Transaction Security Risk Aggregation via Weighted Matrix

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security risk tracking methods provide an incomplete and dated view of security risks, focusing on individual employee compliance without considering the organizational perspective, threat likelihood, or business-level context, and do not evaluate transaction-based security risks effectively.

Innovation Solution

A computerized method and system for transaction-based security risk aggregation and analysis that combines security risk data elements into a weighted risk matrix, generating a risk score based on business-level context and execution priority to determine whether to allow transaction execution, using a server computing device to receive and process security risk data from various sources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If security risk tracking is based on individual employee compliance with risk policies, then ease of operation is improved, but measurement precision and completeness of security risk view deteriorate

Engineering Contradiction:
Improveease of operationVSAvoidmeasurement precision
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent merges multiple security risk data elements from diverse sources (device security posture, user behavior, transaction characteristics, business context) into a unified risk score. This consolidation transforms fragmented compliance data into a comprehensive risk assessment that captures both individual and organizational security health, resolving the contradiction between ease of operation and measurement precision.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The risk scoring system serves multiple functions simultaneously: it assesses individual employee compliance, evaluates device security posture, analyzes transaction risk, and provides organizational security health metrics. This multi-functionality allows the system to maintain operational simplicity while delivering comprehensive security measurements across multiple dimensions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Device complexity

If security risks are evaluated without organizational perspective, then device complexity is reduced, but loss of information about overall security health increases

Engineering Contradiction:
Improvedevice complexityVSAvoidloss of information
Core Design Contradiction:
Device complexityVSLoss of information

Solution Approach 1:

The patent adds an organizational dimension to security risk evaluation by aggregating individual risk scores into departmental and enterprise-level security health metrics. This dimensional expansion enables the system to provide both detailed individual assessments and holistic organizational views without significantly increasing computational complexity, as the aggregation follows standardized algorithms.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Measurement precision

If transaction security risk does not consider business-level context, then measurement precision is improved, but loss of information about execution priority increases

Engineering Contradiction:
Improvemeasurement precisionVSAvoidloss of information
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent applies local quality by customizing risk assessment parameters based on specific transaction characteristics and business context. Different transaction types (e.g., financial transfers, data access, system configuration) receive tailored risk evaluations that consider their specific business implications, execution priority, and potential impact. This localized approach enhances both measurement precision and information completeness simultaneously.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS8966640B1Security risk aggregation and analysis
Publication Date: 2015.02.24 FMR CORP
  • US8966640B1 patent drawing
  • US8966640B1 patent drawing
  • US8966640B1 patent drawing

AI summary

Methods and apparatuses, including computer program products, are described for transaction-based security risk aggregation and analysis. A server computing device receives security risk data elements from a plurality of data sources. The security risk data elements correspond to a transaction submitted by a remote computing device to the server computing device for execution. The server computing device aggregates the security risk data elements into a weighted risk matrix and generates a risk score for the submitted transaction based upon the weighted risk matrix. The server computing device determines a business-level context and an execution priority of the submitted transaction, the business-level context and the execution priority based upon the security risk data elements. The server computing device adjusts the risk score for the submitted transaction based upon the business-level context and the execution priority and determines whether to allow execution of the transaction based upon the adjusted risk score.