Interactive Identity Resolution via Security Console and Resolver

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for IT personnel to resolve host device identity to employee identity and vice versa in secure data networks are inefficient, often requiring manual processes that take minutes to hours, leading to delayed remedial actions during security incidents.

Innovation Solution

A system and method utilizing a security console that interacts with an identity server through a resolver to efficiently convert between user and host identities, allowing for interactive resolution of identities within the secure network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of time

If manual processes are used to query DHCP servers, directory servers, and inventory databases to resolve host device identity to employee identity, then the resolution process can be completed with existing infrastructure, but the time required increases to minutes or hours

Engineering Contradiction:
Improveidentity resolution timeVSAvoidmanual query process complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The patent combines multiple separate query operations (DHCP server queries, directory server queries, inventory database queries) into a single integrated identity resolution system. The security console consolidates these disparate information sources and presents unified identity resolution results, eliminating the need for IT personnel to manually traverse multiple systems sequentially.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces an identity resolution module as an intermediary component that sits between the security console and the various backend systems (DHCP servers, directory servers, inventory databases). This mediator automatically performs the necessary queries and correlations, translating complex multi-system lookups into simple user interactions while reducing resolution time from minutes/hours to seconds.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If IT personnel manually query multiple servers and databases to locate devices during security incidents, then accurate device identification can be achieved, but the response time becomes unacceptable for timely remedial action

Engineering Contradiction:
Improvedevice identification accuracyVSAvoidsecurity incident response speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary action by pre-establishing the identity resolution framework and pre-configuring the security console to access all necessary identity resolution resources. When a security incident occurs, the system has already been prepared to perform rapid lookups across DHCP servers, directory servers, and inventory databases, enabling immediate device identification without ad-hoc manual querying.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces the mechanical manual process of querying multiple servers with an automated electronic system. The identity resolution module uses programmatic interfaces and automated query mechanisms to substitute for manual IT personnel actions, dramatically increasing response speed while maintaining identification accuracy through systematic data retrieval from multiple sources.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Productivity

If a comprehensive identity resolution system is implemented to enable interactive resolution between user and host identities, then the time to address security incidents is reduced, but the system complexity increases

Engineering Contradiction:
Improvesecurity incident resolution efficiencyVSAvoididentity resolution system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent extracts the complex identity resolution logic from the general security management system and places it in a dedicated identity resolution module. This separation allows the core resolution functionality to be optimized independently while presenting a simplified interface through the security console. The complex querying, correlation, and data integration operations are encapsulated within this specialized module, hiding complexity from the end user.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements universality by designing the identity resolution module to handle multiple types of identity resolutions (host to user, user to host, device location, department identification) through a single unified interface. The security console provides consistent functionality for resolving various identity types, eliminating the need for separate tools or processes for different resolution scenarios and simplifying the overall system architecture.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7647635B2System and method to resolve an identity interactively
Publication Date: 2010.01.12 A10 NETWORKS INC
  • US7647635B2 patent drawing
  • US7647635B2 patent drawing
  • US7647635B2 patent drawing

AI summary

A system and method for resolving an identity includes a security console, which displays security information regarding a secure network. The security information includes at least a first identity used to access the secure network. An operator selects the first identity, and the security console sends it to a resolver. The resolver connects with an identity server to find an access session record with an identity matching the first identity. A second identity is extracted from this record, and the resolver returns a result that includes the second identity. The security console displays the second identity; The first identity can be a user identity of a user, where the second identity is corresponding host identity, or vise versa. In this manner, an efficient interface to security information is provided to an operator, where the operator may resolve a user/host identity to a host/user identity interactively.