Authorization Policy Orchestration for Dynamic Transaction Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication systems are unresponsive to dynamic transaction circumstances and authorizing party conditions, leading to potential unauthorized transactions, as they fail to conditionally require authorization based on endogenous and exogenous factors.

Innovation Solution

A system that includes authorization policy orchestration, utilizing user and relying party policy engines to conditionally require authorization by factoring in endogenous and exogenous factors, allowing for varying degrees of authorization and multiple authorizing entities, and enabling conditional authorization for transactions based on device status, location, transaction amount, and risk factors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional authentication systems are used, then transaction processing is simple and quick, but the system cannot respond to dynamic transaction circumstances and authorizing party conditions, leading to potential unauthorized transactions

Engineering Contradiction:
Improvetransaction securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system dynamically adapts its authorization requirements based on real-time transaction circumstances and authorizing party conditions. The policy engine continuously evaluates endogenous and exogenous factors to conditionally require authorization, transforming a static authentication system into a dynamic one that responds to changing conditions.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

A policy engine is introduced as an intermediary component between the transaction processing system and the authorization mechanism. This policy engine evaluates multiple factors (endogenous and exogenous) and determines whether authorization is required, acting as a mediator that adds security without requiring complete system redesign.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authorization is required for all transactions, then transaction security is improved, but transaction processing time and operational complexity increase

Engineering Contradiction:
Improveauthorization assuranceVSAvoidtransaction processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system changes the parameter of authorization requirement from a fixed state (always required or never required) to a variable state that depends on evaluated factors. By monitoring changes in transaction circumstances and authorizing party conditions, the system adjusts authorization requirements in real-time, reducing unnecessary authorization requests while maintaining security where needed.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

Instead of requiring full authorization for all transactions, the system applies partial authorization requirements only when necessary based on factor evaluation. This selective approach avoids the time loss and operational complexity of universal authorization while maintaining adequate security coverage.

Inventive Principle:
Principle #16Partial or excessive action

3Measurement precision

If multiple authorization factors are evaluated, then authorization accuracy is improved, but the complexity of determining authorization requirements increases

Engineering Contradiction:
Improveauthorization determination accuracyVSAvoidpolicy evaluation complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The policy engine segments the authorization evaluation process into distinct components: endogenous factor evaluation, exogenous factor evaluation, and synthesis. This segmentation allows multiple authorization factors to be evaluated systematically without overwhelming complexity, as each factor category can be processed independently and then combined.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10715555B1Hierarchical multi-transaction policy orchestrated authentication and authorization
Publication Date: 2020.07.14 SECUREAUTH CORP
  • US10715555B1 patent drawing
  • US10715555B1 patent drawing
  • US10715555B1 patent drawing

AI summary

A system and method for authentication policy orchestration may include a user device, a client device, and a server. The server may include a network interface configured to be communicatively coupled to a network. The server may further include a processor configured to obtain, from a client device via the network, a transaction request for a transaction, determine an authorization requirement for the transaction request based, at least in part, on a plurality of authorization policies, individual ones of the plurality of authorization policies being separately configurable by at least one of a relying party and an authorizing party, and complete the transaction based on the authorization requirement having been met.