Real-time Data Transmission Validation via Security Profile Comparison

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large enterprise organizations face challenges in real-time monitoring and managing network activity to detect potentially unauthorized data transmissions across complex networks with numerous devices and users, making it difficult to ensure data security and prevent data leaks.

Innovation Solution

A computing platform that collects and compares security profiles of source and destination applications in real-time, detecting mismatches to trigger security actions and prevent unauthorized data transmissions, utilizing a system with processors, memory, and communication interfaces to analyze data transmissions and initiate security measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If real-time monitoring and validation of data transmissions is implemented across complex enterprise networks, then security detection accuracy is improved, but system complexity and resource consumption increase

Engineering Contradiction:
Improvesecurity detection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the security validation process into distinct functional modules: a security profile manager that maintains security profiles in a repository, a validation engine that performs real-time comparisons, and a notification system that alerts users of violations. This modular segmentation allows each component to be optimized independently, reducing overall system complexity while maintaining high detection accuracy through specialized functions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces security profiles as intermediary objects that mediate between data transmissions and validation rules. These profiles contain predefined security requirements and characteristics that act as intermediaries, allowing the system to validate transmissions by comparing against stored profiles rather than implementing complex validation logic directly in the transmission path, thereby simplifying the validation mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If real-time validation of all data transmissions is performed, then unauthorized transmissions are detected more accurately, but processing time and computational resources increase

Engineering Contradiction:
Improveunauthorized transmission detection accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by pre-defining and storing security profiles in a repository before validation is needed. Security profiles contain predetermined security requirements, characteristics, and validation rules that are prepared in advance. When a data transmission occurs, the system simply retrieves the relevant pre-prepared profile and performs a straightforward comparison, eliminating the need for complex real-time analysis and significantly reducing processing time while maintaining high detection accuracy.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If comprehensive security profile comparison is performed for each data transmission, then security validation reliability is improved, but processing speed decreases

Engineering Contradiction:
Improvesecurity validation reliabilityVSAvoiddata transmission processing speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts only the essential security characteristics and validation rules from comprehensive security profiles and stores them in an optimized format in the repository. Rather than performing comparisons against entire complex security frameworks, the system extracts and compares only the relevant security attributes needed for validation, such as data classification levels, encryption requirements, and authorized recipient lists. This extraction approach maintains validation reliability by focusing on critical security parameters while significantly improving processing speed by reducing the data volume being compared.

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If automated security action triggering is implemented to prevent unauthorized transmissions, then security prevention effectiveness is improved, but system automation complexity increases

Engineering Contradiction:
Improvesecurity prevention effectivenessVSAvoidautomation complexity
Core Design Contradiction:
ReliabilityVSExtent of automation

Solution Approach 1:

The patent implements a feedback mechanism where the validation engine continuously monitors data transmissions, compares them against security profiles, and automatically triggers predefined security actions when violations are detected. The system provides feedback to users through notifications about validation results and takes automated corrective actions such as blocking transmissions or alerting security personnel. This feedback loop maintains high prevention effectiveness by ensuring immediate response to security violations while managing automation complexity through rule-based decision-making rather than complex autonomous systems.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11785036B2Real-time validation of data transmissions based on security profiles
Publication Date: 2023.10.10 BANK OF AMERICA CORP
  • US11785036B2 patent drawing
  • US11785036B2 patent drawing
  • US11785036B2 patent drawing

AI summary

Aspects of the disclosure relate to real-time validation of data transmissions based on security profiles. A computing platform may collect, in real-time, information associated with a plurality of data transmissions between applications, where the information may include, for each data transmission, an indication of a source application and a destination application. Then, the computing platform may retrieve, from a repository and for each data transmission, a first security profile associated with the source application, and a second security profile associated with the destination application. The computing platform may then compare, for each data transmission, the first security profile to the second security profile. Subsequently, the computing platform may detect, based on a determination that the first security profile does not match the second security profile, a potentially unauthorized data transmission. Then, the computing platform may trigger one or more security actions to prevent the potentially unauthorized data transmission.