Token-Based Access Control System for Reducing Processing Time

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security systems face inefficiencies in making access decisions due to the need to process numerous attributes individually, which slows down the access control process and increases complexity.

Innovation Solution

A token-based system that stores and processes tokens representing multiple attributes, allowing for faster and more efficient access decisions by using token-based rules and exceptions to grant, deny, or condition access to resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If a security system processes numerous attributes individually to make access decisions, then the access control process becomes thorough and accurate, but the processing time increases and system complexity increases

Engineering Contradiction:
Improveaccess decision accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent combines multiple individual attributes into a single token that represents the user's access credentials. Instead of processing numerous attributes separately, the system merges them into one consolidated token that can be evaluated efficiently, thus reducing processing time while maintaining access decision accuracy.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The token serves multiple functions simultaneously: it identifies the user, represents their credentials, encapsulates access permissions, and enables rapid comparison against access rules. This multi-functionality eliminates the need to handle multiple separate attributes, improving both speed and accuracy of access decisions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If a security system processes numerous attributes individually to make access decisions, then the access control process becomes thorough and accurate, but the device complexity increases

Engineering Contradiction:
Improveaccess decision accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent merges multiple attributes into a single token structure, significantly simplifying the system architecture. Instead of managing numerous separate attribute data structures and their relationships, the system works with unified tokens, reducing memory requirements and computational complexity while preserving the informational content needed for accurate access decisions.

Inventive Principle:
Principle #5Merging (Combining)

3Productivity

If a token-based system condenses and abstracts attributes into tokens, then processing time decreases and efficiency increases, but the system may lose detailed attribute information

Engineering Contradiction:
Improveaccess decision speedVSAvoidattribute detail information
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The token acts as a comprehensive copy or representation of the user's credentials and attributes. It encapsulates all necessary attribute information in a structured format that preserves the essential details needed for access decisions, allowing rapid processing without losing critical information.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8572689B2Apparatus and method for making access decision using exceptions
Publication Date: 2013.10.29 BANK OF AMERICA CORP
  • US8572689B2 patent drawing
  • US8572689B2 patent drawing
  • US8572689B2 patent drawing

AI summary

According to one embodiment, an apparatus may store a plurality of token-based exceptions The apparatus may receive a resource token indicating that access to the resource has been requested. The apparatus may determine, based at least in part upon the resource token, at least one token-based exception. The token-based exception further may condition the grant of access to the resource upon the apparatus determining that the plurality of tokens comprises the at least one token. The apparatus may determine that the plurality of tokens does not comprise the at least one token and determine, in response to the determination that the plurality of tokens does not comprise the at least one token, that access to the resource should be denied.