Security Event Correlation for Faster Authentication Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud-based security solutions lack an efficient method to thoroughly describe authentication processes, consuming significant resources and time in determining authentication details, and often requiring manual intervention by IT administrators.

Innovation Solution

Implementing security event correlation to aggregate and correlate multiple events describing user authentication attempts, generating comprehensive authentication reports that automate the description process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cloud-based security solutions are used to identify and detect threats, then security detection capability is improved, but resource consumption and time required to determine authentication details increase

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidtime required to determine authentication details
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent correlates security events in advance to create aggregated events that contain pre-processed authentication information. When authentication details are needed, the pre-correlated events are already available, eliminating the need for time-consuming manual analysis of individual events. This preliminary correlation action stores authentication information in an accessible format for rapid retrieval.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If cloud-based security solutions are used to identify and detect threats, then security detection capability is improved, but system resource consumption increases

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidsystem resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent merges multiple individual security events into single aggregated events that represent complete authentication processes. Instead of processing and analyzing each event separately, the system combines related events (such as authentication requests, responses, and outcomes) into unified aggregated events, reducing the total number of processing operations and lowering system resource consumption.

Inventive Principle:
Principle #5Merging (Combining)

3Ease of operation

If manual intervention by IT administrators is used to determine authentication details, then authentication analysis can be performed, but administrator efficiency is reduced

Engineering Contradiction:
Improveauthentication analysis capabilityVSAvoidadministrator efficiency
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The patent implements a self-service mechanism where the security system automatically correlates events and generates aggregated authentication information without requiring manual administrator intervention. The system serves itself by autonomously processing security events, correlating them based on common portions, and producing ready-to-analyze aggregated events, thereby freeing administrators from manual authentication analysis tasks.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP4085357B1Using security event correlation to describe an authentication process
Publication Date: 2025.10.01 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP4085357B1 patent drawingFigure 1
  • EP4085357B1 patent drawingFigure 2
  • EP4085357B1 patent drawingFigure 3~4

AI summary

Techniques are described herein that are capable of using security event correlation to describe an authentication process. Multiple events may describe a common (i.e., same) attempt to authenticate the user. For instance, a first event may include a first description of the attempt, a second event may include a second description of the attempt, and a third event may include a third description of the attempt. The first, second, and third events may be correlated based at least in part on the first, second, and third descriptions. The first, second, and third events may be aggregated to provide an aggregated event that includes an aggregation of the first, second, and third descriptions. An authentication report may be generated to include the aggregation of the first, second, and third descriptions to describe the authentication process.