Adaptive Security Policy Management for Mobile Financial Transactions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security systems for mobile financial transactions lack adaptability to changing security environments and risk scenarios, leading to increased vulnerability and delayed market entry for financial account issuers due to static security measures and labor-intensive risk assessments.

Innovation Solution

Implementing trust mediator agents that continuously detect changes in network security characteristics and adapt security safeguards dynamically, allowing financial account issuers to integrate new networks with minimal modifications and manage risk across various device and network types, while balancing user convenience and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If static security measures are deployed in traditional security systems, then security policies can be implemented with minimal complexity, but the system lacks adaptability to changing security environments and risk scenarios

Engineering Contradiction:
Improveadaptability to changing security environmentsVSAvoidsecurity system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic security policies that automatically adjust based on real-time risk assessments. The system transitions from static security configurations to dynamic ones by continuously monitoring security conditions and modifying security measures accordingly, allowing the system to adapt to changing environments without manual intervention.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates continuous feedback loops where security conditions are monitored, risk assessments are performed, and security policies are adjusted based on the feedback received. This closed-loop approach enables the system to learn from security events and automatically refine its security posture in response to emerging threats.

Inventive Principle:
Principle #23Feedback

2Reliability

If labor-intensive risk assessments are performed for each new network integration, then security risks can be thoroughly analyzed, but the time-to-market entry increases substantially

Engineering Contradiction:
Improvesecurity risk assessment accuracyVSAvoidmarket entry speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs automated risk assessments that evaluate security conditions and determine appropriate security measures without requiring manual analysis. The automated assessment engine continuously monitors network security characteristics and independently determines risk levels, eliminating the need for labor-intensive manual evaluations while maintaining assessment accuracy.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system changes security parameters dynamically based on detected security conditions. Instead of performing fixed, manual risk assessments, the system adjusts security parameters automatically in response to changing network conditions, enabling rapid adaptation to new networks while maintaining thorough security evaluation.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If comprehensive security safeguards are implemented for all mobile devices, then security protection is maximized, but user convenience and system usability decrease

Engineering Contradiction:
Improvesecurity protection levelVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system applies security measures locally based on specific risk conditions rather than uniformly across all transactions. Security safeguards are activated only where and when needed based on the assessed risk level, allowing the system to maintain high security protection while minimizing interference with normal user operations in low-risk scenarios.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system implements partial security measures proportional to the assessed risk level. Instead of applying maximum security safeguards in all cases, the system applies only the necessary level of security protection required for each specific transaction or network condition, balancing security needs with user convenience.

Inventive Principle:
Principle #16Partial or excessive action

4Adaptability or versatility

If security systems are modified to accommodate new network security characteristics, then security compatibility is improved, but system stability and operational continuity are disrupted

Engineering Contradiction:
Improvenetwork compatibilityVSAvoidsystem operational stability
Core Design Contradiction:
Adaptability or versatilityVSStability of the object's composition

Solution Approach 1:

The system performs preliminary risk assessments and prepares security policy adjustments in advance before implementing changes. By evaluating security conditions and pre-configuring appropriate security measures, the system can integrate new networks with minimal disruption to ongoing operations, maintaining stability while achieving compatibility.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system maintains continuous security monitoring and protection throughout the network integration process. Security safeguards remain active and operational during transitions, ensuring uninterrupted protection while the system adapts to new network characteristics, thus maintaining both compatibility and operational continuity.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS10360625B2Dynamically adaptive policy management for securing mobile financial transactions
Publication Date: 2019.07.23 AMERICAN EXPRESS TRAVEL RELATED SERVICES CO INC
  • US10360625B2 patent drawing
  • US10360625B2 patent drawing
  • US10360625B2 patent drawing

AI summary

A system for securing a mobile financial transaction using an adaptive security policy is provided by presenting, via an external terminal, an input request associated with a vertex of the security policy. User input is received via the external terminal in response to the input request. A rule associated with the vertex is retrieved from a database. An edge is selected from a plurality of edges associated with the vertex according to the retrieved rule. A communication session of the external terminal is routed to a subsequent vertex via the selected edge.