Application Access Trace Credential Type Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face challenges in securely tracking and managing access to applications, particularly due to the differences in security between personal credentials and single sign-on credentials, which can lead to vulnerabilities and increased resource consumption when tracking multiple applications.

Innovation Solution

A processor determines the type of credential used to access applications and selectively outputs traces, removing or obfuscating sensitive information, to improve security and reduce resource consumption by only communicating relevant data to a backend entity, enabling organizations to manage access through single sign-on credentials based on analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If comprehensive traces of all applications are tracked and communicated to backend entity, then complete security monitoring is achieved, but resource consumption and data exposure risk increase

Engineering Contradiction:
Improvesecurity monitoring completenessVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent extracts only the essential security-relevant information from application traces (credential type, application identification, access status) while excluding unnecessary sensitive data. This selective extraction maintains security monitoring effectiveness while significantly reducing the volume of data transmitted and processed, thereby lowering resource consumption.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies different processing qualities to different parts of the trace data. Sensitive fields such as personal credentials are either removed or obfuscated, while security-critical fields are preserved in full detail. This localized quality adjustment ensures comprehensive security monitoring where needed while minimizing resource usage for non-critical data.

Inventive Principle:
Principle #3Local quality

2Productivity

If all sensitive information is included in traces, then complete troubleshooting and analysis capability is achieved, but security vulnerabilities increase

Engineering Contradiction:
Improvetroubleshooting capabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent converts potentially harmful sensitive information into beneficial security data by obfuscating or removing personally identifiable information while preserving the security-relevant characteristics of the access patterns. This transformation maintains troubleshooting and security analysis capabilities while eliminating security vulnerabilities associated with exposing sensitive user data.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Solution Approach 2:

The patent segments trace data into distinct categories: security-critical information (credential type, access status), application identification, and sensitive personal information. By separating these elements, the system can transmit and analyze security-relevant data while excluding or protecting sensitive personal information, thus maintaining troubleshooting capability without creating security vulnerabilities.

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If personal credentials are tracked with full detail, then individual access analysis is improved, but security risks and resource usage increase

Engineering Contradiction:
Improveaccess analysis precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts only the essential credential type information (personal credential versus single sign-on credential) while removing detailed personal credential data. This extraction maintains the precision needed to distinguish between different authentication methods and their associated security implications, while significantly reducing the complexity of data storage, transmission, and processing.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12143377B2Application single sign-on determinations based on intelligent traces
Publication Date: 2024.11.12 MICROSOFT TECHNOLOGY LICENSING LLC
  • US12143377B2 patent drawing
  • US12143377B2 patent drawing
  • US12143377B2 patent drawing

AI summary

According to examples, an apparatus may include a processor that may determine that an application was accessed through a portal. Based on a determination that the application was accessed through the portal, the processor may determine whether a first credential type or a second credential type was supplied to access the application, in which the first credential type may include a set of personal credentials of a user and the second credential type may include a set of single sign-on credentials that the user may use to access multiple applications. The processor may also output a trace that may indicate an identification of the application that was accessed and the type of the credential supplied to access the application, in which a backed entity may analyze the data included in the trace.