Authorization Policy Orchestration for Dynamic Transaction Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication systems are unresponsive to dynamic transaction circumstances and authorizing party conditions, leading to potential unauthorized transactions, as they fail to conditionally require authorization based on endogenous and exogenous factors.
Innovation Solution
A system that includes authorization policy orchestration, utilizing user and relying party policy engines to conditionally require authorization by factoring in endogenous and exogenous factors, allowing for varying degrees of authorization and multiple authorizing entities, and enabling conditional authorization for transactions based on device status, location, transaction amount, and risk factors.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional authentication systems are used, then transaction processing is simple and quick, but the system cannot respond to dynamic transaction circumstances and authorizing party conditions, leading to potential unauthorized transactions
Solution Approach 1:
The authentication system dynamically adapts its authorization requirements based on real-time transaction circumstances and authorizing party conditions. The policy engine continuously evaluates endogenous and exogenous factors to conditionally require authorization, transforming a static authentication system into a dynamic one that responds to changing conditions.
Solution Approach 2:
A policy engine is introduced as an intermediary component between the transaction processing system and the authorization mechanism. This policy engine evaluates multiple factors (endogenous and exogenous) and determines whether authorization is required, acting as a mediator that adds security without requiring complete system redesign.
2Reliability
If authorization is required for all transactions, then transaction security is improved, but transaction processing time and operational complexity increase
Solution Approach 1:
The system changes the parameter of authorization requirement from a fixed state (always required or never required) to a variable state that depends on evaluated factors. By monitoring changes in transaction circumstances and authorizing party conditions, the system adjusts authorization requirements in real-time, reducing unnecessary authorization requests while maintaining security where needed.
Solution Approach 2:
Instead of requiring full authorization for all transactions, the system applies partial authorization requirements only when necessary based on factor evaluation. This selective approach avoids the time loss and operational complexity of universal authorization while maintaining adequate security coverage.
3Measurement precision
If multiple authorization factors are evaluated, then authorization accuracy is improved, but the complexity of determining authorization requirements increases
Solution Approach 1:
The policy engine segments the authorization evaluation process into distinct components: endogenous factor evaluation, exogenous factor evaluation, and synthesis. This segmentation allows multiple authorization factors to be evaluated systematically without overwhelming complexity, as each factor category can be processed independently and then combined.
Data Source
AI summary
A system and method for authentication policy orchestration may include a user device, a client device, and a server. The server may include a network interface configured to be communicatively coupled to a network. The server may further include a processor configured to obtain, from a client device via the network, a transaction request for a transaction, determine an authorization requirement for the transaction request based, at least in part, on a plurality of authorization policies, individual ones of the plurality of authorization policies being separately configurable by at least one of a relying party and an authorizing party, and complete the transaction based on the authorization requirement having been met.


