Smart Contract Orchestration for Application Session Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for managing applications on computing devices face security risks due to weak configurations, leading to potential fraud and data breaches, especially on smartphones and tablets, as malicious attackers can tamper with application configuration data.

Innovation Solution

The implementation of smart contracts on a blockchain system that monitors application sessions, using deep learning techniques to detect malicious indications and misconfigurations, and dynamically updates rules to deny or shut down unauthorized access to user data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If applications are allowed to interact with the system, then ease of operation is improved, but security reliability deteriorates due to potential fraud and data breaches

Engineering Contradiction:
Improveapplication interactionVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a smart contract as an intermediary between applications and the system. The smart contract acts as a mediator that automatically enforces security rules and configures permissions, allowing applications to interact with the system while maintaining security through automated verification and control mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The smart contract performs self-service by automatically monitoring application sessions, detecting misconfigurations, and enforcing security rules without requiring manual intervention. The system self-regulates by continuously verifying application compliance and automatically responding to security threats.

Inventive Principle:
Principle #25Self-service

2Reliability

If smart contracts continuously monitor application sessions, then security reliability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity monitoringVSAvoidsystem structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces complex manual security monitoring mechanisms with automated smart contract execution on a blockchain system. The smart contract uses cryptographic verification and automated logic to monitor application sessions, substituting complex mechanical monitoring processes with streamlined digital verification mechanisms.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Measurement precision

If deep learning techniques are used to detect malicious indications, then measurement precision is improved, but use of energy increases

Engineering Contradiction:
Improvemalicious detection accuracyVSAvoidenergy consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent applies deep learning techniques selectively rather than continuously. The system uses partial action by triggering deep learning analysis only when specific conditions are met, such as detecting potential misconfigurations or suspicious patterns, rather than continuously processing all application data, thereby reducing overall energy consumption while maintaining high detection accuracy when needed.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20240386106A1Intelligent Distributed Ledger Based Smart Contract Orchestration for Preserving and Self-Healing of Configuration Fraud with Smart Device
Publication Date: 2024.11.21 BANK OF AMERICA CORP
  • US20240386106A1 patent drawing
  • US20240386106A1 patent drawing
  • US20240386106A1 patent drawing

AI summary

Aspects of this disclosure relate to systems and methods to determine whether an application is misconfigured or malicious using smart contracts stored on a distributed ledger and a transferred deep learning system. A smart contract is generated and assigned rules for monitoring an application session on a user computing device when an application session associated with the application is initiated. The smart contract denies or grants the application session permission to access user data and shuts down the application session when a malicious indication is detected in configuration data associated with the application based on rules assigned to the smart contract. The malicious indication is output by a deep learning module trained on historical configuration data associated with the application. The deep learning module transfers layers to an enterprise deep learning module on an enterprise platform to determine a misconfiguration indication indicating the configuration data is misconfigured.