User Fingerprinting via Indirect Performance Telemetry

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current information handling systems lack effective methods to detect and manage anomalous user behavior, leading to potential security breaches and inefficiencies in resource utilization.

Innovation Solution

An intelligent system configuration management system that utilizes interaction telemetry data to create unique user fingerprints by aggregating and analyzing performance parameters such as display brightness, processor thread count, and CPU usage, allowing for real-time monitoring and remediation of unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional user identification methods are used, then system simplicity is maintained, but security against unauthorized access deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces indirect identifiers as intermediary elements that mediate between user actions and identification. Instead of directly monitoring user credentials or biometric data, the system monitors performance parameters (display brightness, processor thread count, CPU usage) that indirectly reveal user identity and behavior patterns, enabling security without direct user data collection

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional mechanical user identification systems (passwords, biometric scanners) with a software-based statistical analysis system that processes performance parameter data to create user fingerprints, eliminating the need for physical security hardware while improving security through data-driven approaches

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If comprehensive monitoring of user interactions is implemented, then detection of anomalous behavior improves, but system performance and power consumption worsen

Engineering Contradiction:
Improvedetection accuracyVSAvoidpower consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies local quality by selectively monitoring specific performance parameters (display brightness, processor thread count, CPU usage) rather than comprehensively monitoring all system operations. This targeted approach focuses resources on parameters most indicative of user behavior patterns, improving detection accuracy while minimizing energy consumption from unnecessary monitoring

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes the monitoring parameters from traditional user input data to performance parameters that indirectly indicate user behavior. By monitoring system performance characteristics rather than direct user actions, the system achieves comprehensive behavior analysis with lower computational overhead and energy consumption

Inventive Principle:
Principle #35Parameter changes

3Speed

If real-time monitoring of performance parameters is implemented, then response time for security breaches improves, but processing resources and system overhead worsen

Engineering Contradiction:
Improveresponse timeVSAvoidprocessing efficiency
Core Design Contradiction:
SpeedVSProductivity

Solution Approach 1:

The patent implements preliminary action by continuously updating user fingerprints with performance parameter data in the background, preparing baseline behavior profiles before security incidents occur. This allows the system to detect anomalies quickly when they happen, as the comparison data is already prepared, improving response time without requiring intensive real-time processing during incident detection

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies partial action by monitoring only the most relevant performance parameters (display brightness, processor thread count, CPU usage) rather than all possible system metrics. This selective monitoring provides sufficient data for effective anomaly detection while minimizing processing overhead and resource consumption

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11663297B2System and method to assess anomalous behavior on an information handling system using indirect identifiers
Publication Date: 2023.05.30 DELL PROD LP
  • US11663297B2 patent drawing
  • US11663297B2 patent drawing
  • US11663297B2 patent drawing

AI summary

A computerized method to store aggregate information handling system interaction telemetry data representing levels of operational activity reported for a user of an information handling system in a monitoring system data repository memory device and for receiving aggregate information handling system interaction telemetry data for a plurality of other users crowd-sourced from a population of information handling systems accessed by a plurality of other users. An interaction signature platform may apply a supervised learning model algorithm to the aggregate information handling system interaction telemetry data for the user in comparison to the aggregate information handling system interaction telemetry data for the plurality of other users to determine at least one indirect identifier of the interaction telemetry data. The interaction signature platform constructs a fingerprint profile of operational activity by the user including a usage signature baseline for the at least one indirect identifier unique enough for identification.