Terminal Device Abstraction for Secure Operation Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud computing, as the number of terminal devices increases, the amount of operation information transmitted to the server device becomes enormous, making it challenging to securely capture illicit operations by terminal devices without omitting any and efficiently reducing the transmitted information, which existing techniques fail to address effectively.

Innovation Solution

A terminal device equipped with abstraction means to generate abstracted operation information based on an abstraction rule, computation means to compute a forecast score indicating the likelihood of illicit operations, and determination means to decide whether to transmit this information to a detection device, thereby reducing unnecessary data transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If operation information from all terminal devices is transmitted to the server device, then illicit operations can be securely detected, but the amount of transmitted information becomes enormous

Engineering Contradiction:
Improvedetection accuracyVSAvoidinformation amount
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent applies local quality by making different terminal devices have different transmission probabilities based on their individual forecast scores. Each terminal's operation information is treated differently according to its specific risk level, with higher-risk terminals transmitting more frequently and lower-risk terminals transmitting less, thus optimizing the balance between detection accuracy and data volume

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes the transmission parameter (transmission probability) based on the forecast score calculated from operation patterns. By dynamically adjusting this parameter according to the likelihood of illicit operations, the system achieves reliable detection while minimizing unnecessary data transmission from low-risk terminals

Inventive Principle:
Principle #35Parameter changes

2Quantity of substance

If operation information is reduced to minimize data transmission, then information overload is alleviated, but illicit operations may be omitted

Engineering Contradiction:
Improveinformation amountVSAvoiddetection accuracy
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The patent implements feedback by continuously monitoring operation patterns, calculating forecast scores, and adjusting transmission decisions based on this feedback loop. The system learns from past operations and adapts transmission probabilities accordingly, ensuring that illicit operations are captured while minimizing normal operation data transmission

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent performs preliminary action by calculating forecast scores in advance based on operation patterns before determining transmission decisions. This preliminary assessment allows the system to pre-identify high-risk terminals that require monitoring while avoiding unnecessary transmission from low-risk terminals

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11514163B2Terminal device, method for control of report of operation information performed by terminal device, and recording medium storing therein program for control of report of operation information performed by terminal device
Publication Date: 2022.11.29 NEC CORP
  • US11514163B2 patent drawing
  • US11514163B2 patent drawing
  • US11514163B2 patent drawing

AI summary

A terminal device includes an abstraction unit for generating abstracted operation information acquired by abstracting operation information indicating a result of operation of an own device, based on an abstraction rule; a computation unit for computing, based on the abstracted operation information, a forecast score indicating a level of forecast possibility relating to the operation information; and a determination unit for determining, based on the forecast score, whether to transmit the operation information to a detection device for detecting that the own device operates in an illicit manner, and thus retains that the detection device securely captures an illicit operation by the terminal device, and efficiently reduces the operation information being transmitted from the terminal device to the detection device.