Dynamic Trust Cookie Authentication Against Stolen Token Replay

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises face challenges in balancing the deterrence of fraudulent attacks while enabling legitimate user access to gated content, resources, and services without excessive inconvenience, particularly due to the increasing prevalence of stolen cryptographic tokens and system-wide data breaches.

Innovation Solution

Implementing a cryptographic security credential system that alters tokens based on user interactions and stores them in a blockchain, tracking usage across multiple interactions to detect system-wide threats, and utilizing machine learning to identify malicious access patterns.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional static cryptographic tokens are used for user authentication, then legitimate users can access resources during the same session, but stolen credentials can be used by attackers to illegitimately access gated content and resources

Engineering Contradiction:
Improveauthentication securityVSAvoidstolen credential attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent transforms static cryptographic tokens into dynamic tokens that automatically change with each user interaction. The token is regenerated based on a formula incorporating the previous token value and current interaction context, making stolen tokens obsolete after a single use and preventing replay attacks

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements feedback by continuously monitoring token usage patterns and user interactions. Machine learning models analyze token behavior to detect anomalies and adjust security measures in real-time, creating a closed-loop system that adapts to emerging threats

Inventive Principle:
Principle #23Feedback

2Reliability

If enhanced security measures are implemented to detect fraudulent attacks, then system security is improved, but legitimate users experience excessive inconvenience

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoiduser access convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs self-service by automatically analyzing token usage patterns and detecting malicious activity without requiring manual security checks. Machine learning models autonomously evaluate each interaction and make real-time decisions about access authorization, eliminating the need for friction-heavy security verification steps for legitimate users

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent dynamically adjusts security parameters based on risk assessment. Low-risk legitimate interactions experience minimal friction, while high-risk patterns trigger enhanced verification. This adaptive approach maintains security while preserving user convenience for normal operations

Inventive Principle:
Principle #35Parameter changes

3Reliability

If cryptographic tokens are altered based on user interactions and tracked in blockchain, then stolen token effectiveness is reduced, but system complexity increases

Engineering Contradiction:
Improvetoken securityVSAvoidsecurity system architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a blockchain-based intermediary layer that mediates between token generation and verification processes. The blockchain stores and verifies token transformation histories, providing a decentralized trust mechanism that simplifies the overall system architecture by removing the need for complex centralized verification infrastructure

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system achieves multi-functionality by combining dynamic token generation, blockchain verification, and machine learning analysis into a unified security framework. This single system simultaneously provides authentication, fraud detection, and audit capabilities, reducing overall system complexity compared to separate specialized systems

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20260012345A1Trust cookie
Publication Date: 2026.01.08 WELLS FARGO BANK NA
  • US20260012345A1 patent drawing
  • US20260012345A1 patent drawing
  • US20260012345A1 patent drawing

AI summary

A system may receive a first cryptographic security credential stored on a user device, alter the first cryptographic security credential using a deterministic cryptographic function, and compare the altered first cryptographic security credential to a second cryptographic security credential stored in a block in a first data structure. A system may in response to a determination that the altered first cryptographic security credential matches the second cryptographic security credential: cause the altered first cryptographic security credential to be stored on the user device, generate a third cryptographic security credential by applying the deterministic cryptographic function to the second cryptographic security credential, store the third cryptographic security credential on a new block of the first data structure, and grant access to the resource based at least in part on the determination that the altered first cryptographic security credential matches the second cryptographic security credential.