Device Access Token Exchange for Secure Account Data Provisioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies face security vulnerabilities and inefficiencies in server-to-device data exchange due to multiple authentication protocols for various applications, leading to issues like code injection, user impersonation, and excessive network traffic.
Innovation Solution
Implementing a unified device access token system that enables secure, direct data exchange between smart devices and service providers, bypassing intermediate systems, and managing authenticated sessions on-demand to minimize processing overhead and network bandwidth.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple authentication protocols are implemented for various applications to access user data, then application functionality and data access capability are improved, but system security deteriorates due to vulnerabilities like code injection and user impersonation
Solution Approach 1:
The patent implements a universal authentication protocol that serves multiple applications and data access scenarios. Instead of having separate authentication protocols for each application, a single standardized protocol handles authentication for banking applications, financial analytics tools, loan applications, and other data access requests, thereby maintaining security consistency while supporting diverse functionalities
Solution Approach 2:
The patent introduces an intermediary authentication mechanism that sits between the user credentials and the application data access. The authentication protocol acts as a mediator that verifies credentials, manages session tokens, and controls data access permissions without exposing the underlying security vulnerabilities to individual applications. This intermediary layer prevents direct access risks while enabling controlled data sharing
2Ease of operation
If user credentials are stored by applications for data access, then data access speed and convenience are improved, but security deteriorates due to credential exposure and compromise risks
Solution Approach 1:
The patent extracts the authentication and credential management functionality from the applications themselves and relocates it to a dedicated authentication protocol layer. Instead of applications storing and managing user credentials locally, the authentication protocol handles credential verification, session management, and token generation centrally, removing the security vulnerability of credential storage from applications while maintaining convenient data access
Solution Approach 2:
The patent uses session tokens as secure copies that replace actual credentials during data access operations. Instead of applications storing or transmitting sensitive user credentials, the system creates temporary token copies that represent authenticated sessions. These tokens can be safely stored and reused for subsequent data access requests without exposing the original credentials, thereby maintaining convenience while eliminating credential exposure risks
3Adaptability or versatility
If traditional authentication systems are used with multiple protocols, then application-specific functionality is maintained, but network traffic and processing overhead increase excessively
Solution Approach 1:
The patent performs authentication actions in advance by establishing session tokens during an initial authentication phase. Once authenticated, the session token is cached and reused for subsequent data access requests within the same session, eliminating the need for repeated authentication handshakes and credential verification. This preliminary authentication action significantly reduces network traffic and processing overhead for multiple data access operations while maintaining application-specific functionality
Solution Approach 2:
The patent merges multiple authentication operations into a single unified authentication session. Instead of executing separate authentication protocols for each data access request, the system combines authentication, session management, and data access authorization into one integrated flow. This merging eliminates redundant authentication traffic and processing steps while preserving the ability to access different applications and data types within the authenticated session
Data Source
AI summary
Various embodiments described herein relate to systems, methods, and non-transitory computer-readable media structured to perform server-to-device secure data exchange using a device access token. In an embodiment, a smart device receives, from a requestor entity provided to the smart device, an account data provisioning request for an account. Based on the account data provisioning request, an account identifier for the account is determined. In some arrangements, the account identifier comprises or is associated with a device access token. Based on the device access token, a data element associated with the account is determined. In some embodiments, the data element is accessible to the requestor entity only if it is not access-restricted based on the device access token. Based on the data element, an executable graphic rendering instruction is generated. The executable graphic rendering instruction is executed, which includes generating and displaying, on a user interface of the smart device, a dynamic account status indicator relating to the account.


