cryptographic system. Instead of providers manually verifying and managing user links to BEOs, the system uses public-key cryptography where users generate key pairs and share public keys for authentication. This substitution eliminates the need for costly manual validation processes while maintaining security through cryptographic verification, thereby reducing operational costs without sacrificing security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Ease of operation

If easy access is provided to improve usability, then usability is improved, but security deteriorates due to illegitimate access

Engineering Contradiction:
ImproveusabilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system introduces cryptographic keys as an intermediary mechanism between users and BEOs. Instead of direct provider-mediated access control, users exchange cryptographic keys that serve as secure intermediaries for authentication. The primary user's public key acts as a mediator that verifies the identity of secondary users attempting to access the BEO, enabling easy self-service access while maintaining security through cryptographic verification rather than restrictive provider controls.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7669246B2System and method for linking user accounts to business entitlement objects
Publication Date: 2010.02.23 HEWLETT PACKARD ENTERPRISE DEV LP
  • US7669246B2 patent drawing
  • US7669246B2 patent drawing
  • US7669246B2 patent drawing

AI summary

A system comprises a business entitlement object, a primary account associated with a first user, wherein the primary account is linked to the business entitlement object, a secondary user condition defined by the first user, and a first secondary account, wherein a second user links the first secondary account to the business entitlement object according to the secondary user condition.