Resource Security System Access Rule Stability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing resource security systems face challenges in maintaining effective access rules over time, leading to increased denial of access to authorized users and granting access to unauthorized users, as fraudsters adapt their methods and legitimate users change their access patterns, degrading the performance of access rules.

Innovation Solution

A resource security system that determines and selects access rules based on their performance and stability over time by generating and comparing potential rules using a training subset of access requests, tracking triggering and predictive percentages, and compensating for reporting delays to reduce fraudulent access and false positives.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access rules are implemented to reject fraudulent access requests, then unauthorized access is prevented, but authorized users may be incorrectly denied access and rule performance degrades over time

Engineering Contradiction:
Improveaccess rule performanceVSAvoidfraud method adaptation
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system dynamically adapts access rules by continuously monitoring their performance metrics (triggering percentage and predictive percentage) and automatically updating or replacing rules that degrade in effectiveness. This allows the security system to evolve alongside changing fraud patterns while maintaining reliable discrimination between authorized and unauthorized access attempts

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements feedback loops where access rule outcomes are tracked and fed back into the rule generation process. By monitoring whether access requests were fraudulent or legitimate, the system continuously refines rule parameters and selects new rules based on observed performance, ensuring rules remain effective against evolving fraud methods

Inventive Principle:
Principle #23Feedback

2Reliability

If access rules are made more stringent to reduce fraudulent access, then security is improved, but false positives increase and legitimate access is denied

Engineering Contradiction:
Improvefraud detection accuracyVSAvoidlegitimate access flow
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system adjusts rule parameters dynamically based on performance data, modifying triggering thresholds and predictive criteria to optimize the balance between fraud detection and false positive reduction. Rules are selected and tuned to maintain high fraud detection accuracy while minimizing impact on legitimate access operations

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If access rules are updated frequently to adapt to new fraud patterns, then fraud detection improves, but system complexity and computational overhead increase

Engineering Contradiction:
Improvefraud pattern recognitionVSAvoidrule management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system performs self-updating of access rules by automatically generating, evaluating, and selecting new rules based on monitored performance metrics. The rule management process operates autonomously, reducing manual intervention and simplifying complexity while maintaining high adaptability to new fraud patterns through continuous self-optimization

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3869373B1Systems and methods for securing access to resources
Publication Date: 2022.10.26 VISA INTERNATIONAL SERVICE ASSOCIATION
  • EP3869373B1 patent drawingFigure 1
  • EP3869373B1 patent drawingFigure 2
  • EP3869373B1 patent drawingFigure 3

AI summary

In some embodiments, a resource security system may determine an access request outcome (e.g., accept, reject, or review) for an access request based on access rules. The resource security system may generate and select the access rules to be used using stability information. For instance, the resource security system may select a training set from the received access requests, e.g., including recently received access requests, segment the training set into a plurality of time-based subsets and generate a plurality of potential access rules based on the training set. The resource security system may determine and compare the detection performance and the stability performance of the potential access rules based on predictive percentages determined for the time-based subsets. The resource security system may select the best performing potential access rules to be used in operation for determining the outcome of access requests.