Token-Based Container Chaining for Secure Resource Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security systems face inefficiencies in determining whether a device is capable of consuming a resource, often requiring extensive attribute verification, which can be slow and cumbersome.

Innovation Solution

An apparatus intercepts requests to access a resource, using token-based rules to verify compliance criteria, generating a compliance token to facilitate provisioning of a container, thereby streamlining the access determination process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If extensive attribute verification is performed to determine device capability, then security and reliability are improved, but processing time and system complexity increase

Engineering Contradiction:
Improvedevice capability determination accuracyVSAvoidaccess determination time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the device capability verification process into distinct token-based components: a resource token representing the resource and a hard token representing the device. These segmented tokens can be independently verified against compliance criteria, enabling parallel processing and reducing overall verification time while maintaining comprehensive security checks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by pre-establishing compliance criteria and pre-generating tokens that encode device attributes and resource requirements. This allows the system to perform capability determination faster by matching pre-processed token information against compliance rules, rather than performing extensive attribute verification from scratch during each access request.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If comprehensive compliance verification is performed, then access security is improved, but system complexity and processing overhead increase

Engineering Contradiction:
Improveaccess control securityVSAvoidverification system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces tokens as intermediary objects that mediate between the device and resource. These tokens encapsulate complex compliance criteria and device attributes, allowing the verification system to work with simplified token representations rather than directly managing complex attribute verification logic. This reduces system complexity while maintaining comprehensive security checks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transforms the verification process by changing parameters from extensive attribute-by-attribute verification to token-based compliance checking. The system evaluates whether tokens match compliance criteria rather than verifying individual device attributes, significantly simplifying the verification system while maintaining comprehensive security.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If traditional attribute verification methods are used, then comprehensive device assessment is achieved, but processing efficiency and speed decrease

Engineering Contradiction:
Improvedevice capability assessment accuracyVSAvoidaccess determination throughput
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent creates simplified copies of device and resource information in the form of tokens. Instead of performing extensive verification on actual device attributes and resource specifications, the system works with token representations that capture essential compliance information. This copying approach maintains assessment accuracy while dramatically improving processing throughput.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent changes the fundamental parameter of verification from detailed attribute matching to token compliance evaluation. This parameter change enables the system to maintain precise device capability assessment by evaluating token compliance criteria, while achieving higher processing throughput through more efficient token-based comparison operations.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8566918B2Method and apparatus for token-based container chaining
Publication Date: 2013.10.22 BANK OF AMERICA CORP
  • US8566918B2 patent drawing
  • US8566918B2 patent drawing
  • US8566918B2 patent drawing

AI summary

According to one embodiment, an apparatus may intercept a request to access a resource represented by a resource token. The apparatus may receive a hard token representing identification information of a device. The apparatus may determine, based at least in part upon the hard token and the resource token, at least one token-based rule specifying compliance criteria required to consume the resource. The apparatus may receive at least one token representing compliance information of the device in response to a request for compliance information of the device. The apparatus may then compare the compliance information against the compliance criteria to determine that the device is capable of consuming the resource. The apparatus may then generate a compliance token representing the determination that the device is capable of consuming the resource, and communicate the compliance token to facilitate the provisioning of a container to the device.