Online Data Signing System Aberrant Usage Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data signing systems lack a framework to manage permissions flexibly across organizations and are vulnerable to aberrant use, leading to security breaches and revenue loss due to unauthorized access and sharing of subscription credentials.

Innovation Solution

An online data signing system (ODSS) that generates and manages account activity patterns to detect and flag aberrant usage, incorporating a hierarchical organization structure and role-based access to prevent unauthorized data signing and ensure secure, permission-based operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If code signing services are provided online with fee-based models, then productivity and service accessibility are improved, but the system becomes vulnerable to aberrant use and revenue loss

Engineering Contradiction:
Improvecode signing service efficiencyVSAvoidsystem security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary actions by establishing baseline usage patterns for each account before detecting aberrant behavior. It proactively monitors and compares current usage against historical patterns, enabling early detection of potential security threats before they can cause significant harm or revenue loss.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback loops by monitoring account usage in real-time, comparing it against established baselines, and automatically responding to deviations. This feedback mechanism enables the system to adapt to changing usage patterns while maintaining security through automated anomaly detection and alerting.

Inventive Principle:
Principle #23Feedback

2Ease of operation

If subscription credentials are shared among multiple users, then ease of operation is improved, but security and revenue collection are compromised

Engineering Contradiction:
Improvecredential sharing convenienceVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system enables self-service functionality by automatically detecting and responding to aberrant usage patterns without requiring manual intervention. It autonomously monitors usage, identifies anomalies, and triggers appropriate responses such as alerts or account suspensions, reducing the need for human oversight while maintaining security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system replaces manual security monitoring and credential management with automated computational methods. Instead of relying on human operators to detect sharing behavior, the system uses algorithmic analysis of usage patterns to identify aberrant activity, substituting mechanical human processes with automated electronic monitoring.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Adaptability or versatility

If human-in-the-loop subscriptions are allowed, then service flexibility is improved, but the system becomes susceptible to credential sharing abuse

Engineering Contradiction:
Improvesubscription model flexibilityVSAvoidrevenue loss from abuse
Core Design Contradiction:
Adaptability or versatilityVSObject-generated harmful factors

Solution Approach 1:

The system implements dynamic monitoring that adapts to different subscription types and their expected usage patterns. It adjusts baseline expectations and anomaly detection thresholds based on whether the subscription is human-in-the-loop or machine-to-machine, allowing flexible subscription models while maintaining security through context-aware anomaly detection.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes monitoring parameters and detection thresholds based on the type of subscription and expected usage patterns. By adjusting sensitivity and baseline parameters according to the specific subscription model, the system maintains flexibility in offering different service types while effectively detecting aberrant behavior specific to each model.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20230252137A1Method and apparatus to detect and manage aberrant use of a software signing, encryption and obfuscation system
Publication Date: 2023.08.10 ARRIS ENTERPRISES LLC
  • US20230252137A1 patent drawing
  • US20230252137A1 patent drawing
  • US20230252137A1 patent drawing

AI summary

A system and method for detecting and managing aberrant use of a remote data signing, encryption and obfuscation utility is disclosed. In one embodiment, the method comprises generating a first account activity characteristic pattern associated with the account, the first account activity characteristic pattern generated from execution of one or more first activities associated with the account occurring over a first temporal period, generating a second account activity characteristic pattern, the second account activity characteristic pattern generated from execution of one or more second activities associated with the account occurring over a second temporal period, comparing the first account activity characteristic pattern and the second account characteristic activity pattern, and flagging the account for action according to the comparison.