Dynamic Constraint Matrix for Secure Network Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In large computing environments, existing solutions face challenges in timely detection of potentially unauthorized access, system errors, or data loss events due to the complexity of monitoring numerous interconnected end-point systems, leading to delayed responses and security breaches.

Innovation Solution

The implementation of a dynamic constraint specification matrix using AI/ML techniques within Security Information and Event Management (SIEM) systems for centralized security monitoring and analysis, combining human expertise with machine learning capabilities to identify potential vulnerabilities and anomalies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional monitoring methods are used in large computing environments, then system complexity is reduced, but detection speed and accuracy of unauthorized access and security events deteriorate

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the monitoring system into multiple specialized components: event collectors gather data from diverse sources, normalization engines standardize formats, correlation engines analyze relationships, and constraint specification matrices define security rules. This segmentation enables each component to specialize in specific tasks, improving detection accuracy while managing system complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary elements such as normalization engines that translate diverse event formats into standardized structures, and constraint specification matrices that mediate between raw event data and security decisions. These intermediaries bridge the gap between complex data sources and simplified analysis, enhancing detection precision without proportionally increasing overall system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive monitoring of numerous end-point systems is implemented, then security coverage is improved, but response time to detect and respond to security events deteriorates

Engineering Contradiction:
Improvesecurity coverageVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action through pre-defined constraint specification matrices that encode security rules and relationships before events occur. The system pre-establishes what constitutes suspicious patterns, approval combinations, and malfeasant indicators, enabling immediate evaluation of events against these pre-configured criteria rather than analyzing patterns in real-time, thus maintaining comprehensive coverage while accelerating response.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent incorporates feedback mechanisms where investigation actions generate results that feed back into the monitoring process. When potential malfeasance is detected, the system initiates investigations that provide feedback on whether access was properly approved, refining the understanding of security events and improving future detection accuracy while maintaining rapid response through iterative learning.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If manual analysis of access logs and application permissions is performed, then detection precision is improved, but productivity and scalability deteriorate

Engineering Contradiction:
Improvedetection precisionVSAvoidanalysis throughput
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent enables self-service through automated correlation engines that independently analyze events against constraint specification matrices without requiring continuous manual intervention. The system automatically detects potential malfeasance, initiates investigations, and generates findings, maintaining high detection precision through rule-based automation while achieving scalability that manual analysis cannot provide.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical analysis with automated computational systems. Constraint specification matrices provide structured rules that algorithms can evaluate efficiently, substituting human analysts' cognitive processes with machine-based pattern recognition. This substitution maintains detection precision through consistent rule application while dramatically increasing productivity and enabling analysis of large-scale data that would be infeasible for manual review.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Measurement precision

If extensive investigation actions are taken to verify access approvals, then detection accuracy is improved, but loss of time and computational resources increases

Engineering Contradiction:
Improveverification accuracyVSAvoidinvestigation time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies partial action by initiating investigation actions selectively rather than for every detected event. The system identifies potential malfeasance indicators and triggers investigations only for those cases meeting specific criteria, such as unusual approval combinations or constraint violations. This partial investigation approach maintains high verification accuracy for suspicious cases while avoiding the time and resource expenditure of investigating every single event, achieving a balanced approach between thoroughness and efficiency.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20250016158A1System and method for secure network access management using a dynamic constraint specification matrix
Publication Date: 2025.01.09 BANK OF AMERICA CORP
  • US20250016158A1 patent drawing
  • US20250016158A1 patent drawing
  • US20250016158A1 patent drawing

AI summary

Systems, computer program products, and methods are described herein for secure network access management using a dynamic constraint specification matrix. The method includes receiving an application access log associated with a user of a network. The application access log includes one or more approved applications for which the user has access. The method also includes determining a potential malfeasance indication for the user based on the application access log. The potential malfeasance indication is based on a first application of the one or more approved applications and a second application of the one or more approved applications that correspond to one of one or more potential malfeasant approval combinations. Each of the one or more potential malfeasant approval combinations includes two or more applications that one or more users on the network should not be authorized for access simultaneously. The method further includes causing an execution of an investigation action.