Secure Event Recording and Processing via Identity-Linked Packaging

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current event logging technologies face security vulnerabilities, compatibility issues among different services, and lack of standardized taxonomies, which compromise the integrity and security of transactional event recording and processing.

Innovation Solution

A method for secure event recording and processing involves identifying events produced by applications, obtaining application identities through an identity service, and generating secure packages that include metadata for encryption, authentication, and context information, ensuring secure encapsulation and processing of events across networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If detailed event information is captured in logs, then auditing and reporting capabilities are improved, but security vulnerabilities increase as intruders can obtain information to penetrate bank accounts or identify attackable resources

Engineering Contradiction:
Improveevent detail informationVSAvoidsecurity vulnerability
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts only the essential event information needed for auditing and reporting purposes, removing detailed sensitive data from logs. This selective extraction maintains the usefulness of event logs for security monitoring while eliminating the security vulnerability of exposing sensitive information that could be exploited by intruders.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies different logging quality levels to different event types. Sensitive events undergo stricter filtering and anonymization, while non-sensitive events retain more detail. This local differentiation ensures that security-critical information is protected while maintaining adequate audit capability for less sensitive operations.

Inventive Principle:
Principle #3Local quality

2Ease of operation

If event logs are made easily accessible for debugging and problem resolution, then ease of operation is improved, but security practices are compromised as logs become vulnerable to manipulation and unauthorized access

Engineering Contradiction:
Improvelog accessibilityVSAvoidlog security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediary security layer between log storage and access. This intermediary enforces authentication, authorization, and integrity verification, allowing legitimate debugging access while preventing unauthorized manipulation. The intermediary acts as a gatekeeper that maintains both accessibility for authorized users and security against unauthorized access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary security measures including digital signatures, hashing, and access control policies before logs are accessed or manipulated. These pre-established security mechanisms ensure that even when logs are accessible for debugging, their integrity is protected and unauthorized changes are prevented through advance security configurations.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If different services use their own proprietary logging formats and taxonomies, then service-specific functionality is improved, but compatibility among interacting services deteriorates

Engineering Contradiction:
Improveservice-specific logging capabilityVSAvoidlogging system compatibility
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the logging system into standardized core components and service-specific extensions. A common standardized event format and taxonomy provide the foundation for compatibility, while allowing services to add proprietary fields and custom taxonomies as extensions. This segmentation enables both universal interoperability and service-specific functionality without requiring full customization across the entire system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal logging framework that can handle multiple service-specific formats through a common interface. The standardized event structure and taxonomy serve as a universal language that different services can speak, enabling compatibility among interacting services while still allowing each service to maintain its own logging capabilities through the standardized framework.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7934087B2Techniques for secure event recording and processing
Publication Date: 2011.04.26 ORACLE INT CORP
  • US7934087B2 patent drawing
  • US7934087B2 patent drawing
  • US7934087B2 patent drawing

AI summary

Techniques for secure event recording and processing are provided. An application produces an event. The identity of the application is associated with the event, and the event and identity information are packaged in a secure environment as a secure event package. Subsequent consuming applications: receive the secure event package; validate the identity information; and acquire other metadata for processing the event, which is included within the secure event package.