Token Generation Algorithm with Domain Designator for Collision Avoidance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing token-based solutions face challenges in minimizing token collision, especially in multiple active domain environments, as they require centralized implementation and struggle to maintain a one-to-one relationship between tokens and sensitive data across geographically distant locations.

Innovation Solution

A method is implemented where a first data vault is established at a primary domain, with replicas at secondary domains, using a token generation algorithm that embeds a domain designator within the token, ensuring uniqueness and preventing collisions by generating tokens independent of sensitive data portions, thus allowing decentralized token management and collision avoidance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a centralized token implementation is used to minimize token collision, then token uniqueness is improved, but system complexity and geographical scalability worsen

Engineering Contradiction:
Improvetoken uniquenessVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides the centralized token management into multiple domain-specific data vaults distributed across different geographical locations. Each domain maintains its own data vault, segmenting the centralized system into independent yet coordinated units that can operate autonomously while preventing token collision through domain-specific token generation algorithms.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimension to token generation by incorporating a domain designator into the token structure. This additional dimensional component ensures that tokens generated in different domains remain unique even if the base token generation produces identical values, thereby maintaining uniqueness without requiring centralized control.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If a centralized data store is used to ensure one-to-one relationship between tokens and sensitive data, then data security is improved, but adaptability to multiple active domains worsens

Engineering Contradiction:
Improvedata securityVSAvoidmulti-domain adaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system segments the centralized data store into multiple domain-specific data vaults distributed across different geographical locations. Each domain maintains its own data vault, segmenting the centralized system into independent yet coordinated units that can operate autonomously while preventing token collision through domain-specific token generation algorithms.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements universality by enabling any domain to generate tokens for any other domain through the replication of data vaults. The token generation algorithm is designed to work universally across all domains, with each domain capable of creating tokens that are valid throughout the entire multi-domain system, thereby achieving both security and adaptability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If tokens are generated independently of sensitive data portions, then token collision is eliminated, but token generation complexity increases

Engineering Contradiction:
Improvetoken collision avoidanceVSAvoidtoken generation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides the centralized token management into multiple domain-specific data vaults distributed across different geographical locations. Each domain maintains its own data vault, segmenting the centralized system into independent yet coordinated units that can operate autonomously while preventing token collision through domain-specific token generation algorithms.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a domain designator as an intermediary element in the token generation process. This mediator component ensures that tokens generated in different domains remain unique even if the base token generation produces identical values, thereby maintaining uniqueness without requiring centralized control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8806204B2Systems and methods for maintaining data security across multiple active domains
Publication Date: 2014.08.12 OPEN TEXT HOLDINGS INC
  • US8806204B2 patent drawing
  • US8806204B2 patent drawing
  • US8806204B2 patent drawing

AI summary

Systems and methods for maintaining data security across multiple active domains are presented. Each domain includes a token generator that can generate tokens associated with sensitive data such as credit card numbers. The primary domain includes a centralized key manager. In one embodiment, each domain includes its own local data vault and a replica of each data vault associated with every remote domain. Any domain can access the data vaults (local and replica) and retrieve a token created by any other domain. The possibility of token collision is eliminated by a token generation algorithm that embeds a domain designator corresponding to the active domain where the token was created. When multiple tokens represent the same sensitive data, the token manager returns a set of all such tokens found in the data vaults.