Identity Provider Containment for Compromised User Identities

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security systems fail to effectively contain user identities compromised by security threats, such as phishing attacks, leading to potential unauthorized access to secure resources.

Innovation Solution

Implementing a system that receives and evaluates security alerts from threat detection devices, allowing an identity provider to enforce security policies by classifying alerts into action categories, such as denying access or requiring additional authentication factors, to protect user identities in real-time.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If device-based security monitoring is used, then security threats on endpoint devices can be detected, but malicious users can bypass security by using stolen user identities on different devices

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidsecurity containment effectiveness
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The security system segments the monitoring focus from endpoint devices to user identities. Instead of tracking security threats at the device level, the system independently monitors and contains compromised user identities across any device, preventing malicious users from bypassing security by switching devices.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary identity layer between the user and the secure resource. This identity monitoring and containment mechanism acts as a mediator that can detect compromised identities and enforce containment policies regardless of which endpoint device is used to access the secure resource.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If real-time identity containment is implemented, then compromised user identities can be protected, but additional authentication factors and security checks increase authentication complexity

Engineering Contradiction:
Improveidentity protection capabilityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary security assessments and pre-establishes containment policies for user identities before authentication attempts. By proactively monitoring identities and pre-defining containment actions, the system reduces the need for complex real-time authentication decisions, simplifying the authentication process while maintaining strong security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where security event data from monitoring user identities is continuously analyzed and used to dynamically adjust containment policies. This feedback loop enables the system to adapt authentication requirements based on actual security conditions, avoiding unnecessary complexity while maintaining appropriate security levels.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3423981B1Identity security and containment based on detected threat events
Publication Date: 2024.08.21 SECUREAUTH CORP
  • EP3423981B1 patent drawingFigure 1
  • EP3423981B1 patent drawingFigure 2
  • EP3423981B1 patent drawingFigure 3A~3B

AI summary

An alert source issues security alerts to an identity provider, which acts as a gatekeeper to a secure resource. Each security alert is associated with an alert user identity and a security threat. When a user identity requests access to the secure resource, the identity provider may look up security alerts associated with the user identity, such as my matching up the user identity with the alert user identity associated with each alert. Based on any discovered security alerts that correspond to the user identity and a pre-defined security policy, the identity provider may perform various security actions on the user identity. For example, the identity provider may contain a user identity associated with high-risk and/or high fidelity security alerts. The identity provider may deny the user identity access to the secure resource, or the identity provider may request additional authentication factors associated with the user identity before access to the secure resource is provided. The identity provider may provide access to the secure resource without containing the user identity if there are no discovered security alerts associated with the user identity, or if the discovered security alerts pose a minor threat.