Device Access Token Exchange for Secure Account Data Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies face security vulnerabilities and inefficiencies in server-to-device data exchange due to multiple authentication protocols for various applications, leading to issues like code injection, user impersonation, and excessive network traffic.

Innovation Solution

Implementing a unified device access token system that enables secure, direct data exchange between smart devices and service providers, bypassing intermediate systems, and managing authenticated sessions on-demand to minimize processing overhead and network bandwidth.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple authentication protocols are implemented for various applications to access user data, then application functionality and data access capability are improved, but system security deteriorates due to vulnerabilities like code injection and user impersonation

Engineering Contradiction:
Improveapplication functionalityVSAvoidsystem security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements a universal authentication protocol that serves multiple applications and data access scenarios. Instead of having separate authentication protocols for each application, a single standardized protocol handles authentication for banking applications, financial analytics tools, loan applications, and other data access requests, thereby maintaining security consistency while supporting diverse functionalities

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary authentication mechanism that sits between the user credentials and the application data access. The authentication protocol acts as a mediator that verifies credentials, manages session tokens, and controls data access permissions without exposing the underlying security vulnerabilities to individual applications. This intermediary layer prevents direct access risks while enabling controlled data sharing

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If user credentials are stored by applications for data access, then data access speed and convenience are improved, but security deteriorates due to credential exposure and compromise risks

Engineering Contradiction:
Improvedata access convenienceVSAvoidcredential exposure risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the authentication and credential management functionality from the applications themselves and relocates it to a dedicated authentication protocol layer. Instead of applications storing and managing user credentials locally, the authentication protocol handles credential verification, session management, and token generation centrally, removing the security vulnerability of credential storage from applications while maintaining convenient data access

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent uses session tokens as secure copies that replace actual credentials during data access operations. Instead of applications storing or transmitting sensitive user credentials, the system creates temporary token copies that represent authenticated sessions. These tokens can be safely stored and reused for subsequent data access requests without exposing the original credentials, thereby maintaining convenience while eliminating credential exposure risks

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If traditional authentication systems are used with multiple protocols, then application-specific functionality is maintained, but network traffic and processing overhead increase excessively

Engineering Contradiction:
Improveapplication-specific functionalityVSAvoidnetwork bandwidth
Core Design Contradiction:
Adaptability or versatilityVSLoss of energy

Solution Approach 1:

The patent performs authentication actions in advance by establishing session tokens during an initial authentication phase. Once authenticated, the session token is cached and reused for subsequent data access requests within the same session, eliminating the need for repeated authentication handshakes and credential verification. This preliminary authentication action significantly reduces network traffic and processing overhead for multiple data access operations while maintaining application-specific functionality

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent merges multiple authentication operations into a single unified authentication session. Instead of executing separate authentication protocols for each data access request, the system combines authentication, session management, and data access authorization into one integrated flow. This merging eliminates redundant authentication traffic and processing steps while preserving the ability to access different applications and data types within the authenticated session

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12572928B1Server-to-device secure data exchange transactions
Publication Date: 2026.03.10 WELLS FARGO BANK NA
  • US12572928B1 patent drawing
  • US12572928B1 patent drawing
  • US12572928B1 patent drawing

AI summary

Various embodiments described herein relate to systems, methods, and non-transitory computer-readable media structured to perform server-to-device secure data exchange using a device access token. In an embodiment, a smart device receives, from a requestor entity provided to the smart device, an account data provisioning request for an account. Based on the account data provisioning request, an account identifier for the account is determined. In some arrangements, the account identifier comprises or is associated with a device access token. Based on the device access token, a data element associated with the account is determined. In some embodiments, the data element is accessible to the requestor entity only if it is not access-restricted based on the device access token. Based on the data element, an executable graphic rendering instruction is generated. The executable graphic rendering instruction is executed, which includes generating and displaying, on a user interface of the smart device, a dynamic account status indicator relating to the account.