Application Access Trace Credential Type Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems face challenges in securely tracking and managing access to applications, particularly due to the differences in security between personal credentials and single sign-on credentials, which can lead to vulnerabilities and increased resource consumption when tracking multiple applications.
Innovation Solution
A processor determines the type of credential used to access applications and selectively outputs traces, removing or obfuscating sensitive information, to improve security and reduce resource consumption by only communicating relevant data to a backend entity, enabling organizations to manage access through single sign-on credentials based on analysis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If comprehensive traces of all applications are tracked and communicated to backend entity, then complete security monitoring is achieved, but resource consumption and data exposure risk increase
Solution Approach 1:
The patent extracts only the essential security-relevant information from application traces (credential type, application identification, access status) while excluding unnecessary sensitive data. This selective extraction maintains security monitoring effectiveness while significantly reducing the volume of data transmitted and processed, thereby lowering resource consumption.
Solution Approach 2:
The patent applies different processing qualities to different parts of the trace data. Sensitive fields such as personal credentials are either removed or obfuscated, while security-critical fields are preserved in full detail. This localized quality adjustment ensures comprehensive security monitoring where needed while minimizing resource usage for non-critical data.
2Productivity
If all sensitive information is included in traces, then complete troubleshooting and analysis capability is achieved, but security vulnerabilities increase
Solution Approach 1:
The patent converts potentially harmful sensitive information into beneficial security data by obfuscating or removing personally identifiable information while preserving the security-relevant characteristics of the access patterns. This transformation maintains troubleshooting and security analysis capabilities while eliminating security vulnerabilities associated with exposing sensitive user data.
Solution Approach 2:
The patent segments trace data into distinct categories: security-critical information (credential type, access status), application identification, and sensitive personal information. By separating these elements, the system can transmit and analyze security-relevant data while excluding or protecting sensitive personal information, thus maintaining troubleshooting capability without creating security vulnerabilities.
3Measurement precision
If personal credentials are tracked with full detail, then individual access analysis is improved, but security risks and resource usage increase
Solution Approach 1:
The patent extracts only the essential credential type information (personal credential versus single sign-on credential) while removing detailed personal credential data. This extraction maintains the precision needed to distinguish between different authentication methods and their associated security implications, while significantly reducing the complexity of data storage, transmission, and processing.
Data Source
AI summary
According to examples, an apparatus may include a processor that may determine that an application was accessed through a portal. Based on a determination that the application was accessed through the portal, the processor may determine whether a first credential type or a second credential type was supplied to access the application, in which the first credential type may include a set of personal credentials of a user and the second credential type may include a set of single sign-on credentials that the user may use to access multiple applications. The processor may also output a trace that may indicate an identification of the application that was accessed and the type of the credential supplied to access the application, in which a backed entity may analyze the data included in the trace.


