Task Token Security Mechanism for Distributed Computing Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computing systems face challenges in enhancing security, particularly in ensuring that only authorized users can access specific data within a data storage system, especially when tasks are executed across distributed computing resources.

Innovation Solution

Implementing a token-based system where a task-specific token associates a user with their task, ensuring the token's validity is tied to the task's lifespan rather than a fixed time, and using these tokens to enforce data access controls, allowing or denying access based on user permissions and task validity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a fixed-time token validity approach is used, then token management is simple, but security is weakened because tokens remain valid after task completion

Engineering Contradiction:
ImprovesecurityVSAvoidtoken management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The token validity period is made dynamic by tying it to the task lifespan rather than using a fixed time duration. The token becomes invalid automatically when the associated task completes, ensuring security without requiring complex manual management. This resolves the contradiction by making the security mechanism adaptive to task completion status.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements feedback by continuously monitoring task execution status and automatically adjusting token validity accordingly. When a task completes, the system detects this state change and invalidates the associated token, creating a closed-loop security mechanism that maintains reliability without excessive complexity.

Inventive Principle:
Principle #23Feedback

2Loss of information

If user identification is associated with every task execution, then audit capability is improved, but system complexity increases

Engineering Contradiction:
Improveaudit informationVSAvoidsystem complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent introduces a token as an intermediary that carries user identification information. Instead of directly embedding user ID in every task execution context, the token serves as a mediator that encapsulates authentication data and can be validated without exposing underlying system complexity. This enables audit trails while maintaining system simplicity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If data access control is enforced through tokens, then data protection is improved, but access operation complexity increases

Engineering Contradiction:
Improvedata protectionVSAvoiddata access operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

Authentication and token generation are performed in advance before data access operations. Users obtain tokens prior to task execution, and these tokens automatically enforce data access controls during operations. This preliminary authentication step simplifies actual data access operations while maintaining strong protection, as the heavy lifting of security verification occurs beforehand.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11201738B2Systems and methods for associating a user with a task executed in a computing system
Publication Date: 2021.12.14 SHOPIFY INC
  • US11201738B2 patent drawing
  • US11201738B2 patent drawing
  • US11201738B2 patent drawing

AI summary

It is desired to try to increase the security of a computing system running computer applications that may access data in a data storage system. In some embodiments, a token associates a user with a task that is being executed by a computing node. It may therefore be possible to determine which user executed which tasks. In some embodiments, the validity of a token is tied to the lifespan of a task associated with the token, rather than to a fixed amount of time. Therefore, if the task associated with the token is complete, the token may become invalid, rather than remaining valid for a duration of time that possibly exceeds the lifespan of the associated task. In some embodiments, a token is used to enforce data access control, e.g. to deny certain users access to certain data in the data storage system.