Token-Based Access Control System for Network Resource Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security systems face inefficiencies in making access decisions due to the need to process and evaluate numerous individual attributes for access control, which can lead to slower and less efficient access management.

Innovation Solution

A token-based system that stores and processes token-based rules and tokens representing user and device attributes, allowing for the computation of risk tokens and the determination of access decisions based on these tokens, thereby facilitating faster and more efficient access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If individual attributes are processed and evaluated for access control, then access decisions can be made with detailed information, but the processing time and system complexity increase

Engineering Contradiction:
Improveaccess decision accuracyVSAvoidaccess decision time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent segments the access control process by introducing token-based rules that divide the evaluation of multiple attributes into discrete, pre-defined rule sets. Each token represents a specific attribute or combination of attributes, allowing the system to process access requests by evaluating tokens rather than individual attributes, thereby reducing processing time while maintaining decision accuracy

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies preliminary action by pre-computing and storing token-based rules that encapsulate access control logic before actual access decisions are needed. These rules are prepared in advance and can be quickly applied to access requests, eliminating the need to process individual attributes in real-time while preserving the ability to make accurate access decisions

Inventive Principle:
Principle #10Preliminary action

2Reliability

If multiple individual attributes are evaluated for each access request, then comprehensive access control is achieved, but the computational complexity and processing overhead increase

Engineering Contradiction:
Improveaccess control securityVSAvoidsystem processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple individual attributes into token-based representations that encapsulate combinations of attributes. By combining related attributes into single tokens and using token-based rules to evaluate these tokens, the system maintains comprehensive access control coverage while significantly reducing the computational complexity of processing multiple individual attributes for each access request

Inventive Principle:
Principle #5Merging (Combining)

3Measurement precision

If detailed attribute evaluation is performed, then accurate risk assessment is possible, but the processing time and computational resources increase

Engineering Contradiction:
Improverisk assessment accuracyVSAvoidaccess decision speed
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent creates simplified copies of attribute information in the form of tokens that represent underlying attributes without containing the full detail. These token copies enable rapid evaluation while preserving the essential information needed for accurate risk assessment, allowing the system to maintain productivity by working with lightweight token representations rather than processing detailed attribute data directly

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8789162B2Method and apparatus for making token-based access decisions
Publication Date: 2014.07.22 BANK OF AMERICA CORP
  • US8789162B2 patent drawing
  • US8789162B2 patent drawing
  • US8789162B2 patent drawing

AI summary

According to one embodiment, an apparatus may store a plurality of token-based rules that facilitate access to a resource, and a plurality of tokens indicating a user is using a device to request access to a resource over a network. The apparatus may receive a risk token indicating the risk associated with granting at least one of the user and the device access to the resource. The risk token may be computed from a set of tokens in the plurality of tokens. The apparatus may determine at least one token-based rule based at least in part upon the plurality of tokens and the risk token. The apparatus may then make an access decision based upon the at least one token-based rule, and communicate a decision token representing the access decision.