Server-to-Device Data Exchange Using Device Access Tokens

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies face security vulnerabilities due to multiple authentication protocols for various applications on smart devices, leading to issues like code injection, user impersonation, and data interception, while also requiring frequent login credentials for data access, increasing network traffic and processing overhead.

Innovation Solution

Implementing a unified device access token system that enables secure server-to-device data exchange by authenticating smart devices and applications through a single protocol, allowing direct data provisioning without intermediaries and minimizing authentication frequency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple authentication protocols are implemented for various applications on smart devices, then application functionality and adaptability are improved, but security vulnerabilities increase due to code injection, user impersonation, and data interception risks

Engineering Contradiction:
Improveapplication functionalityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements a universal authentication protocol where the smart device itself is authenticated once to access multiple applications and services. The device authentication token serves multiple functions across different applications, eliminating the need for separate authentication protocols for each application while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary authentication mechanism where the smart device acts as a trusted intermediary between the user and multiple applications. Instead of applications directly authenticating users through multiple protocols, the device itself is authenticated and then mediates access to various applications, reducing security vulnerabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If login credentials are frequently required for data access by applications, then data security control is improved, but network traffic and processing overhead increase

Engineering Contradiction:
Improvedata security controlVSAvoidnetwork traffic and processing overhead
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent performs authentication in advance by authenticating the smart device itself before applications need to access data. The device authentication token is obtained beforehand and stored securely, allowing applications to access data without requiring frequent re-authentication, thus reducing network traffic and processing overhead while maintaining security control.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The smart device performs self-authentication with the server to obtain its own authentication token, eliminating the need for continuous user credential verification. The device manages its own authentication state and uses the obtained token to facilitate data access for applications, reducing the burden of frequent authentication.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If applications store user credentials locally, then ease of operation is improved by enabling quick access, but security is compromised due to potential credential exposure

Engineering Contradiction:
Improvequick accessVSAvoidcredential exposure
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts user credentials from the application layer and stores them securely in the smart device's secure storage, separate from application data. Applications do not directly store or handle sensitive credentials; instead, they request data access through the authenticated device, which retrieves information using securely stored authentication tokens.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The smart device acts as an intermediary between applications and user credentials. Instead of applications directly storing and using credentials, the device securely stores authentication tokens and mediates all data access requests, preventing credential exposure while enabling quick access through the device's authentication mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12518271B1Server-to-device secure data exchange transactions
Publication Date: 2026.01.06 WELLS FARGO BANK NA
  • US12518271B1 patent drawing
  • US12518271B1 patent drawing
  • US12518271B1 patent drawing

AI summary

Various embodiments described herein relate to systems, methods, and non-transitory computer-readable media structured to perform server-to-device secure data exchange using a device access token. In an embodiment, a smart device receives, from a requestor entity provided to the smart device, an account data provisioning request for an account. Based on the account data provisioning request, an account identifier for the account is determined. In some arrangements, the account identifier comprises or is associated with a device access token. Based on the device access token, a data element associated with the account is determined. In some embodiments, the data element is accessible to the requestor entity only if it is not access-restricted based on the device access token. Based on the data element, an executable graphic rendering instruction is generated. The executable graphic rendering instruction is executed, which includes generating and displaying, on a user interface of the smart device, a dynamic account status indicator relating to the account.