Security Awareness Assessment for Network Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for protecting users from phishing and unauthorized access on web sites rely heavily on technology, which can increase costs and complexity for users and sites, and do not effectively enhance user security awareness, leaving vulnerable users at risk.

Innovation Solution

A system that measures and utilizes user security awareness to control access to network site features, empowering users with knowledge and awareness to prevent confidential information disclosure, independent of financial status or site security technologies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If strong authentication technology and two-factor authentication devices are implemented, then security protection against phishing attacks is improved, but device complexity and operational complexity for users increase

Engineering Contradiction:
Improvesecurity protectionVSAvoidauthentication complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces complex mechanical/authentication systems (two-factor authentication devices, strong authentication technology) with a psychological/cognitive-based system that measures security awareness through user responses to scenarios and questions, thereby reducing device complexity while maintaining security protection

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent changes the parameter for security verification from technical authentication factors (devices, passwords) to a measurable parameter of security awareness level, determined through assessment of user knowledge and behaviors related to security risks

Inventive Principle:
Principle #35Parameter changes

2Reliability

If users are required to register verifiable financial information to access advanced functions, then protection from fraud is improved for the site sponsor, but user security awareness and security enhancement are not improved

Engineering Contradiction:
Improveprotection from fraudVSAvoiduser security awareness
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

Instead of requiring users to provide financial information as a proxy for trustworthiness, the patent inverts the approach by measuring and requiring demonstration of security awareness knowledge, thereby directly improving user security understanding rather than merely protecting the site sponsor

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The system enables users to self-assess and demonstrate their security awareness through responses to scenarios and questions, allowing them to independently verify and improve their own security knowledge without requiring site sponsors to verify financial information

Inventive Principle:
Principle #25Self-service

3Reliability

If enhanced technology solutions such as stronger authentication mechanisms are provided, then security protection is improved, but cost of operating the site increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidoperating cost
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent replaces expensive, long-term infrastructure investments in enhanced authentication technology with a cost-effective software-based awareness assessment system that can be quickly implemented and adjusted, reducing operating costs while maintaining security protection

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS8365246B2Protecting confidential information on network sites based on security awareness
Publication Date: 2013.01.29 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US8365246B2 patent drawing
  • US8365246B2 patent drawing
  • US8365246B2 patent drawing

AI summary

A system for protecting confidential information based upon user security awareness is provided. The system includes a network interface for connecting the system to a plurality of remotely-located network sites. The system also includes one or more processors on which at one or more data processing feature execute in response to a request received from a user of one of the remotely-located network sites. The system further includes a security-awareness module configured to execute in conjunction with the one or more processors for determining a measure of security awareness of the user, and for granting or denying the user access to the at least one data processing feature based upon the measure of security awareness.