ML Security Requirement Mapping for Software Integrity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing software development processes struggle to integrate security requirements effectively, leading to a philosophical and practical separation between business and technical user descriptions, resulting in high false-positive and false-negative security outcomes, and a lack of scalability in expert resources.

Innovation Solution

Utilize machine learning models, specifically Natural Language Processing (NLP) and deep learning techniques like Recurrent Neural Networks (RNN), to classify functional requirements and prescribe accurate, contextual, and specific security acceptance criteria during the software development cycle.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If machine learning models are used to classify functional requirements and prescribe security acceptance criteria, then security requirements integration is automated and accuracy is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity classification accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces machine learning models as intermediary components that bridge functional requirements and security acceptance criteria. These models act as mediators that automatically classify requirements and generate security prescriptions without direct human intervention, thereby improving accuracy while managing complexity through automation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces manual security requirement integration processes with automated machine learning-based systems. The mechanical/manual classification and prescription process is substituted with intelligent algorithms that can process and classify functional requirements automatically, reducing human effort and improving consistency.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Productivity

If expert resources are scaled up to handle security governance, then security coverage is improved, but resource costs and management complexity increase

Engineering Contradiction:
Improvesecurity governance scalabilityVSAvoidresource management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent enables security governance to become self-service through automated machine learning models that can independently classify functional requirements and generate security acceptance criteria without requiring extensive expert intervention. This allows the system to scale security coverage without proportionally increasing expert resource requirements.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent uses machine learning models to replicate expert security classification capabilities across multiple requirements simultaneously. Instead of requiring one expert per requirement, the system creates copies of expert-level classification能力 through trained models, enabling scalable security governance.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS20260023554A1System and methods for software security integrity
Publication Date: 2026.01.22 WELLS FARGO BANK NA
  • US20260023554A1 patent drawing
  • US20260023554A1 patent drawing
  • US20260023554A1 patent drawing

AI summary

A method may include querying, using a processing unit, a project data store with a project identifier; in response to the querying, receiving a functional requirement of a project data structure stored in the project data store as associated with the project identifier; inputting, using the processing unit, the functional requirement into a trained machine learning model, the trained machine learning model configured with output nodes corresponding to a set of security concerns; after the inputting, accessing output values from the output nodes; and adding, using the processing unit, a security concern of the set of security concerns to the project data structure based on the output values.