Event Data Fencing for Authentication Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Data breaches in authentication systems can compromise the security of connected companies due to shared data, leading to unintended vulnerabilities in user authentication processes.

Innovation Solution

Implementing an event data fencing method that uses a media monitoring algorithm to identify vulnerabilities associated with data breaches and prevent the use of affected event data in authentication processes by scanning publicly available reports for breach-related information and fencing the relevant data to prevent its utilization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data is shared between multiple applications for authentication purposes, then authentication functionality is improved, but security vulnerability increases due to potential data breaches

Engineering Contradiction:
Improveauthentication functionalityVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system proactively monitors data breaches and vulnerabilities before they can compromise authentication processes. By detecting compromised data in advance through continuous scanning of security advisories and breach databases, the system prevents vulnerable data from being used in authentication, thus resolving the contradiction between maintaining authentication functionality and preventing security vulnerabilities

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary component (data fencing mechanism) that sits between the shared data and the authentication process. This intermediary layer filters and blocks compromised data from reaching authentication systems while allowing legitimate data to pass through, thus maintaining authentication functionality without exposing systems to security vulnerabilities

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If event data is fenced to prevent use in authentication, then security is improved, but loss of information increases due to data unavailability

Engineering Contradiction:
ImprovesecurityVSAvoiddata unavailability
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system applies data fencing selectively only to compromised data portions rather than blocking all event data. By using vulnerability detection algorithms to identify specific compromised records, the system fences only the necessary minimal portion of data, thus maintaining security while preserving availability of legitimate non-compromised data for authentication purposes

Inventive Principle:
Principle #16Partial or excessive action

3Measurement precision

If media monitoring algorithm continuously scans for data breaches, then vulnerability detection is improved, but use of energy increases due to continuous operation

Engineering Contradiction:
Improvevulnerability detectionVSAvoidenergy consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The media monitoring algorithm operates periodically at scheduled intervals rather than continuously. The system scans for data breaches and vulnerability advisories at defined time periods, which reduces energy consumption while maintaining effective vulnerability detection capability. This periodic operation balances the need for timely breach detection with energy efficiency constraints

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS11496503B2Event data fencing based on vulnerability detection
Publication Date: 2022.11.08 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11496503B2 patent drawing
  • US11496503B2 patent drawing
  • US11496503B2 patent drawing

AI summary

A method for event data fencing includes initializing a media monitoring algorithm, wherein the media monitoring algorithm scans for one or more words relating to a data breach in publicly available reports. Responsive to identifying a report from the publicly available reports relating to a vulnerability associated with the data breach, the method determines whether the vulnerability is associated with event data utilized for an authentication process. Responsive to determining the vulnerability is associated with a portion of the event data utilized for the authentication process, the method fences the portion of event data associated with the vulnerability, wherein fencing prevents the portion of event data from being utilized in the authentication process.