Security Token Embedding Initialization Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing process of establishing secure communications between a local computing device and a remote server is slow due to the need for repeated authentication and separate requests for data after receiving a security token, which delays the exchange of useful data.

Innovation Solution

Embedding initialization data and user preferences within the security token returned during the initial authentication process, allowing the local device to access data without additional requests, thus streamlining the communication setup.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of time

If a standard security token is returned during authentication, then security is maintained, but additional data requests are required which increase communication time

Engineering Contradiction:
Improvecommunication setup timeVSAvoidtoken structure complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The patent combines multiple data elements (user preferences, initialization data, configuration information) with the security token into a single integrated data structure. This merging eliminates the need for separate data requests after authentication, directly reducing communication setup time while the structured organization maintains manageable complexity

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The enhanced security token serves multiple functions simultaneously: it provides authentication credentials, contains user preferences, stores initialization data, and delivers configuration information. This multi-functionality allows the single token to replace what would otherwise require multiple separate communications, reducing overall setup time

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Productivity

If useable data is embedded in the security token, then subsequent data requests are eliminated, but the token size and processing complexity increase

Engineering Contradiction:
Improvedata exchange efficiencyVSAvoidtoken processing complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the embedded data into distinct categories (user preferences, initialization data, configuration information) with clear structural organization. This segmentation allows the system to efficiently process and extract only the specific data elements needed, rather than handling a monolithic data structure, thus improving data exchange efficiency while controlling processing complexity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary action by pre-packaging all necessary data (user preferences, initialization data, configuration information) into the security token during the authentication phase. This advance preparation eliminates the need for subsequent data requests and processing steps, significantly improving productivity despite the increased initial token complexity

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9838387B2Security token with embedded data
Publication Date: 2017.12.05 THE DESCARTES SYST GROUP
  • US9838387B2 patent drawing
  • US9838387B2 patent drawing
  • US9838387B2 patent drawing

AI summary

A system and method are presented that provide authentication tokens to a local device from a remote server. The authentication token incorporates standard token content, and also includes additional token components that are needed by the local device. The additional token components incorporate user preferences information, initialization data, or other useable information needed by the local device. In contrast to standard processes, which must return a security token to the local device before any useful data can be exchanged, the disclosed embodiment inserts useable data into the returned token and eliminates the time required to obtain this data through a separate data request.