Immutable Ledger for Insider Threat Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional systems fail to effectively detect and prevent privilege insider threats, as malicious insiders can exploit security vulnerabilities and bypass controls, especially when they are involved in the identity and access management processes, leading to unauthorized access and data breaches.

Innovation Solution

A threat prevention system that utilizes immutable records, zero-trust security, and secure identity proofing to verify user identities and access requests, ensuring that user credentials are cryptographically bound to physical devices and stored in immutable storage, allowing both the identity provider and relying party to independently validate transactions without relying on trust in a single entity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional monitoring and SIEM systems are used to detect insider threats, then security monitoring capability is improved, but the system can be bypassed by privileged insiders who define and implement the security controls

Engineering Contradiction:
Improvedetection capabilityVSAvoidbypass vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an immutable ledger as an intermediary between the identity provider and relying party. This mediator stores verification data that neither party can alter, creating a trustless verification mechanism that prevents privileged insiders from manipulating authentication outcomes while maintaining system reliability

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If trust is placed in a single entity (identity provider or relying party) for authentication, then system complexity is reduced, but security is compromised when that entity is controlled by malicious insiders

Engineering Contradiction:
Improvesystem architectureVSAvoidauthentication security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the authentication verification process into two independent components stored in the immutable ledger: the relying party stores a verification key and the identity provider stores corresponding verification data. This segmentation allows both parties to independently verify authentication without trusting each other, maintaining security even when controlled by malicious insiders

Inventive Principle:
Principle #1Segmentation

3Productivity

If privileged users have broad access rights to perform administrative tasks, then operational efficiency is improved, but the risk of insider threats increases

Engineering Contradiction:
Improveoperational efficiencyVSAvoidinsider threat risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by pre-storing verification data in the immutable ledger before authentication occurs. This preemptive measure ensures that even if privileged users attempt malicious actions, the immutable verification data will prevent unauthorized authentication, thus countering potential harm before it occurs while maintaining operational efficiency

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS11818154B2Privilege insider threat protection
Publication Date: 2023.11.14 IDEE LTD
  • US11818154B2 patent drawing
  • US11818154B2 patent drawing
  • US11818154B2 patent drawing

AI summary

Systems and methods for preventing insider threats. An identity provider system at least one of identifies and authenticates one or more users. A relying party system provides access to at least one electronic resource. A storage system stores one or more immutable records. The immutable records store user credential reference information associated with the users, including verifiable assurance of user identity mutually written by the identity provider and relying party systems. The identity provider system and the relying party system are configured to independently at least one of verify and validate a user request associated with at least one user among the users based on the user credential reference information stored in the immutable records.