Token-Based Session Termination for Unauthorized Access Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security systems face inefficiencies in detecting and responding to unauthorized access attempts, particularly in managing token-based access decisions, which can lead to delayed or inadequate responses to potential security threats.

Innovation Solution

An apparatus that stores token-based rules and tokens, including session tokens, to detect unauthorized access attempts and terminate sessions promptly by applying token-based rules to determine when access should be terminated, facilitating faster and more efficient responses to unauthorized users.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security systems are used to detect unauthorized access attempts, then comprehensive security checking can be performed, but the response time is delayed and efficiency is reduced

Engineering Contradiction:
Improvesecurity detection accuracyVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-configuring token-based rules and storing multiple token types (session tokens, biometric tokens, device tokens) before unauthorized access occurs. When access attempts are detected, the pre-established token framework enables immediate validation and termination decisions without requiring complex real-time analysis, thus resolving the contradiction between comprehensive security checking and fast response time

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces traditional mechanical security verification systems with a token-based automated decision system. Instead of relying on slow, manual security protocols, the system uses electronically stored tokens and rule-based automated logic to instantly validate access attempts and terminate sessions when unauthorized access is detected, significantly reducing response time while maintaining security reliability

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If session tokens are maintained for extended periods, then user convenience is improved, but the risk of unauthorized access increases

Engineering Contradiction:
Improveuser convenienceVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system applies dynamics by making session token validity conditional rather than static. Session tokens are configured with expiration times and can be dynamically terminated based on rule-based conditions (such as detecting unauthorized devices or biometric mismatches). This dynamic approach allows tokens to remain valid long enough for legitimate user convenience while automatically becoming invalid when security conditions change, thus resolving the contradiction between extended session duration and unauthorized access risk

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements feedback mechanisms where security conditions are continuously monitored and fed back into token validation decisions. When conditions change (such as detection of unauthorized access attempts or device changes), the feedback triggers automatic session termination regardless of the original token expiration time. This feedback loop maintains user convenience for legitimate sessions while rapidly responding to security threats, resolving the contradiction between session duration and security risk

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8850515B2Method and apparatus for subject recognition session validation
Publication Date: 2014.09.30 BANK OF AMERICA CORP
  • US8850515B2 patent drawing
  • US8850515B2 patent drawing
  • US8850515B2 patent drawing

AI summary

According to one embodiment, an apparatus may store a plurality of token-based rules. A token-based rule may facilitate access to a resource. The apparatus may further store a plurality of tokens. The plurality of tokens may include a session token associated with access to the resource by a user. The apparatus may receive a first token indicating at least one of the detection of a face other than the user's and the detection of a voice other than the user's. The apparatus may determine, based at least in part upon at least one token-based rule from the plurality of token-based rules, that access to the resource should be terminated in response to receiving the first token and terminate the session token in response to the determination that access to the resource should be terminated.