Identity Correlation Data Store for DLP Incident Tracking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data loss prevention (DLP) technologies fail to efficiently correlate multiple user identities across different computing environments, making it difficult to identify users involved in data leaks and track their activities, especially when they use various external identifiers.

Innovation Solution

A method and apparatus dynamically populate an identity-correlation data store that maps external identifiers to unique internal identifiers assigned by an entity, allowing for the correlation of multiple identities to a single user, thereby updating incident records with internal identifiers to identify the responsible user and track their activities across different identities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If external identifiers are used to track user activities across different computing environments, then the ability to monitor user behavior increases, but the difficulty of identifying and correlating user identities increases

Engineering Contradiction:
Improveuser identification reliabilityVSAvoididentity correlation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an identity correlation service as an intermediary component that receives external identifiers from various computing environments and correlates them with internal user identities. This service acts as a mediator between the external identifier system and the internal user management system, resolving the complexity of direct correlation while maintaining reliable user identification across different platforms and devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple external identifiers are monitored to track user activities, then the coverage of monitoring increases, but the difficulty of correlating identifiers to single users increases

Engineering Contradiction:
Improvemonitoring coverageVSAvoididentifier correlation difficulty
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The identity correlation service is designed as a universal system that can handle multiple types of external identifiers from various computing environments (mobile devices, desktop computers, different operating systems, various applications). It provides a single correlated user identity that works across all these different platforms and contexts, enabling comprehensive monitoring coverage while simplifying the correlation process through a unified approach.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If incident records are updated with internal identifiers, then the ability to identify responsible users improves, but the processing time increases

Engineering Contradiction:
Improveuser identification precisionVSAvoidincident record processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary correlation of external identifiers with internal user identities in advance, building and maintaining an identity correlation database before incidents occur. When an incident is detected, the system can quickly query this pre-built correlation data to identify the responsible user, rather than performing complex correlation analysis in real-time during incident processing. This reduces the time loss while maintaining precise user identification.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8868754B1Dynamically populating an identity-correlation data store
Publication Date: 2014.10.21 CA TECH INC
  • US8868754B1 patent drawing
  • US8868754B1 patent drawing
  • US8868754B1 patent drawing

AI summary

A method and apparatus for detecting a violation of a data loss prevention (DLP) policy and correlating an external identifier of an incident record of the violation to a unique internal identifier using an identity-correlation data store are described.