Configuration Server Authorized Time-Lapse View of Credential Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Security management systems lack effective means to detect unauthorized changes in access privileges and provide a clear, authorized view of system and credential data change history, which can be complex and sensitive.

Innovation Solution

A configuration management server tracks changes in system and credential data, determining user authorization status to output an authorized view of records, limiting change history display based on this status, and providing a timeline control for selecting modification points with visual cues and restoration options.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If complete change history of system and credential data is tracked and made accessible, then transparency and auditability are improved, but security risks increase due to potential unauthorized access to sensitive information

Engineering Contradiction:
Improvetransparency of change historyVSAvoidsecurity risk from unauthorized access
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent implements role-based access control where different user roles (e.g., administrators, auditors, end-users) are granted different levels of access to change history data. Each user type sees only the portion of the change history relevant to their security clearance and job function, thereby maintaining transparency for authorized users while preventing unauthorized access to sensitive information.

Inventive Principle:
Principle #3Local quality

2Reliability

If detailed change history is displayed to all users, then accountability and detection of unauthorized changes are improved, but system complexity and difficulty of data management increase

Engineering Contradiction:
Improvedetection of unauthorized changesVSAvoidcomplexity of change history management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The change history data is segmented into multiple categories or views based on user roles and data sensitivity. The system divides the comprehensive change history into authorized portions that different user types can access, managing complexity through structured segmentation rather than presenting all data to all users.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary access control layer between users and the change history database. This intermediary component automatically filters and presents only the appropriate portion of change history to each user based on their authorization level, reducing the complexity of manual data management while maintaining reliable detection capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If full access to credential data is provided for monitoring purposes, then security monitoring capability is improved, but vulnerability to rogue user attacks increases

Engineering Contradiction:
Improvesecurity monitoring capabilityVSAvoidvulnerability to rogue user attacks
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The system grants monitoring access on a need-to-know basis, where different monitoring roles are assigned different levels of data access. Critical credential data is only accessible to high-level administrators with additional authentication, while lower-level monitors see only summary information, reducing the impact of potential rogue user attacks while maintaining effective security monitoring.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11297062B2Authorized time lapse view of system and credential data
Publication Date: 2022.04.05 HONEYWELL INTERNATIONAL INC
  • US11297062B2 patent drawing
  • US11297062B2 patent drawing
  • US11297062B2 patent drawing

AI summary

A system includes a configuration management server operable to interface with a plurality of client devices via a network. The configuration management server includes a processor that is configured to track a change history of modifications to one or more records of a plurality of system data and credential data. An authorization status of a user of an access client of one of the client devices is determined. An authorized view of a selected record of the one or more records is output to the access client. One or more fields of the selected record are displayed based on the authorization status. An output of the change history of modifications to the one or more fields of the selected record to the access client is limited based on the authorization status.