Cloud Broker Session Lifecycle Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud access security broker environments, users experience inconsistencies in single sign-on due to differing session timeouts across service providers, leading to re-authentication requirements and inconsistent user experiences, while threat intelligence is not adequately integrated into access policies to manage risk-based session management.

Innovation Solution

A system that monitors user behaviors and integrates real-time threat alerts to modify session data within an identity provider, adjusting session timeouts and access policies dynamically based on user interactions and risk assessments across multiple service providers, enabling seamless single sign-on and enhanced security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If session timeouts are extended to maintain consistent single sign-on across service providers, then user experience consistency is improved, but security risk increases due to prolonged access sessions

Engineering Contradiction:
Improveuser experience consistencyVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements dynamic session timeout adjustment by monitoring user behavior patterns and threat intelligence data in real-time. Session durations are not fixed but adapt based on current risk assessments, allowing the system to extend sessions for low-risk users while maintaining shorter sessions for high-risk scenarios, thus resolving the contradiction between user experience consistency and security risk

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the timeout parameter dynamically based on multiple factors including user behavior analysis, threat intelligence feeds, and service provider risk levels. By modifying the timeout parameter in response to changing conditions, the system achieves both consistent user experience and adaptive security posture

Inventive Principle:
Principle #35Parameter changes

2Reliability

If session timeouts are shortened to enhance security, then security risk is reduced, but user experience degrades due to frequent re-authentication

Engineering Contradiction:
Improvesecurity riskVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system dynamically adjusts session timeout durations based on real-time risk assessment. For users exhibiting normal behavior patterns and low threat indicators, the system extends session timeouts to prevent frequent re-authentication, thereby maintaining good user experience while preserving security through continuous monitoring

Inventive Principle:
Principle #15Dynamics

3Reliability

If threat intelligence integration is implemented to enable risk-based session management, then security is enhanced, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a session management system that acts as an intermediary between identity providers and service providers. This intermediary layer handles threat intelligence integration, risk assessment, and session timeout adjustment, shielding the underlying complexity from both users and existing system components while enhancing security

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements continuous feedback loops where user behavior is monitored, threat intelligence is integrated, and session parameters are adjusted accordingly. This automated feedback mechanism enables risk-based session management without requiring manual intervention, managing system complexity through automation

Inventive Principle:
Principle #23Feedback

4Reliability

If multiple service providers have different session timeout policies, then each provider can optimize for their specific security needs, but single sign-on consistency is broken requiring re-authentication

Engineering Contradiction:
Improveprovider-specific security optimizationVSAvoidsingle sign-on consistency
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The session management system provides universal session timeout adjustment that works across multiple service providers. It monitors user behavior and threat intelligence globally and applies appropriate timeout adjustments across all providers, maintaining single sign-on consistency while respecting individual provider security requirements through configurable policies

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11012455B2Modifying a user session lifecycle in a cloud broker environment
Publication Date: 2021.05.18 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11012455B2 patent drawing
  • US11012455B2 patent drawing
  • US11012455B2 patent drawing

AI summary

A method for modifying a user session lifecycle is provided. The method may include verifying a user session on a cloud service provider is valid. The method may also include monitoring a plurality of user behaviors exhibited during the verified user session. The method may further include determining a plurality of session data within an identity provider should be updated based on the monitored plurality of user behaviors and a policy within a database. The method may also include modifying the determined plurality of session data.