Dynamic Decision Boundary for Electronic Authorization Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Activity processing systems face challenges in preventing unauthorized users from identifying and exploiting the decision boundary of authentication algorithms, leading to potential unauthorized electronic activity requests.

Innovation Solution

An electronic authorization system dynamically alters the decision boundary of decisioning algorithms, determines exposure levels, and performs remediation actions, such as blocking or changing algorithms, to prevent profiling and unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a static decision boundary is used in the authentication algorithm, then the system is easier to implement and analyze, but it becomes vulnerable to profiling attacks where unauthorized users can identify and exploit the decision boundary

Engineering Contradiction:
Improvedecisioning algorithm complexityVSAvoidauthentication security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent applies the dynamics principle by transitioning from a static decision boundary to a dynamic decision boundary that changes over time. The decision boundary is periodically updated using techniques such as adding noise, changing thresholds, or retraining the authentication algorithm, making it difficult for attackers to profile or exploit a fixed boundary while maintaining system security

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements parameter changes by modifying the decision boundary parameters dynamically. This includes changing decision thresholds, adjusting weightings of authentication factors, or altering the mathematical parameters that define the decision boundary, thereby preventing attackers from identifying and exploiting fixed parameter patterns

Inventive Principle:
Principle #35Parameter changes

2Reliability

If the decision boundary is dynamically altered to prevent profiling attacks, then authentication security is improved, but the system complexity and computational overhead increase

Engineering Contradiction:
Improveauthentication securityVSAvoiddecisioning algorithm complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies periodic action by updating the decision boundary at predetermined intervals or after processing a certain number of authentication requests. This periodic reconfiguration provides security against profiling attacks while allowing the system to maintain relative simplicity between updates, reducing continuous computational overhead

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The patent implements preliminary action by pre-planning and scheduling decision boundary updates in advance. The system prepares update strategies, selects appropriate timing for boundary changes, and orchestrates reconfiguration events beforehand, reducing the complexity of ad-hoc decision-making during authentication processing

Inventive Principle:
Principle #10Preliminary action

3Reliability

If frequent updates to the decision boundary are performed, then protection against profiling attacks is enhanced, but the processing time and computational resources increase

Engineering Contradiction:
Improveprotection against profiling attacksVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent uses periodic action to update the decision boundary at optimized intervals that balance security needs with processing efficiency. By updating boundaries periodically rather than continuously or too frequently, the system maintains protection against profiling attacks while avoiding excessive processing time consumption

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The patent applies partial action by implementing selective updates to the decision boundary based on detected attack patterns or risk levels. Rather than updating the entire boundary uniformly, the system performs targeted updates only when and where necessary, reducing overall processing time while maintaining adequate protection

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11050772B2Method and system for identification and prevention of profiling attacks in electronic authorization systems
Publication Date: 2021.06.29 BANK OF AMERICA CORP
  • US11050772B2 patent drawing
  • US11050772B2 patent drawing
  • US11050772B2 patent drawing

AI summary

An electronic authorization system is typically configured for: receiving electronic activity requests from a plurality of source nodes; analyzing each of the electronic activity requests using a decisioning algorithm, wherein a decision boundary of the decisioning algorithm is dynamically altered while analyzing the electronic activity requests; for each of the electronic activity requests, determining an activity exposure level of the decision boundary based on (i) a distance to the decision boundary and (ii) an amount of information exposed regarding the decision boundary; for each of the plurality of source nodes, determining a source exposure level of the decision boundary based on the activity exposure levels of the decision boundary of the electronic activity requests; and in response to determining that a likelihood of decision boundary profiling by one or more first source nodes exceeds a defined threshold, performing an exposure remediation action.