Token-Based Real-Time Risk Updating for Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security systems face inefficiencies in real-time risk updating and access control, as they often require processing numerous attributes individually, leading to slower and less efficient access decisions.

Innovation Solution

A token-based system that generates and updates risk tokens in real-time by detecting changes associated with user access, allowing for faster and more efficient risk assessments through the use of dataset tokens and recomputed risk tokens.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If security systems process numerous attributes individually for risk assessment, then access control decisions can be comprehensive, but the processing speed and efficiency deteriorate

Engineering Contradiction:
Improveaccess control decision accuracyVSAvoidrisk update speed
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent merges multiple individual attributes into a single risk token that encapsulates comprehensive risk information. Instead of processing attributes separately, the system combines user credentials, device information, network environment, and other factors into a unified risk token structure, enabling both comprehensive assessment and fast processing through token-based operations

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a simplified copy of the complex attribute set in the form of a risk token. This token serves as a condensed representation that captures the essential risk characteristics without requiring processing of all original attributes individually, thus maintaining decision accuracy while improving processing efficiency

Inventive Principle:
Principle #26Copying

2Reliability

If security systems perform comprehensive risk assessments by examining multiple factors, then access control reliability improves, but the time required for risk updates increases

Engineering Contradiction:
Improveaccess control reliabilityVSAvoidrisk update time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary action by pre-establishing risk tokens that encapsulate comprehensive risk assessments before actual access decisions are needed. These tokens are updated in advance when changes occur in user credentials, device status, or network conditions, so that when access is required, the comprehensive risk information is already ready, reducing real-time processing time while maintaining reliability

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where the system continuously monitors changes in risk factors and automatically updates risk tokens accordingly. This feedback loop ensures that risk assessments remain current and reliable without requiring time-consuming re-evaluations, as the system responds to changes by updating existing token structures rather than performing comprehensive reassessments from scratch

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9253197B2Method and apparatus for token-based real-time risk updating
Publication Date: 2016.02.02 BANK OF AMERICA CORP
  • US9253197B2 patent drawing
  • US9253197B2 patent drawing
  • US9253197B2 patent drawing

AI summary

According to one embodiment, an apparatus may store a plurality of tokens indicating a user is accessing a resource over a network. The plurality of tokens may include a risk token indicating a risk associated with access by the user to the resource. The apparatus may detect a token indicating a change associated with accessing the resource, and determine that the change triggers a risk update. The apparatus may then generate a dataset token that represents the risk token and the token indicating the change, and communicate the dataset token to a token provider to perform the risk update. The apparatus may then receive a recomputed risk token representing an updated risk. The updated risk may indicate the risk associated with continuing access to the resource with the change.