Dynamic Token Generation with Format Matching Policies
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional tokenization techniques produce static tokens that do not match the format of input data and have inflexible detokenization processes, limiting their customization and usability across different systems.
Innovation Solution
A system for generating and managing data security tokens with customizable token generation and access policies, allowing tokens to be created based on specific data types and stored in a distributed token store, with flexible resolution and deletion processes controlled by token access policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional tokenization techniques are used, then data can be substituted with tokens for security purposes, but the tokens produce a static format that does not match the format of the input data
Solution Approach 1:
The patent implements dynamic token generation where the tokenization system adapts its output format based on the input data type and configured policies. Instead of producing static-format tokens, the system dynamically determines token formats that match the original data characteristics, allowing the same tokenization mechanism to produce different token formats for different data types while maintaining security.
Solution Approach 2:
The system changes the parameters of token generation by introducing configurable policies that define how tokens should be formatted for different data types. These policies allow adjustment of token length, format patterns, and other parameters to match the input data characteristics, transforming the rigid static format into a flexible parameter-driven format.
2Reliability
If conventional tokenization techniques are used, then data substitution can be performed, but the detokenization process is inflexible with static permissions for different system types
Solution Approach 1:
The patent implements dynamic access policies for detokenization that adapt based on the requesting system's characteristics, credentials, and the specific token being accessed. Instead of static permission sets, the system dynamically evaluates multiple factors including system identity, user roles, token metadata, and contextual information to determine whether detokenization should be permitted, enabling flexible yet secure access control.
Solution Approach 2:
The system changes the parameters of access control by introducing multiple configurable policy dimensions including system type, user role, token age, data sensitivity level, and purpose of access. These policy parameters allow the detokenization process to be controlled by a combination of factors rather than a single static permission setting, providing nuanced flexibility in access decisions.
3Adaptability or versatility
If custom token generation is implemented to match input data format, then token usability improves, but the system complexity increases
Solution Approach 1:
The patent implements a universal tokenization framework that handles multiple data types and format requirements through a single system. The configurable policies and standardized processing pipeline allow the same core tokenization engine to produce appropriate tokens for various input formats (text, numerical, structured data) without requiring separate customization for each data type, reducing overall system complexity while maintaining adaptability.
Solution Approach 2:
The system applies local quality by allowing format-specific processing rules to be defined only where needed within the general framework. Rather than requiring complete customization throughout the system, the patent enables localized configuration of format-matching parameters for specific data types while maintaining standardized processing elsewhere, balancing customization needs with system simplicity.
Data Source
AI summary
Token generation and management are disclosed, including: generating a token corresponding to a set of user data based at least in part on a token generation policy; storing a mapping between the token and the set of user data; and determining whether to grant a token resolution request associated with the token based at least in part on a token access policy associated with the token and a context parameter associated with the token resolution request.


