User Fingerprinting via Indirect Performance Telemetry
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current information handling systems lack effective methods to detect and manage anomalous user behavior, leading to potential security breaches and inefficiencies in resource utilization.
Innovation Solution
An intelligent system configuration management system that utilizes interaction telemetry data to create unique user fingerprints by aggregating and analyzing performance parameters such as display brightness, processor thread count, and CPU usage, allowing for real-time monitoring and remediation of unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional user identification methods are used, then system simplicity is maintained, but security against unauthorized access deteriorates
Solution Approach 1:
The patent introduces indirect identifiers as intermediary elements that mediate between user actions and identification. Instead of directly monitoring user credentials or biometric data, the system monitors performance parameters (display brightness, processor thread count, CPU usage) that indirectly reveal user identity and behavior patterns, enabling security without direct user data collection
Solution Approach 2:
The patent replaces traditional mechanical user identification systems (passwords, biometric scanners) with a software-based statistical analysis system that processes performance parameter data to create user fingerprints, eliminating the need for physical security hardware while improving security through data-driven approaches
2Reliability
If comprehensive monitoring of user interactions is implemented, then detection of anomalous behavior improves, but system performance and power consumption worsen
Solution Approach 1:
The patent applies local quality by selectively monitoring specific performance parameters (display brightness, processor thread count, CPU usage) rather than comprehensively monitoring all system operations. This targeted approach focuses resources on parameters most indicative of user behavior patterns, improving detection accuracy while minimizing energy consumption from unnecessary monitoring
Solution Approach 2:
The patent changes the monitoring parameters from traditional user input data to performance parameters that indirectly indicate user behavior. By monitoring system performance characteristics rather than direct user actions, the system achieves comprehensive behavior analysis with lower computational overhead and energy consumption
3Speed
If real-time monitoring of performance parameters is implemented, then response time for security breaches improves, but processing resources and system overhead worsen
Solution Approach 1:
The patent implements preliminary action by continuously updating user fingerprints with performance parameter data in the background, preparing baseline behavior profiles before security incidents occur. This allows the system to detect anomalies quickly when they happen, as the comparison data is already prepared, improving response time without requiring intensive real-time processing during incident detection
Solution Approach 2:
The patent applies partial action by monitoring only the most relevant performance parameters (display brightness, processor thread count, CPU usage) rather than all possible system metrics. This selective monitoring provides sufficient data for effective anomaly detection while minimizing processing overhead and resource consumption
Data Source
AI summary
A computerized method to store aggregate information handling system interaction telemetry data representing levels of operational activity reported for a user of an information handling system in a monitoring system data repository memory device and for receiving aggregate information handling system interaction telemetry data for a plurality of other users crowd-sourced from a population of information handling systems accessed by a plurality of other users. An interaction signature platform may apply a supervised learning model algorithm to the aggregate information handling system interaction telemetry data for the user in comparison to the aggregate information handling system interaction telemetry data for the plurality of other users to determine at least one indirect identifier of the interaction telemetry data. The interaction signature platform constructs a fingerprint profile of operational activity by the user including a usage signature baseline for the at least one indirect identifier unique enough for identification.


