Access Token Verification via Embedded Receiver Identity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing access token systems fail to verify whether an access token is transmitted by a proper receiver and identify the proper receiver of a falsely transmitted access token, leading to potential malicious use and convenience issues due to shortened token validity.
Innovation Solution
An information processing device generates an access token including identification information of the receiver, along with a digital signature, to enable verification of the proper distribution and authenticity of the access token, using a verification device to determine validity and proper distribution based on the token's content and time constraints.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the term of validity of an access token is shortened to prevent malicious use, then security is improved, but the available period for legitimate use is reduced and convenience deteriorates
Solution Approach 1:
The patent applies preliminary action by embedding identification information of the proper receiver into the access token before transmission. This allows the verification device to proactively check whether the token is transmitted by the proper receiver, preventing malicious use before it occurs. The token includes all necessary verification data in advance, enabling immediate validation without shortening the validity period.
Solution Approach 2:
The patent introduces an intermediary verification mechanism where the access token carries identification information that acts as a mediator between the transmitter and verification device. This intermediary element enables the verification device to authenticate the transmitter's identity, allowing longer token validity periods while maintaining security through proper verification.
2Reliability
If identification information is added to the access token to verify proper distribution, then verification capability is improved, but the complexity of the token structure increases
Solution Approach 1:
The patent merges the identification information with the access token structure, combining multiple functions into a single integrated token. The identification information is embedded within the token itself rather than being a separate element, allowing verification of proper distribution without requiring additional external verification structures or complex multi-component systems.
Solution Approach 2:
The access token is designed with multi-functionality, serving both as an authentication credential and as a carrier of identification information for verifying proper distribution. This universal design allows the same token structure to perform multiple verification functions without requiring separate specialized structures for each function.
Data Source
AI summary
An information processing device according to the present invention includes: a memory storing instructions; and at least one processor configured to execute the instructions to perform: acquiring a first time; generating, based on the first time, a term of validity of a first access token, and generating a policy including the first access token, the term of validity, and identification information of a receiver of the first access token; generating a digital signature, based on the policy; generating a second access token including the policy and the digital signature; and transmitting the second access token to another device.


