Authentication-Based Endpoint Management for Unmanaged Endpoint Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing endpoint management systems struggle to identify and manage unmanaged devices accessing organizational networks, leading to increased cybersecurity vulnerabilities due to the lack of visibility and enforcement of security policies on unauthorized devices.
Innovation Solution
Implement a method for endpoint management classification that detects authentication attempts, determines the management status of endpoints, and transmits this data to the organization or service provider, enabling the implementation of protective protocols to mitigate security risks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional endpoint management systems are used, then managed endpoints can be monitored and controlled, but unmanaged endpoints cannot be detected or managed
Solution Approach 1:
The patent introduces an intermediary service that acts as a mediator between endpoints and the endpoint management system. This service receives authentication requests, determines management status, and enables detection of both managed and unmanaged endpoints without requiring direct agent-to-manager communication for status detection
Solution Approach 2:
The system implements feedback mechanisms where the intermediary service communicates endpoint management status back to the authentication system. This feedback loop enables continuous monitoring and detection of endpoint states, allowing the system to identify unmanaged endpoints that would otherwise be invisible
2Loss of information
If endpoint management agents are installed on all devices, then visibility and control are improved, but device complexity and user convenience deteriorate
Solution Approach 1:
The intermediary service eliminates the need for complex agent installations by providing a simplified authentication-based detection mechanism. The service can determine management status through authentication processes alone, reducing the software burden on endpoints while maintaining visibility
Solution Approach 2:
The intermediary service performs multiple functions: it handles authentication, determines management status, and provides visibility into endpoint states. This multi-functional approach replaces the need for dedicated management agents, simplifying the overall system while maintaining comprehensive endpoint visibility
3Loss of time
If authentication occurs before management status determination, then access is granted quickly, but security is compromised due to unknown endpoint status
Solution Approach 1:
The system performs preliminary determination of endpoint management status during the authentication process itself, before granting access. The intermediary service evaluates management status as part of the authentication sequence, ensuring security decisions are made with complete information while minimizing additional time overhead
Solution Approach 2:
The patent merges the authentication process with management status determination into a single integrated flow. By combining these two functions, the system eliminates separate detection steps, maintaining quick access approval while ensuring security decisions are based on known endpoint status
Data Source
AI summary
A system and method for mitigating security vulnerabilities of a computer network by detecting a management status of an endpoint computing device attempting to authenticate to one or more computing resources accessible via the computer network includes: detecting an authentication attempt by the endpoint computing device to the computer network; during the authentication attempt, collecting management status indicia from the endpoint computing device, wherein the management status indicia comprise data used to determine a management status of the endpoint computing device; using the management status indicia to identify the management status of the endpoint computing device and identifying the management status of the endpoint computing device; and controlling access to the computer network based on (a) whether the authentication attempt by the endpoint computing device is successful and (b) the identified management status of the endpoint computing device.


