Unified Device Access Tokens for Secure Server-to-Device Data Exchange
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies face security vulnerabilities due to multiple authentication protocols for various applications on smart devices, leading to issues like code injection, user impersonation, and data interception, while also requiring frequent login credentials for data access, increasing network traffic.
Innovation Solution
Implementing a unified device access token system that enables secure server-to-device data exchange by authenticating smart devices and managing authenticated sessions, allowing direct communication with service providers without intermediaries, and minimizing data storage on the device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple authentication protocols are implemented for various applications on smart devices, then data access capability is improved, but security vulnerabilities increase
Solution Approach 1:
The patent consolidates multiple authentication protocols into a single unified authentication mechanism. The server implements one authentication protocol that handles multiple applications and data types, eliminating the need for separate authentication protocols for each application. This merging approach maintains data access capability across various applications while reducing security vulnerabilities associated with multiple protocols.
Solution Approach 2:
The authentication mechanism is designed to be universal, serving multiple applications and data access scenarios through a single protocol. The server's authentication system can authenticate requests from different applications, handle various data types, and manage multiple users through the same authentication framework, providing multi-functionality without requiring separate protocols for each function.
2Reliability
If login credentials are frequently required for data access, then security control is improved, but network traffic increases
Solution Approach 1:
The system performs authentication in advance and establishes a persistent authenticated session. Instead of requiring frequent login credentials for each data access request, the server authenticates the user once, creates a session token, and uses this token for subsequent data access operations. This preliminary authentication action maintains security control while significantly reducing network traffic associated with repeated credential transmissions.
Solution Approach 2:
The authenticated session maintains continuous access rights for the duration of the session. Once authentication is complete, the session remains active and allows multiple data access operations without requiring re-authentication. This continuity of useful action ensures security control is maintained while eliminating the need for frequent network transactions involving login credentials.
3Speed
If applications store credentials locally, then data access speed is improved, but account security is compromised
Solution Approach 1:
The patent extracts sensitive credential information from the application's local storage and relocates it to the server's secure environment. Instead of applications storing login credentials locally on user devices, the system stores credentials only on the server. The application receives temporary access tokens that allow fast data access without requiring local storage of sensitive credentials, thus maintaining both data access speed and account security.
Solution Approach 2:
The system introduces an intermediary mechanism in the form of session tokens and access credentials managed by the server. Instead of applications directly using stored login credentials for data access, they use intermediate tokens that the server issues after authentication. These tokens enable fast local access operations while the server maintains control over actual credential security, preventing applications from having direct access to sensitive authentication data.
Data Source
AI summary
Various embodiments described herein relate to systems, methods, and non-transitory computer-readable media structured to perform server-to-device secure data exchange using a device access token. In an embodiment, a smart device receives, from a requestor entity provided to the smart device, an account data provisioning request for an account. Based on the account data provisioning request, an account identifier for the account is determined. In some arrangements, the account identifier comprises or is associated with a device access token. Based on the device access token, a data element associated with the account is determined. In some embodiments, the data element is accessible to the requestor entity only if it is not access-restricted based on the device access token. Based on the data element, an executable graphic rendering instruction is generated. The executable graphic rendering instruction is executed, which includes generating and displaying, on a user interface of the smart device, a dynamic account status indicator relating to the account.


