Device Access Token Authentication for Secure Data Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies face security vulnerabilities due to multiple authentication protocols for various applications on smart devices, leading to issues like code injection, user impersonation, and data interception, while also requiring frequent login credentials for data access, increasing network traffic.

Innovation Solution

Implementing a unified device access token system that enables secure server-to-device data exchange by authenticating smart devices and applications directly with a service provider computing system, minimizing the need for repeated authentication and reducing data storage on the device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple authentication protocols are implemented for various applications, then application functionality and versatility are improved, but security vulnerabilities increase due to code injection, user impersonation, and data interception risks

Engineering Contradiction:
Improveapplication functionalityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements a universal authentication protocol that serves multiple applications and data access scenarios. A single protocol handles account data access, transaction initiation, and third-party application authorization, eliminating the need for multiple separate authentication mechanisms while maintaining security consistency across all functions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary authentication mechanism that mediates between applications and account data. The authentication protocol acts as a secure intermediary layer that verifies requests without exposing sensitive credentials to applications, preventing code injection and data interception while enabling versatile application access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If login credentials are stored by applications for data access, then ease of operation is improved, but security is compromised due to credential storage vulnerabilities

Engineering Contradiction:
Improvedata access convenienceVSAvoidaccount security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts sensitive credential storage from applications and relocates it to a secure server environment. Applications no longer store login credentials locally; instead, authentication tokens are generated and managed securely on the server, eliminating the security vulnerability of local credential storage while maintaining convenient access through token-based authentication.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent replaces the mechanical credential storage system in applications with a server-based token authentication system. Instead of applications storing and managing passwords mechanically, the system uses server-generated authentication tokens that are transmitted securely, substituting the vulnerable local storage mechanism with a secure remote authentication infrastructure.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If frequent authentication is required for data access, then security control is improved, but network traffic increases due to repeated authentication requests

Engineering Contradiction:
Improvesecurity controlVSAvoidnetwork bandwidth
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent implements preliminary authentication where credentials are verified once during account setup or initial login. The authentication result is cached and reused for subsequent data access requests within the same session, eliminating the need for repeated authentication while maintaining security control. This preliminary action reduces network traffic from frequent authentication requests.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent establishes continuous authenticated sessions that maintain security control without requiring repeated authentication. Once authenticated, the system maintains a continuous secure connection that allows multiple data access operations without breaking the authentication state, ensuring continuous security monitoring while minimizing network overhead compared to discrete frequent authentication cycles.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS20260087490A1Server-to-device secure data exchange transactions
Publication Date: 2026.03.26 WELLS FARGO BANK NA
  • US20260087490A1 patent drawing
  • US20260087490A1 patent drawing
  • US20260087490A1 patent drawing

AI summary

Various embodiments described herein relate to systems, methods, and non-transitory computer-readable media structured to perform server-to-device secure data exchange using a device access token. A computing device can receive, from a native application, a transaction request associated with a device access token including a device identifier and a provider system identifier. The computing device can transmit the token and request to a computing system, which determines an account based on the provider identifier, verifies the request does not violate an account restriction, and generates an electronic message based on the account. The computing device can receive the electronic message from the computing system and provide a response to the transaction request to the native application based on the electronic message.