Logon Access Management via ID Transformation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Businesses face a security risk as sensitive customer information is accessed outside their firewall, where logon IDs are not controlled, and former employees or vendors may still have access to this data, posing a misuse and breach risk.
Innovation Solution
A method and system for logon access management that captures logon IDs and associated user data, searches for matches within the entity, and transforms logon IDs into network IDs for controlled access, ensuring only valid users access sensitive applications and data, with periodic monitoring and transformation to prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If logon IDs from external sources are allowed to access applications and data outside the firewall, then service delivery to customers is enabled, but security risk increases due to uncontrolled access and potential data breaches
Solution Approach 1:
The patent introduces an intermediary system that sits between external logon IDs and internal applications/data. This intermediary captures external logon IDs, transforms them into internal network IDs through matching user data against internal databases, and then grants access. This mediator layer enables service delivery while maintaining security control, as all access must pass through the transformation and matching process.
Solution Approach 2:
The patent segments the access control process into distinct phases: capturing external logon IDs, storing them in an external database, transforming them through matching user data against internal databases, and granting access only after successful transformation. This segmentation allows the system to maintain both service delivery capability and security control by separating the external access interface from internal resource protection.
2Ease of operation
If logon IDs from terminated employees or vendors are not monitored, then operational simplicity is maintained, but unauthorized access risk increases
Solution Approach 1:
The patent implements a feedback mechanism where the system periodically retrieves and matches external logon IDs against internal network IDs, and vice versa. This continuous feedback loop automatically detects when access credentials should be revoked (such as when employees or vendors terminate), ensuring access control reliability without requiring manual monitoring while maintaining operational simplicity through automation.
Solution Approach 2:
The automated matching and transformation system performs self-service access control management. The system automatically monitors, matches, and revokes access credentials without human intervention, eliminating the need for manual tracking of terminated personnel while maintaining reliable access control. This self-service approach enhances both operational simplicity and control reliability.
3Measurement precision
If manual monitoring of external logon access is implemented, then access control accuracy improves, but system complexity and resource consumption increase
Solution Approach 1:
The patent replaces manual mechanical monitoring processes with an automated computer-based system. Instead of human operators manually checking and matching logon IDs, the system uses automated database matching and transformation processes. This substitution maintains high measurement precision for access control accuracy while reducing system complexity by eliminating manual intervention requirements.
Solution Approach 2:
The patent creates copies of external logon ID databases and stores them internally, then performs automated matching between external and internal databases. This copying approach enables precise access control through systematic comparison while maintaining relatively simple system architecture, as the matching process uses standard database operations rather than complex monitoring infrastructure.
Data Source
AI summary
A system and method for logon access management that includes capturing a logon id and associated user data, the logon id allowing access to at least one of an application or data outside of a entity, automatically searching for a match of at least a portion of the user data with id data inside the entity, and transforming the logon id into a network id when a match is found. The entity may be a company, business, organization, system, or network.


