Domain Specific Tokens for Multi-Enterprise Authorization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing methods for generating virtual tokens are inefficient, leading to a finite number of tokens being exhausted quickly, as they are generated on a one-to-one basis with the information they represent, limiting their scalability and availability.
Innovation Solution
A computing platform generates domain-specific tokens, each corresponding to a card number and having an approved users list, allowing for the modification and management of these lists to authorize multiple enterprises to use a single token, thereby reducing the number of tokens needed.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If virtual tokens are generated on a one-to-one basis with card information, then each card number has a dedicated token for security representation, but the finite number of available tokens is exhausted quickly
Solution Approach 1:
The patent implements multi-functionality by allowing a single virtual token to represent multiple card information sets from different enterprises. The tokenization system enables one token to be associated with multiple primary account numbers (PANs) through the approved users list mechanism, thereby reducing the total number of tokens needed while maintaining security representation for each card.
Solution Approach 2:
The patent merges multiple token-card mappings into a single token that can represent multiple cards. By combining the authentication and authorization functions into a unified token structure with an approved users list, the system consolidates what would traditionally require multiple separate tokens into one shared resource.
2Productivity
If multiple enterprises are authorized to use a single domain specific token, then token efficiency is enhanced and token depletion is delayed, but the complexity of managing approved users lists increases
Solution Approach 1:
The patent introduces an intermediary token management system that handles the complexity of user list management. The computing platform acts as a mediator between enterprises and tokens, automatically managing the approved users lists and handling the authorization logic, thereby shielding the complexity from the end users while enabling efficient token sharing.
Solution Approach 2:
The approved users list mechanism enables a single token to serve multiple enterprises and multiple card information sets. This universal token design allows one token to perform multiple functions: representing different cards, authorizing different enterprises, and maintaining security across multiple contexts, thereby improving productivity while the system manages the inherent complexity.
3Quantity of substance
If domain specific tokens are generated for multiple card information sets, then the number of tokens needed is reduced, but the validation process for event processing requests becomes more complex
Solution Approach 1:
The patent implements a feedback mechanism in the validation process where the computing platform checks whether the presenting enterprise is authorized to use the token by consulting the approved users list. This feedback loop automatically determines validity and can revoke access if needed, managing the complexity through automated decision-making rather than manual validation processes.
Data Source
AI summary
Aspects of the disclosure relate to virtual tokens. A computing platform may generate a domain specific token, corresponding to a card number and having an approved users list. The computing platform may receive, from a first enterprise device corresponding to a first enterprise, card information of a card. The computing platform may identify that tokenization of the card information is approved by a second enterprise corresponding to the card. Based on identifying that the tokenization is approved, the computing platform may modify the approved users list to include the first enterprise. The computing platform may send, to the first enterprise device, the first domain specific token, where the computing platform is configured to validate an event processing request based on receipt of the first domain specific token from the first enterprise device.


