Unified Device Access Tokens for Secure Server-to-Device Data Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies face security vulnerabilities due to multiple authentication protocols for various applications on smart devices, leading to issues like code injection, user impersonation, and data interception, while also requiring frequent login credentials for data access, increasing network traffic.

Innovation Solution

Implementing a unified device access token system that enables secure server-to-device data exchange by authenticating smart devices and managing authenticated sessions, allowing direct communication with service providers without intermediaries, and minimizing data storage on the device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple authentication protocols are implemented for various applications on smart devices, then data access capability is improved, but security vulnerabilities increase

Engineering Contradiction:
Improvedata access capabilityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent consolidates multiple authentication protocols into a single unified authentication mechanism. The server implements one authentication protocol that handles multiple applications and data types, eliminating the need for separate authentication protocols for each application. This merging approach maintains data access capability across various applications while reducing security vulnerabilities associated with multiple protocols.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The authentication mechanism is designed to be universal, serving multiple applications and data access scenarios through a single protocol. The server's authentication system can authenticate requests from different applications, handle various data types, and manage multiple users through the same authentication framework, providing multi-functionality without requiring separate protocols for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If login credentials are frequently required for data access, then security control is improved, but network traffic increases

Engineering Contradiction:
Improvesecurity controlVSAvoidnetwork traffic
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The system performs authentication in advance and establishes a persistent authenticated session. Instead of requiring frequent login credentials for each data access request, the server authenticates the user once, creates a session token, and uses this token for subsequent data access operations. This preliminary authentication action maintains security control while significantly reducing network traffic associated with repeated credential transmissions.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authenticated session maintains continuous access rights for the duration of the session. Once authentication is complete, the session remains active and allows multiple data access operations without requiring re-authentication. This continuity of useful action ensures security control is maintained while eliminating the need for frequent network transactions involving login credentials.

Inventive Principle:
Principle #20Continuity of useful action

3Speed

If applications store credentials locally, then data access speed is improved, but account security is compromised

Engineering Contradiction:
Improvedata access speedVSAvoidaccount security
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent extracts sensitive credential information from the application's local storage and relocates it to the server's secure environment. Instead of applications storing login credentials locally on user devices, the system stores credentials only on the server. The application receives temporary access tokens that allow fast data access without requiring local storage of sensitive credentials, thus maintaining both data access speed and account security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system introduces an intermediary mechanism in the form of session tokens and access credentials managed by the server. Instead of applications directly using stored login credentials for data access, they use intermediate tokens that the server issues after authentication. These tokens enable fast local access operations while the server maintains control over actual credential security, preventing applications from having direct access to sensitive authentication data.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12380437B1Server-to-device secure data exchange transactions
Publication Date: 2025.08.05 WELLS FARGO BANK NA
  • US12380437B1 patent drawing
  • US12380437B1 patent drawing
  • US12380437B1 patent drawing

AI summary

Various embodiments described herein relate to systems, methods, and non-transitory computer-readable media structured to perform server-to-device secure data exchange using a device access token. In an embodiment, a smart device receives, from a requestor entity provided to the smart device, an account data provisioning request for an account. Based on the account data provisioning request, an account identifier for the account is determined. In some arrangements, the account identifier comprises or is associated with a device access token. Based on the device access token, a data element associated with the account is determined. In some embodiments, the data element is accessible to the requestor entity only if it is not access-restricted based on the device access token. Based on the data element, an executable graphic rendering instruction is generated. The executable graphic rendering instruction is executed, which includes generating and displaying, on a user interface of the smart device, a dynamic account status indicator relating to the account.