External Entity Validation System for Secure Data Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current practices in large enterprises, particularly financial institutions, are unreliable and inconsistent in ensuring the protection and security of confidential data when shared with external entities, such as vendors, as assessments are often sporadic and lack consistent review and approval processes.

Innovation Solution

A system that initiates a validation process for external entities based on triggering events like contract actions, assessing their data handling mechanisms, procedures, and governance, ensuring compliance with enterprise security standards before allowing secure data communication, and includes ongoing assessments and off-boarding processes to maintain data security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If sporadic assessments of external entities are conducted, then some level of data protection is achieved, but the reliability and consistency of data security cannot be ensured

Engineering Contradiction:
Improvedata security reliabilityVSAvoidassessment system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by establishing comprehensive assessment protocols and security requirements before any data sharing occurs with external entities. Validation processes are initiated proactively rather than reactively, ensuring security measures are in place before potential breaches can occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback mechanisms through ongoing assessments, monitoring, and validation of external entities. This creates a closed-loop system where security effectiveness is constantly evaluated and adjusted, transforming sporadic checks into a reliable, continuous security assurance process.

Inventive Principle:
Principle #23Feedback

2Reliability

If comprehensive validation processes are implemented for external entities, then data security is improved, but the time and resources required for assessment increase

Engineering Contradiction:
Improvedata protection consistencyVSAvoidassessment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Assessments are conducted in advance of data sharing activities, allowing comprehensive validation to occur before business needs arise. This preliminary timing eliminates the need for rushed evaluations and ensures thorough security checks are completed without impacting operational timelines.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system employs dynamic assessment approaches that can adapt the depth and scope of validation based on risk levels, data sensitivity, and entity classifications. This allows comprehensive security validation while optimizing resource allocation and time investment according to specific circumstances.

Inventive Principle:
Principle #15Dynamics

3Adaptability or versatility

If external entities are allowed to host confidential data on Internet or mobile platforms, then data accessibility and utility are improved, but the risk of data exposure increases

Engineering Contradiction:
Improvedata hosting flexibilityVSAvoiddata breach risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system introduces an intermediary layer of validation, monitoring, and control mechanisms between the enterprise and external entities hosting data on Internet or mobile platforms. This intermediary framework enables flexible data sharing while maintaining security oversight and reducing exposure risks through structured governance.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system dynamically adjusts security parameters, access controls, and monitoring intensity based on the specific hosting environment, data sensitivity, and entity trust level. This allows flexible data hosting arrangements while adapting security measures to match the actual risk profile of each deployment scenario.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9635034B2System for authorizing electronic communication of confidential or proprietary data to external entities
Publication Date: 2017.04.25 BANK OF AMERICA CORP
  • US9635034B2 patent drawing
  • US9635034B2 patent drawing
  • US9635034B2 patent drawing

AI summary

A platform for providing authorization of electronic communication of secure data to external entities, e.g., vendors, third parties or the like based on an assessment of the data risk associated with communicating the data to the external entity. The secure data that is to be communicated, in the form of specific data items, are identified as well as the associated security standards. The external identity is assessed to ensure their capabilities to properly meet the enterprise/sender's information security, business privacy and continuity standards, along with applicable industry standards. Based on the results of the assessment, remediation action may be required to address critical vulnerabilities or recommendations may be presented to a decision-making entity to grant authorization to electronically communicate the data in question to the external entity. In response to granting authorization, secure communication channels are allocated and established to allow for communication of the data.