Restricted Access Token Validation via URL Snapshot Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems struggle to effectively restrict access to resources, services, or items on shared user devices, leading to potential security breaches and poor user experience.

Innovation Solution

Implementing restricted access tokens that bind specific items or entities, allowing subsequent use only for actions related to those bound items, and validating network operations based on URL data to ensure authorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional access tokens are issued to allow broad resource access, then user convenience and access efficiency are improved, but security and control over sensitive information deteriorate

Engineering Contradiction:
Improveaccess convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the broad access token into multiple restricted access tokens, each tied to specific entities or resources. This allows the system to maintain convenience for authorized access while improving security by limiting each token's scope to only what is necessary for specific tasks, preventing unauthorized access to sensitive information.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by creating tokens with different restriction levels and scopes tailored to specific entities, resources, or time periods. Each restricted access token has customized permissions matching the user's needs for particular resources while maintaining security for sensitive areas, allowing differentiated access control across different parts of the system.

Inventive Principle:
Principle #3Local quality

2Reliability

If passwords are used to restrict access to resources, then security is improved, but ease of operation deteriorates due to password management complexity

Engineering Contradiction:
ImprovesecurityVSAvoidpassword management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces the mechanical password-based authentication system with a digital restricted access token system. Instead of managing multiple passwords manually, users receive automated tokens with embedded permissions that are validated by the system, eliminating the need for users to remember and manage complex password hierarchies while maintaining strong security controls.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system automatically generates, distributes, and manages restricted access tokens without requiring manual password configuration by users. The tokens are issued programmatically with predefined restrictions, and the system automatically validates them against entity permissions, reducing operational complexity while maintaining security.

Inventive Principle:
Principle #25Self-service

3Reliability

If restricted access tokens with entity binding are implemented, then security and fraud prevention are improved, but device complexity increases

Engineering Contradiction:
Improvefraud preventionVSAvoidtoken validation system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-binding tokens to specific entities, resources, and time periods before use. This pre-configuration of restrictions and permissions eliminates the need for complex real-time decision-making during validation, as the system only needs to check whether the token's predefined constraints are satisfied, simplifying the validation process while maintaining strong fraud prevention.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces restricted access tokens as intermediaries between users and resources. These tokens act as mediators that encapsulate complex permission logic and entity bindings, allowing the system to enforce security policies without requiring complex validation algorithms to run during each access attempt. The tokens themselves carry the restriction logic, simplifying the validation mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12332981B2Validation of a network operation related to use of a token via token-request-triggered storage of snapshot URL data
Publication Date: 2025.06.17 CAPITAL ONE SERVICES LLC
  • US12332981B2 patent drawing
  • US12332981B2 patent drawing
  • US12332981B2 patent drawing

AI summary

In some embodiments, validation of a network operation based on screenshot-derived uniform resource locator (URL) data may be facilitated. In some embodiments, in connection with use by a user of a first token associated with a first entity, user activity data associated with the user may be stored in a database in association with the first token. In some embodiments, the first user activity data may comprise first URL data and first timestamps associated with the first URL data. After the storage of the first user activity data, a first action request for a first action involving use of the first token may be obtained. A validation process may be performed on the first action by performing a first query of the database for user activity data based on the first action request.