Credential Change Detection via Suspicious Pattern Matching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

First-line workers, who are non-technical and lack oversight, are vulnerable to credential management threats due to their delegation of credential management responsibilities, which can lead to malicious activities by untrusted figures of authority.

Innovation Solution

A credential change management system that automatically detects suspicious credential changes by comparing data surrounding credential changes with known suspicious patterns and triggers mitigation actions such as notifications, suspension of credential management privileges, and enhanced monitoring.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If credential management responsibilities are delegated to first-line workers or store managers, then ease of operation is improved, but reliability deteriorates due to lack of technical expertise and oversight

Engineering Contradiction:
Improvecredential management accessibilityVSAvoidcredential security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an automated monitoring system that acts as an intermediary between credential management actions and security verification. This system continuously monitors credential changes, compares them against suspicious patterns, and can trigger alerts or mitigations, thereby enabling non-technical workers to manage credentials easily while maintaining security through automated oversight

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements continuous feedback loops by monitoring credential management activities, comparing them against known suspicious patterns, and providing real-time alerts or automated responses. This feedback mechanism allows the system to learn from and respond to credential management actions, maintaining security while enabling broad access to credential management functions

Inventive Principle:
Principle #23Feedback

2Reliability

If automated detection systems are implemented to monitor credential changes, then reliability is improved, but device complexity increases

Engineering Contradiction:
Improvecredential change detection accuracyVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates simplified copies or representations of credential change data that can be analyzed against pattern databases. Instead of implementing complex real-time analysis of all credential operations, the system captures essential change data, compares it against pre-established suspicious patterns, and triggers responses based on pattern matching, thereby reducing system complexity while maintaining detection reliability

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system performs preliminary actions by pre-establishing databases of suspicious credential change patterns before monitoring begins. By having these patterns pre-defined and stored, the monitoring system only needs to compare actual credential changes against these predetermined patterns, significantly reducing the computational complexity required for real-time detection while maintaining high reliability

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3841539B1Suspicious credential change detection and mitigation
Publication Date: 2025.04.02 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3841539B1 patent drawingFigure 1
  • EP3841539B1 patent drawingFigure 2
  • EP3841539B1 patent drawingFigure 3

AI summary

Suspicious credential changes are automatically detected and mitigated. A comparison of data surrounding user-account credential changes with suspicious change patterns forms a basis for detecting suspicious credential changes. More particularly, if a credential change substantially matches a known suspicious change pattern, the credential change can be flagged as suspicious. After a credential change is determined to be suspicious, one or more mitigation activities can be triggered to allay adverse effects associated with a suspicious credential change.