Authorization Layer for Role-Based Resource Transfer Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing resource transfer systems are vulnerable to security breaches and inaccurate data transfers due to varying user privileges, leading to data loss, unauthorized usage, and increased latency.

Innovation Solution

Implementing an authorization layer that controls resource transfers based on user approval status, automatically performing transfers for approver administrators, delaying for approver non-administrators, and requiring approval indicators for non-approver non-administrators, thereby preventing unauthorized or inaccurate requests.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If user privileges are varied to enable different user roles (administrator, non-administrator), then ease of operation is improved, but security vulnerability increases due to unauthorized access risks

Engineering Contradiction:
Improveuser role differentiationVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system segments user privileges into distinct roles (administrator, non-administrator, approver, non-approver) and assigns specific permissions to each role. This segmentation allows the system to provide differentiated access control where each user group operates within defined boundaries, improving ease of operation while mitigating security risks through role-based access control.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary approval mechanism where non-approver users must obtain authorization from approver users before executing certain resource transfer operations. This intermediary layer acts as a security buffer, allowing operational flexibility for non-administrators while preventing unauthorized actions through mandatory approval workflows.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If approval workflows are implemented for non-approver users, then security is improved, but transfer latency increases due to additional approval steps

Engineering Contradiction:
Improveauthorization controlVSAvoidtransfer latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-configuring user roles and approval requirements before resource transfer operations occur. Approval workflows, notification rules, and user permissions are established in advance, allowing the system to automatically route requests through appropriate approval channels without ad-hoc decision-making, thereby reducing actual transfer latency while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements self-service capabilities where approver users can configure their own approval preferences, notification methods, and delegation rules. This self-service approach empowers users to optimize their own workflows, reducing the time required for approval decisions while maintaining appropriate authorization controls.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If graphical user interface with user listings is generated, then ease of operation is improved, but system complexity increases

Engineering Contradiction:
Improveinterface accessibilityVSAvoidsystem architecture
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system generates simplified graphical user interface representations (copies) of the underlying complex user data structures and permission matrices. The GUI displays user listings, role assignments, and approval statuses in an accessible format without exposing the complexity of the backend authorization logic, allowing users to interact with the system easily while the complex permission management operates transparently in the background.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS20250322401A1Authorization layer for controlling resource transfers
Publication Date: 2025.10.16 TRUIST BANK
  • US20250322401A1 patent drawing
  • US20250322401A1 patent drawing
  • US20250322401A1 patent drawing

AI summary

A system can be provided for controlling resource transfers based on user approval status. For example, the system receiving user data. The user data can include users associated with an entity and at least one approval status for each of the users. The at least one approval status of each user can be selected from a group consisting of approver administrator, approver non-administrator, and non-approver non-administrator. The system can further generate a graphical user interface based on the user data. The graphical user interface can include user listings and corresponding approval status identifiers. Each user listing can correspond to one of the users and the corresponding approval status identifiers can indicate the at least one approval status of each user.