Authorized User Set for Account Security Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computer systems are vulnerable to unauthorized access when unattended, and users' varying levels of competency in protecting their systems allow adversaries to exploit limitations in security software, particularly in detecting malicious activities and social engineering attacks.

Innovation Solution

A system that authorizes a set of users to receive notifications and send responsive security actions when specific activities occur on another user's account, leveraging real-world social relationships to enhance security by allowing community members to monitor and respond to anomalies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If security software is used to detect malicious activity, then detection capability is improved, but the system remains vulnerable to social engineering attacks and advanced persistent threats that bypass automated detection

Engineering Contradiction:
Improvedetection capabilityVSAvoidsecurity protection
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent introduces authorized users as intermediaries between the monitored account and the security response system. When suspicious activity is detected, these intermediary users receive notifications and can manually assess the situation, providing a human judgment layer that complements automated detection and can distinguish between legitimate and malicious activity that automated systems may misclassify

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements a feedback loop where authorized users provide responses to security notifications, which then triggers appropriate security actions. This feedback mechanism allows the system to adapt to detected threats in real-time, with human users providing contextual feedback that improves the overall security response effectiveness

Inventive Principle:
Principle #23Feedback

2Speed

If automated security monitoring is implemented, then response speed is improved, but the system cannot detect external conditions and privacy-sensitive data that require human judgment

Engineering Contradiction:
Improveresponse speedVSAvoiddetection of external conditions
Core Design Contradiction:
SpeedVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary automated monitoring and detection of suspicious activities, then promptly notifies authorized users who can provide human judgment. This preliminary action by the automated system ensures rapid detection while the human users provide the necessary contextual understanding of external conditions and privacy-sensitive situations

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If users are directly responsible for protecting their own systems, then system autonomy is improved, but security effectiveness decreases due to varying user competency levels

Engineering Contradiction:
Improvesystem autonomyVSAvoidsecurity effectiveness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent creates a universal security network where multiple authorized users can monitor and respond to security events across different accounts. This multi-functional approach allows users with varying competency levels to contribute to security, with more proficient users potentially helping to protect accounts of less proficient users within the trusted network

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If security notifications are sent to multiple authorized users, then security coverage is improved, but notification management complexity increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidnotification management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the authorization management by allowing users to selectively specify which users are authorized to receive notifications for particular accounts or types of activities. This segmentation approach enables fine-grained control over notification distribution, improving security coverage while managing complexity through organized, account-specific authorization lists

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10389725B2Enhance computer security by utilizing an authorized user set
Publication Date: 2019.08.20 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10389725B2 patent drawing
  • US10389725B2 patent drawing
  • US10389725B2 patent drawing

AI summary

An approach is provided that enhances computer system security. In the approach, a set of users is authorized to be notified when any of a selected set of activities occurs on the user's account. When the system detects that one of the activities has occurred on the account, a notification is sent to the set of authorized users. The set of users may individually send a responsive security response to protect the user's account. Responsive to receiving the security response from one of the set of users, a security action is performed that is anticipated to protect the user's account.