Dynamic Trust Security System with Time-Based Feedback

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current information security approaches are inadequate in detecting and mitigating attacks, particularly phishing and data exfiltration, due to reliance on trusted authorities and binary trust models, which can fail when compromised, and lack measurable efficacy and efficiency.

Innovation Solution

Implementing a time-based security approach with dynamic feedback loops and trust factors to quantify security postures, detect and react to threats, and reduce exposure time through delayed action and out-of-band security protocols, while using AI and machine learning for enhanced detection and analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current information security approaches (firewalls, trusted authority models) are used, then security structure is established, but detection and reaction efficacy is insufficient and cannot be measured

Engineering Contradiction:
Improvesecurity efficacyVSAvoiddetection measurement
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent implements feedback loops that continuously measure and adjust security parameters. Detection systems provide feedback about security events, and this feedback is used to dynamically adjust security policies and responses, enabling both improved reliability and measurable performance through continuous optimization based on actual detection data

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent changes security from a static binary trust model to a dynamic parameter-based system. Security decisions are based on continuously varying parameters such as trust scores, risk levels, and detection confidence values that can be precisely measured and adjusted, enabling granular control and measurable efficacy

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If trusted authority models are used for security decisions, then security control is centralized, but the system fails when the trusted authority is compromised

Engineering Contradiction:
Improvesecurity controlVSAvoidsecurity robustness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the centralized trusted authority into multiple distributed decision-making nodes. Instead of relying on a single trusted authority, security decisions are distributed across multiple entities that independently evaluate trust parameters, providing both ease of operation through automated local decisions and robustness through distributed redundancy

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transforms static trust relationships into dynamic, continuously evolving trust parameters. Trust scores are updated in real-time based on ongoing interactions and detection data, allowing the system to adapt to compromises and maintain reliability through dynamic adjustment rather than fixed authority structures

Inventive Principle:
Principle #15Dynamics

3Ease of manufacture

If binary trust models are used for security decisions, then security implementation is simple, but the system cannot adapt to evolving threats and lacks measurable efficacy

Engineering Contradiction:
Improvesecurity implementationVSAvoidthreat adaptation
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent replaces binary trust models with continuous parameter-based trust scores that can take any value within a range. This maintains implementation simplicity through standardized calculations while enabling sophisticated threat adaptation through nuanced parameter differentiation and dynamic adjustment based on detection data

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent implements dynamic trust parameters that evolve over time based on interactions and detection events. Rather than static binary classifications, trust relationships are continuously updated through feedback loops, enabling the system to adapt to evolving threats while maintaining measurable and predictable behavior through consistent parameter updates

Inventive Principle:
Principle #15Dynamics

4Reliability

If security detection and reaction systems are implemented, then threat detection capability is improved, but exposure time remains too long

Engineering Contradiction:
Improvedetection capabilityVSAvoidexposure time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary actions by pre-evaluating trust parameters and establishing baseline security policies before threats materialize. Detection systems continuously assess trust scores and prepare response actions in advance, reducing exposure time by having detection and reaction mechanisms already positioned and ready rather than initiating them after threat detection

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses feedback loops to continuously measure detection performance and adjust response times. By monitoring detection accuracy and reaction effectiveness in real-time, the system optimizes exposure time through continuous refinement of detection thresholds and response protocols, balancing detection capability with minimized exposure

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11438369B2Information security
Publication Date: 2022.09.06 SCHWARTAU WINN
  • US11438369B2 patent drawing
  • US11438369B2 patent drawing
  • US11438369B2 patent drawing

AI summary

An information security system that incorporates time, feedback, and/or varying trust in analyzing and responding to attacks. A solution can defer processing of a request for a period of time, which can be sufficient to allow the request to be approved or disproved. The solution can be configured to automatically approve or disprove the request after the period of time if no affirmative response is received. Trust for an entity can be periodically determined and can automatically decay over time. Feedback can be used as part of the approval/disproval process and/or to reevaluate trust.