Device Access Token Authentication for Secure Data Exchange
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies face security vulnerabilities due to multiple authentication protocols for various applications on smart devices, leading to issues like code injection, user impersonation, and data interception, while also requiring frequent login credentials for data access, increasing network traffic.
Innovation Solution
Implementing a unified device access token system that enables secure server-to-device data exchange by authenticating smart devices and applications directly with a service provider computing system, minimizing the need for repeated authentication and reducing data storage on the device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple authentication protocols are implemented for various applications, then application functionality and versatility are improved, but security vulnerabilities increase due to code injection, user impersonation, and data interception risks
Solution Approach 1:
The patent implements a universal authentication protocol that serves multiple applications and data access scenarios. A single protocol handles account data access, transaction initiation, and third-party application authorization, eliminating the need for multiple separate authentication mechanisms while maintaining security consistency across all functions.
Solution Approach 2:
The patent introduces an intermediary authentication mechanism that mediates between applications and account data. The authentication protocol acts as a secure intermediary layer that verifies requests without exposing sensitive credentials to applications, preventing code injection and data interception while enabling versatile application access.
2Ease of operation
If login credentials are stored by applications for data access, then ease of operation is improved, but security is compromised due to credential storage vulnerabilities
Solution Approach 1:
The patent extracts sensitive credential storage from applications and relocates it to a secure server environment. Applications no longer store login credentials locally; instead, authentication tokens are generated and managed securely on the server, eliminating the security vulnerability of local credential storage while maintaining convenient access through token-based authentication.
Solution Approach 2:
The patent replaces the mechanical credential storage system in applications with a server-based token authentication system. Instead of applications storing and managing passwords mechanically, the system uses server-generated authentication tokens that are transmitted securely, substituting the vulnerable local storage mechanism with a secure remote authentication infrastructure.
3Reliability
If frequent authentication is required for data access, then security control is improved, but network traffic increases due to repeated authentication requests
Solution Approach 1:
The patent implements preliminary authentication where credentials are verified once during account setup or initial login. The authentication result is cached and reused for subsequent data access requests within the same session, eliminating the need for repeated authentication while maintaining security control. This preliminary action reduces network traffic from frequent authentication requests.
Solution Approach 2:
The patent establishes continuous authenticated sessions that maintain security control without requiring repeated authentication. Once authenticated, the system maintains a continuous secure connection that allows multiple data access operations without breaking the authentication state, ensuring continuous security monitoring while minimizing network overhead compared to discrete frequent authentication cycles.
Data Source
AI summary
Various embodiments described herein relate to systems, methods, and non-transitory computer-readable media structured to perform server-to-device secure data exchange using a device access token. A computing device can receive, from a native application, a transaction request associated with a device access token including a device identifier and a provider system identifier. The computing device can transmit the token and request to a computing system, which determines an account based on the provider identifier, verifies the request does not violate an account restriction, and generates an electronic message based on the account. The computing device can receive the electronic message from the computing system and provide a response to the transaction request to the native application based on the electronic message.


