Token-Based Access Control Integrity Determination

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security systems face inefficiencies in determining integrity levels and making access decisions due to the complexity of processing individual attributes, which can lead to slower and less accurate access control processes.

Innovation Solution

The system employs token-based rules and tokens that represent multiple attributes, allowing for faster and more efficient access decisions by associating access values with network tokens and determining integrity levels based on these tokens, thereby streamlining the access control process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If individual attributes are processed to determine integrity levels, then access control decisions can be made with detailed information, but the processing time increases and efficiency decreases

Engineering Contradiction:
Improveintegrity level determination accuracyVSAvoidaccess decision processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent combines multiple individual attributes into aggregated token representations. Instead of processing each attribute separately, the system merges attributes like user identity, device information, and network characteristics into consolidated tokens, which are then processed as unified units to determine integrity levels.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates simplified copies of complex attribute sets in the form of tokens. These token copies contain essential attribute information but in a condensed format that enables faster processing while preserving the necessary data for integrity level determination.

Inventive Principle:
Principle #26Copying

2Reliability

If multiple individual attributes are evaluated for access control, then more comprehensive security assessment is achieved, but the system complexity increases

Engineering Contradiction:
Improveaccess control security assessmentVSAvoidattribute processing system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the complex attribute processing system into distinct functional components: attribute collection modules, token generation modules, token processing modules, and decision-making modules. Each segment handles specific tasks, making the overall system more manageable and easier to implement while maintaining comprehensive security assessment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces tokens as intermediary representations between raw attributes and access control decisions. These tokens serve as mediators that simplify the interaction between multiple attributes and the decision-making process, reducing system complexity while preserving security assessment capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If detailed attribute processing is performed, then access decisions are more accurate, but processing speed decreases

Engineering Contradiction:
Improveaccess decision accuracyVSAvoidaccess decision processing speed
Core Design Contradiction:
Measurement precisionVSSpeed

Solution Approach 1:

The patent performs preliminary processing of attributes by converting them into tokens before the actual access decision is needed. This preliminary action of tokenization prepares the data in advance in a condensed format, enabling faster retrieval and processing during the critical access decision moment while maintaining accuracy.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8584202B2Apparatus and method for determining environment integrity levels
Publication Date: 2013.11.12 BANK OF AMERICA CORP
  • US8584202B2 patent drawing
  • US8584202B2 patent drawing
  • US8584202B2 patent drawing

AI summary

According to one embodiment, an apparatus may receive a resource token indicating that access to the resource has been requested. The apparatus may determine the value of an access value associated with at least one network token. The apparatus may then determine that the value of the access value is insufficient to grant access to the resource and determine that access to the resource over the network should be denied.