Client Device Authentication with Unified API Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current digital servicing platforms for business banking fail to support the evolving needs of businesses, requiring multiple credentials for interactions and lacking robust security, leading to vulnerabilities and inefficiencies.

Innovation Solution

Implementing a security architecture with API policies and a backend system that uses OAuth tokens and TLS encryption to make user identity and entitlements immutable, offloading authentication and authorization from front-end components to a secure back-end environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current digital servicing platforms are used, then businesses can access financial services, but the systems lack robust security and require multiple credentials, creating vulnerabilities

Engineering Contradiction:
ImprovesecurityVSAvoidmultiple credentials
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges authentication and authorization functions into a unified policy enforcement interceptor that intercepts API calls and validates credentials through a centralized policy information point, eliminating the need for multiple separate credential systems while enhancing security

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The policy enforcement interceptor acts as an intermediary between client devices and the enterprise system, mediating authentication and authorization by intercepting API calls and validating credentials through the policy information point, thereby centralizing security control

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authentication and authorization are handled by front-end components, then systems can process requests, but security vulnerabilities arise

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts authentication and authorization logic from front-end components and relocates it to a back-end policy enforcement interceptor, removing security vulnerabilities from the front-end while maintaining seamless user experience through transparent credential validation

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If platforms are updated with current digital experience expectations, then servicing capabilities improve, but significant updates are required impacting the workforce

Engineering Contradiction:
Improveservicing capabilitiesVSAvoidsystem updates
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The policy enforcement interceptor provides universal authentication and authorization capabilities that work across multiple systems and applications, enabling the enterprise system to meet current digital experience expectations without requiring separate credential systems for each application

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12363114B2System and method for authenticating client devices communicating with an enterprise system
Publication Date: 2025.07.15 THE TORONTO DOMINION BANK
  • US12363114B2 patent drawing
  • US12363114B2 patent drawing
  • US12363114B2 patent drawing

AI summary

A system and method are provided for authenticating client devices communicating with an enterprise system. The method includes providing a policy enforcement interceptor to intercept API calls and enabling the policy enforcement interceptor to communicate with a policy information point to query the at least one endpoint for entitlements associated with an account. The method also includes intercepting an API call to the application API, communicating with the policy information point to determine entitlements associated with the account by having the policy information point query an entitlements database and, when the entitlements returned to the policy enforcement interceptor are valid, invoking a policy decision point to validate the client device. The method also includes, when the client device is validated, permitting invocation of the API. The method also includes providing an API response to the client device to permit access to the application via the API.