Attribution Data Assignment Module for Container Cryptography

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional tools fail to accurately identify which application is responsible for the usage of cryptographic materials in complex systems, especially on container platforms like Kubernetes, where multiple applications coexist, making it difficult to assign attribution data to the correct owner.

Innovation Solution

A platform, cloud, and language agnostic attribution data assignment module that instruments the operating system level to capture a 'chain of responsibility' process tree, allowing for the mapping of OS-level processes to their parent processes and assigning attribution data to logical applications, enabling unique identification of owners within administration domains.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional monitoring tools are used to observe cryptographic usage, then system-wide monitoring coverage is achieved, but the ability to identify which specific application is responsible is lost

Engineering Contradiction:
Improveapplication identification precisionVSAvoidapplication ownership information
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent introduces an intermediary mechanism (attribution data assignment module) that captures process tree information and parent-process attribution data as intermediate representations. This intermediary layer bridges the gap between OS-level process observation and application-level ownership identification, allowing the system to maintain both monitoring coverage and application identification precision.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the monitoring system into distinct components: process tree capture, parent-process attribution data collection, and application identification. By dividing the monitoring function into these segments, each handling a specific aspect of attribution, the system achieves precise application identification while maintaining comprehensive monitoring coverage.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If detailed process tree data is collected at OS level, then accurate application attribution is achieved, but data collection overhead and system complexity increase

Engineering Contradiction:
Improveattribution accuracyVSAvoidmonitoring system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements self-service by having the monitoring system automatically capture process tree information and parent-process attribution data without requiring manual configuration or intervention. The system autonomously builds and maintains the attribution data structures, reducing operational complexity while maintaining high attribution accuracy.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary action by pre-capturing process tree information and parent-process attribution data before cryptographic operations occur. This advance preparation of attribution data structures enables accurate application identification without adding complexity to the actual monitoring and analysis processes.

Inventive Principle:
Principle #10Preliminary action

3Loss of information

If all process data is monitored and traced, then complete attribution information is obtained, but processing time and computational resources increase

Engineering Contradiction:
Improveattribution information completenessVSAvoiddata processing time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The patent extracts only the essential attribution information (process tree data and parent-process attribution data) needed for application identification, rather than monitoring and processing all process data. This selective extraction maintains complete attribution information while significantly reducing processing time and computational resource requirements.

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If multiple instrumentation probes are implemented to collect comprehensive data, then complete system visibility is achieved, but system performance overhead increases

Engineering Contradiction:
Improvemonitoring reliabilityVSAvoidsystem performance overhead
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements a universal instrumentation probe that performs multiple functions: capturing process tree information, collecting parent-process attribution data, and enabling application identification all through a single monitoring mechanism. This multi-functional approach maintains monitoring reliability while minimizing system performance overhead by avoiding redundant instrumentation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20240370320A1System, method, and computer program for enhanced attribution assignment to an application
Publication Date: 2024.11.07 JPMORGAN CHASE BANK NA
  • US20240370320A1 patent drawing
  • US20240370320A1 patent drawing
  • US20240370320A1 patent drawing

AI summary

Various methods, apparatuses/systems, and media for automating sponsored-search data pipelines are disclosed. A processor instruments a system at an operating system level based on implementing an instrumentation probe from a set of custom instrumentation probes; generates a chain of responsibility process tree based on instrumenting the system at the operating system level and a collected data from desired administration domain. The processor also maps corresponding operating system level process to a direct or indirect parent process that is assigned as an entry point for a logical application among a plurality of logical applications by implementing the chain of responsibility process tree; and assigns, in response to mapping, attribution data to the logical application.