Electronic Token System for Network Resource Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Internet protocols lack effective methods for controlling unauthorized access to network resources, leading to issues such as unwanted email and bandwidth usage, which existing software filters attempt to address through manual whitelisting but are cumbersome and inefficient.

Innovation Solution

An electronic token system that includes a token grantor identifier, a token grantee identifier, and a resource access control field, allowing for controlled access to network resources by specifying permissions and restrictions, which can be generated and transmitted to ensure only authorized access is granted.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual whitelisting is used to control access, then access control capability is improved, but ease of operation deteriorates due to manual adding of email addresses or domains

Engineering Contradiction:
Improveaccess control capabilityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary action by automatically generating and distributing tokens to senders before actual email delivery. This advance token distribution eliminates the need for manual whitelisting operations, as tokens are automatically issued to authorized senders based on user preferences set in advance.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary token system that mediates between the user and incoming emails. Instead of manually managing whitelist entries, the token acts as an automated intermediary that verifies sender authorization, thereby improving ease of operation while maintaining access control capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If no authentication is required for Internet protocols, then ease of operation is improved, but object-affected harmful factors worsen due to unwanted email and bandwidth usage

Engineering Contradiction:
Improveease of operationVSAvoidunwanted email and bandwidth usage
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system applies preliminary anti-action by preventing unwanted emails before they are generated or transmitted. Tokens are distributed in advance to authorized senders, and emails without valid tokens are automatically rejected, thereby eliminating harmful factors while maintaining ease of operation for legitimate communications.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent implements self-service by enabling the system to automatically manage access control without user intervention. The token distribution and verification process operates autonomously, eliminating the need for manual authentication while effectively blocking unwanted emails and reducing bandwidth usage.

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If existing software filters are used to block unwanted email, then object-affected harmful factors are reduced, but device complexity increases due to filter management requirements

Engineering Contradiction:
Improveunwanted emailVSAvoidfilter management complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent extracts the access control function from complex filter management systems and implements it through a simple token-based mechanism. By separating the authentication function into standalone tokens, the system reduces device complexity while effectively blocking unwanted emails.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system uses disposable tokens that are valid for specific purposes and time periods. These temporary, single-use tokens replace complex, persistent filter rules, thereby reducing device complexity while maintaining effective blocking of unwanted emails.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

4Reliability

If manual whitelisting is implemented at client or mail server, then access control capability is improved, but loss of time increases due to manual maintenance requirements

Engineering Contradiction:
Improveaccess control capabilityVSAvoidmanual maintenance time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements self-service by automatically generating, distributing, and managing tokens without user intervention. This eliminates the time-consuming manual maintenance of whitelists while maintaining access control capability, as the system autonomously handles token lifecycle management.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent applies preliminary action by pre-distributing tokens to authorized senders before they need to send emails. This advance preparation eliminates the need for ongoing manual whitelist maintenance, thereby reducing time loss while preserving access control capability.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7924709B2Access control of resources using tokens
Publication Date: 2011.04.12 HEWLETT PACKARD ENTERPRISE DEV LP
  • US7924709B2 patent drawing
  • US7924709B2 patent drawing
  • US7924709B2 patent drawing

AI summary

An electronic token useable for controlling access to a resource is described. The token includes a token grantor identifier indicating a token grantor, a token grantee identifier indicating a token grantee, and a resource access control field. The resource access control field indicates control of additional limitations of token grantee access to a resource as specified by the token grantor. A method for generating and using the electronic token includes generating an electronic token based on a token grantee identifier, a token grantor identifier, and a resource access control field, wherein the resource access control field indicates control of additional limitations of token grantee access to a resource as specified by the token grantor. The electronic token is transmitted to a token grantee computer system. The token grantee computer system transmits the electronic token to a computer system controlling access to a resource requested by the token grantee computer system.