Token-Based Network Session Validation Apparatus

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security systems face inefficiencies in network session validation, as they often require processing numerous individual attributes for access decisions, leading to slower and less efficient access control processes.

Innovation Solution

An apparatus that stores token-based rules and generates session tokens based on token combinations, including a second token indicating association with a virtual private network, to facilitate faster and more efficient network session validation by condensing attributes into tokens for quicker decision-making.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If individual attributes are processed for access decisions, then access control accuracy is maintained, but processing time increases and efficiency decreases

Engineering Contradiction:
Improveaccess control processing efficiencyVSAvoidsession validation time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent combines multiple individual attributes into consolidated tokens representing network session information. Instead of processing numerous separate attributes, the system merges them into unified token structures that can be validated more efficiently, directly addressing the efficiency-time tradeoff in network session validation.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If multiple tokens are validated for network session access, then security reliability is improved, but processing complexity increases

Engineering Contradiction:
Improvenetwork session validation securityVSAvoidtoken processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the network session validation process into distinct token types (first token for basic session information, second token for VPN association). This segmentation allows the system to validate multiple security criteria while maintaining manageable processing complexity through structured, modular token validation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces tokens as intermediary data structures between the network session and the validation logic. These tokens serve as mediators that encapsulate complex attribute information in standardized formats, simplifying the validation process while maintaining security requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8572724B2Method and apparatus for network session validation
Publication Date: 2013.10.29 BANK OF AMERICA CORP
  • US8572724B2 patent drawing
  • US8572724B2 patent drawing
  • US8572724B2 patent drawing

AI summary

According to one embodiment, an apparatus may store a plurality of token-based rules. A token-based rule facilitates access to a resource. The apparatus may further store a plurality of tokens. The apparatus may receive a first token indicating that access to the resource has been requested and determine at least one token-based rule based at least in part upon the first token. The at least one token-based rule may condition access to the resource upon a second token. The second token may indicate that the resource is associated with a virtual private network of the link layer of the open systems interconnection model. The apparatus may determine that the plurality of tokens includes the second token associated with the at least one token-based rule and generate a session token based at least in part upon the first token and the second token.