Tokenized Authentication Intermediary for Secure Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing information systems face challenges in ensuring the security and efficiency of user authentication while optimizing technical operations, particularly in preventing unauthorized access to secured resources.

Innovation Solution

Implementing tokenized authentication techniques through a computing platform that interacts with a social messaging server to validate user authentication tokens, ensuring secure access to user accounts by generating validation messages and step-up authentication prompts as needed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods are used to ensure security, then unauthorized access is prevented, but system complexity and operational inefficiency increase

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a tokenization service as an intermediary component that mediates between the client portal server and social messaging server. This service handles the complex token generation, validation, and authentication logic centrally, allowing the client portal server to maintain simplicity while achieving robust security through the intermediary's sophisticated authentication mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional authentication methods are used to ensure security, then unauthorized access is prevented, but operational efficiency decreases

Engineering Contradiction:
ImprovesecurityVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary authentication actions by generating validation tokens in advance through the tokenization service. When a user needs to access the client portal, the authentication status is already validated through the social messaging server, and the pre-generated token enables immediate access without requiring complex real-time authentication checks, thus improving operational efficiency while maintaining security.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If robust authentication mechanisms are implemented to prevent unauthorized access, then security is enhanced, but ease of operation is reduced

Engineering Contradiction:
ImprovesecurityVSAvoidease of access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent uses token copying where a validation token is generated that represents the user's authentication status. Instead of requiring users to repeatedly prove their identity through complex authentication mechanisms, the system creates and distributes valid tokens that users can present for access. This copying approach simplifies the user experience while maintaining strong security through the underlying token validation infrastructure.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10057249B2Preventing unauthorized access to secured information systems using tokenized authentication techniques
Publication Date: 2018.08.21 BANK OF AMERICA CORP
  • US10057249B2 patent drawing
  • US10057249B2 patent drawing
  • US10057249B2 patent drawing

AI summary

A computing platform may receive, from a client portal server, a request to authenticate a user to a user account associated with a client portal provided by the client portal server. Based on receiving the request to authenticate, the computing platform may send, to a social messaging server, an authentication token request message. Subsequently, the computing platform may receive, from the social messaging server, an authentication token. Thereafter, the computing platform may validate the authentication token received from the social messaging server. Based on validating the authentication token received from the social messaging server, the computing platform may generate a validation message directing the client portal server to provide the user with access to the user account. Subsequently, the computing platform may send, to the client portal server, the validation message directing the client portal server to provide the user with access to the user account.