Item-Restricted Token Binding for Shared-Device Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional content aggregation platforms lack effective mechanisms to restrict access to resources or services on shared user devices, leading to security concerns and poor user experiences when multiple users share a device, as users may inadvertently access sensitive information or malicious content.

Innovation Solution

Implementing restricted access tokens that bind to specific items or entities, allowing access only to those items or entities, and validating actions based on URL data to ensure security and control access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional access tokens are issued to enable access to resources on a shared user device, then multiple users can access services and content, but security is compromised as users may access sensitive information or malicious content they should not access

Engineering Contradiction:
Improveaccess convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the access token into a primary token and one or more secondary tokens. Each secondary token is associated with specific items or entities and has restricted access permissions. This segmentation allows different users to have different levels of access to different resources, resolving the contradiction between ease of access and security by enabling fine-grained access control.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by assigning different access permissions to different secondary tokens based on their association with specific items or entities. Each secondary token has localized access rights rather than universal access, allowing users to access only the specific resources they are authorized for, thereby maintaining security while enabling convenient access to permitted resources.

Inventive Principle:
Principle #3Local quality

2Reliability

If passwords or secrets are used to restrict access to resources, then security is improved, but users can still learn these passwords and circumvent the security mechanism

Engineering Contradiction:
ImprovesecurityVSAvoidsecurity effectiveness
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces secondary tokens as intermediaries between users and resources. Instead of relying on passwords that users can learn and share, the system uses token-based authentication where the secondary tokens automatically enforce access restrictions. This intermediary mechanism eliminates the need for users to memorize or share passwords, providing more reliable and adaptable security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical password-based security system with a token-based authentication system. The secondary tokens automatically manage access control through programmatic validation of item associations, eliminating the weaknesses of password-based systems where users can learn or share credentials. This substitution provides more robust and adaptable security enforcement.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Ease of operation

If a user device is shared among multiple users with full access tokens, then all users can access all services, but sensitive information and malicious content become accessible to unauthorized users

Engineering Contradiction:
Improvedevice sharing capabilityVSAvoidunauthorized access to sensitive information
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments access permissions by creating secondary tokens that are each associated with specific items or entities. When a user device is shared, each user receives secondary tokens that limit their access to only the resources they are authorized to use. This segmentation prevents unauthorized access to sensitive information while maintaining the ability to share the device among multiple users.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by giving each secondary token specific access permissions tied to particular items or entities rather than providing universal access. This ensures that even when a device is shared, users can only access the specific resources their tokens permit, preventing exposure to sensitive information and malicious content they should not access.

Inventive Principle:
Principle #3Local quality

4Reliability

If restricted access tokens are implemented with item binding, then security is enhanced by limiting access to specific items, but device complexity increases due to token validation and URL data verification

Engineering Contradiction:
Improveaccess control securityVSAvoidtoken validation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal validation mechanism that handles multiple security functions through a single process. The secondary token validation system simultaneously verifies token authenticity, checks item associations, validates URL data, and enforces access permissions all in one unified process. This multi-functionality reduces the apparent complexity by consolidating multiple security checks into a single coherent validation framework.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent incorporates feedback mechanisms where the system validates URL data and item associations and uses this information to dynamically control access. The validation process provides feedback about whether access should be granted or denied based on the secondary token's item associations and the current request context. This feedback-driven approach streamlines the validation process by making decisions based on real-time verification rather than complex pre-configured rules.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12375279B2Item-access-based activation of an item set for an item-restricted token associated with a primary token
Publication Date: 2025.07.29 CAPITAL ONE SERVICES LLC
  • US12375279B2 patent drawing
  • US12375279B2 patent drawing
  • US12375279B2 patent drawing

AI summary

In some embodiments, an item-restricted access token may be bound to one or more items. In some embodiments, a first item that is accessible via a first website accessed by a user may be detected. Based on the detection and an authentication of a user, an item-restricted access token may be activated for accessing an item that corresponds to the first item. After the activation of the item-restricted token, a request may be obtained for an action related to a candidate item. The action related to the candidate item may be validated based on the item-restricted access token, where the validation indicates that the action related to the candidate item is valid based on a determination that the candidate item corresponds to the first item.