IP Library Granted Patent US 12,615,152
Granted Patent B2
US 12,615,152 · App. 18/637,517 · Granted Apr 28, 2026

Preventing unauthorized resource access related to a compromised token

Inventor: Jason B. Cohoon (Sparta, TN)
Assignee: Truist Bank
H04L9/3213G06F21/1014G06F21/62
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,615,152
App. No.
18/637,517
Granted
Apr 28, 2026
Kind
B2
Abstract

A system can be used to prevent unauthorized resource access related to a compromised token. The system can receive a cancel request indicating that the compromised token has been compromised. The cancel request can include a time at which the compromised token was compromised. Additionally, the system can remove a related token associated with sensitive data corresponding to the compromised token. The related token can be generated subsequent to the time at which the compromised token was compromised. The system can output a response to an operation processing system to indicate when the related token was last used to deny access to one or more protected resources by preventing an execution of an unauthorized transfer operation. The operation processing system can identify the unauthorized transfer operation based on the response.

Claims (31)

1 . A system comprising:

a processor; and

a memory including instructions that are executable by the processor for causing the processor to perform operations comprising:

receiving, by a token management service, a cancel request indicating that a token has been compromised, the cancel request including a time at which the compromised token was compromised;

removing, by the token management service, a related token associated with sensitive data corresponding to the compromised token, the related token being generated subsequent to the time at which the compromised token was compromised; and

outputting, by the token management service, a response indicating when the related token was last used to deny access to one or more protected resources by preventing an execution of an unauthorized transfer operation, wherein the unauthorized transfer operation is identifiable based on the response.

2 . The system of claim 1 , wherein removing the related token comprises adjusting, by the token management service, a token status corresponding to the related token based on the cancel request.

3 . The system of claim 1 , wherein the execution of the unauthorized transfer operation is prevented based on detecting that the unauthorized transfer operation was initiated using the compromised token or the related token.

4 . The system of claim 3 , wherein preventing the execution of the unauthorized transfer operation further comprises removing the unauthorized transfer operation from a processing queue to prevent the unauthorized transfer operation from being executed.

5 . The system of claim 1 , wherein the cancel request is generated to remove the related token that is generated subsequent to the time included in the cancel request, and wherein the cancel request is generated in response to receiving user input from an entity at a user interface outputted for display to the entity.

6 . The system of claim 1 , wherein the time at which the token was compromised is provided to the token management service as a time range based on an estimated value.

7 . The system of claim 1 , wherein the compromised token is a virtual token associated with a software application installed on a mobile device to initiate one or more transfer operations using the mobile device.

8 . A computer-implemented method comprising:

receiving, by a token management service, a cancel request indicating that a token has been compromised, the cancel request including a time at which the compromised token was compromised;

removing, by the token management service, a related token associated with sensitive data corresponding to the compromised token, the related token being generated subsequent to the time at which the compromised token was compromised; and

outputting, by the token management service, a response indicating when the related token was last used to deny access to one or more protected resources by preventing an execution of an unauthorized transfer operation, wherein the unauthorized transfer operation is identifiable based on the response.

9 . The computer-implemented method of claim 8 , wherein removing the related token comprises adjusting, by the token management service, a token status corresponding to the related token based on the cancel request.

10 . The computer-implemented method of claim 8 , wherein the execution of the unauthorized transfer operation is prevented based on detecting that the unauthorized transfer operation was initiated using the compromised token or the related token.

11 . The computer-implemented method of claim 10 , wherein preventing the execution of the unauthorized transfer operation further comprises removing the unauthorized transfer operation from a processing queue to prevent the unauthorized transfer operation from being executed.

12 . The computer-implemented method of claim 8 , wherein the cancel request is generated to remove the related token that is generated subsequent to the time included in the cancel request, and wherein the cancel request is generated in response to receiving user input from an entity at a user interface outputted for display to the entity.

13 . The computer-implemented method of claim 8 , wherein the time at which the token was compromised is provided to the token management service as a time range based on an estimated value.

14 . The computer-implemented method of claim 8 , wherein the compromised token is a virtual token associated with a software application installed on a mobile device to initiate one or more transfer operations using the mobile device.

15 . A non-transitory computer-readable medium comprising program code executable by a processor for causing the processor to perform operations comprising:

receiving, by a token management service, a cancel request indicating that a token has been compromised, the cancel request including a time at which the compromised token was compromised;

removing, by the token management service, a related token associated with sensitive data corresponding to the compromised token, the related token being generated subsequent to the time at which the compromised token was compromised; and

outputting, by the token management service, a response indicating when the related token was last used to deny access to one or more protected resources by preventing an execution of an unauthorized transfer operation, wherein the unauthorized transfer operation is identifiable based on the response.

16 . The non-transitory computer-readable medium of claim 15 , wherein removing the related token comprises adjusting, by the token management service, a token status corresponding to the related token based on the cancel request.

17 . The non-transitory computer-readable medium of claim 15 , wherein the execution of the unauthorized transfer operation is prevented based on detecting that the unauthorized transfer operation was initiated using the compromised token or the related token.

18 . The non-transitory computer-readable medium of claim 17 , wherein preventing the execution of the unauthorized transfer operation further comprises removing the unauthorized transfer operation from a processing queue to prevent the unauthorized transfer operation from being executed.

19 . The non-transitory computer-readable medium of claim 15 , wherein the cancel request is generated to remove the related token that is generated subsequent to the time included in the cancel request, and wherein the cancel request is generated in response to receiving user input from an entity at a user interface outputted for display to the entity.

20 . The non-transitory computer-readable medium of claim 15 , wherein the time at which the token was compromised is provided to the token management service as a time range based on an estimated value.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 17, 2024
From: COHOON, JASON B.
To: TRUIST BANK
Reel/Frame 067131/0201 →
Continuity (2)
Continuation 18636889 · Apr 16, 2024
Related Publication 20250322042A1 · Oct 16, 2025
References Cited (13)
US 10423777B2 · Spisak · 2019 [cited by examiner]
US 12126546B1 · De Castro Marchese · 2024 [cited by examiner]
US 20110041167A1 · Nguyen · 2011 [cited by examiner]
US 20130047200A1 · Radhakrishnan · 2013 [cited by examiner]
US 20140230020A1 · Mogaki · 2014 [cited by examiner]
US 20150312038A1 · Palanisamy · 2015 [cited by examiner]
US 20180300717A1 · Haque · 2018 [cited by examiner]
US 20190036700A1 · Sundaresan · 2019 [cited by examiner]
US 20190268342A1 · Rossman · 2019 [cited by examiner]
US 20220255745A1 · Tiffany · 2022 [cited by examiner]
US 20230092902A1 · Jiang · 2023 [cited by examiner]
US 20240080195A1 · Schrum · 2024 [cited by examiner]
US 20240291658A1 · O'Brien · 2024 [cited by examiner]