Token Cancellation Timing for Unauthorized Transfer Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Unauthorized access to compromised tokens can lead to fraudulent transfer operations, allowing malicious actors to gain access to protected resources, and the creation of additional related tokens for further unauthorized activities.

Innovation Solution

A system generates a cancel request indicating the compromised token's compromise time, transmitting this to a token management service to deactivate the compromised token and related tokens, and prevents execution of unauthorized transfer operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a token is compromised and remains active, then existing systems continue to allow unauthorized transfer operations, but security is compromised and protected resources are at risk

Engineering Contradiction:
ImprovesecurityVSAvoidunauthorized access
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary action by automatically detecting token compromise and deactivating the token before unauthorized operations can succeed. The continuous monitoring and automatic deactivation mechanism acts in advance to prevent harmful effects, rather than reacting after unauthorized access occurs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback by continuously monitoring token usage patterns and automatically responding to suspicious activity. When compromise is detected, the system provides feedback by sending deactivation commands to the token management service, creating a closed-loop security mechanism that adapts to threats in real-time.

Inventive Principle:
Principle #23Feedback

2Ease of operation

If related tokens generated after compromise are not deactivated, then malicious actors can continue unauthorized operations, but maintaining token activity is needed for legitimate operations

Engineering Contradiction:
Improvelegitimate operationsVSAvoidfraudulent transfer operations
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system applies segmentation by distinguishing between related tokens generated before and after the compromise time. By segmenting the token lifecycle based on the compromise timestamp, the system can selectively deactivate only the harmful post-compromise tokens while preserving pre-compromise tokens that may still be legitimate.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes the temporal parameter of token validity by using the compromise time as a reference point. Tokens generated after this parameter change (compromise time) are automatically deactivated, while tokens generated before remain valid, allowing legitimate operations to continue uninterrupted.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If manual token deactivation is required, then security response time is delayed, but automated systems increase complexity

Engineering Contradiction:
Improvesecurity response timeVSAvoidautomated monitoring system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements self-service by enabling automated detection and deactivation of compromised tokens without requiring manual security administrator intervention. The monitoring system autonomously identifies compromise, determines the compromise time, and executes deactivation commands, making the security system self-managing and dramatically reducing response time.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary action by pre-configuring automated monitoring rules and deactivation protocols before compromise occurs. This preliminary setup allows the system to immediately respond to compromise events without requiring complex real-time decision-making, simplifying the operational complexity while maintaining rapid response.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12621156B2Preventing unauthorized resource access related to a compromised token
Publication Date: 2026.05.05 TRUIST BANK
  • US12621156B2 patent drawing
  • US12621156B2 patent drawing
  • US12621156B2 patent drawing

AI summary

A system can be used to prevent unauthorized resource access related to a compromised token. The system can generate a cancel request indicating that the compromised token has been compromised. The cancel request can include a time at which the compromised token was compromised. Additionally, the system can transmit the cancel request to a token management service to remove a related token associated with sensitive data corresponding to the compromised token. The related token can be generated subsequent to the time at which the compromised token was compromised. The system can determine that an unauthorized transfer operation was initiated using the compromised token or the related token. The system then can deny access to one or more protected resources by preventing an execution of the unauthorized transfer operation.