Authentication-Based Endpoint Management for Unmanaged Endpoint Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing endpoint management systems struggle to identify and manage unmanaged devices accessing organizational networks, leading to increased cybersecurity vulnerabilities due to the lack of visibility and enforcement of security policies on unauthorized devices.

Innovation Solution

Implement a method for endpoint management classification that detects authentication attempts, determines the management status of endpoints, and transmits this data to the organization or service provider, enabling the implementation of protective protocols to mitigate security risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional endpoint management systems are used, then managed endpoints can be monitored and controlled, but unmanaged endpoints cannot be detected or managed

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidendpoint management status detection
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces an intermediary service that acts as a mediator between endpoints and the endpoint management system. This service receives authentication requests, determines management status, and enables detection of both managed and unmanaged endpoints without requiring direct agent-to-manager communication for status detection

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where the intermediary service communicates endpoint management status back to the authentication system. This feedback loop enables continuous monitoring and detection of endpoint states, allowing the system to identify unmanaged endpoints that would otherwise be invisible

Inventive Principle:
Principle #23Feedback

2Loss of information

If endpoint management agents are installed on all devices, then visibility and control are improved, but device complexity and user convenience deteriorate

Engineering Contradiction:
Improveendpoint visibilityVSAvoidsoftware installation requirements
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The intermediary service eliminates the need for complex agent installations by providing a simplified authentication-based detection mechanism. The service can determine management status through authentication processes alone, reducing the software burden on endpoints while maintaining visibility

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The intermediary service performs multiple functions: it handles authentication, determines management status, and provides visibility into endpoint states. This multi-functional approach replaces the need for dedicated management agents, simplifying the overall system while maintaining comprehensive endpoint visibility

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Loss of time

If authentication occurs before management status determination, then access is granted quickly, but security is compromised due to unknown endpoint status

Engineering Contradiction:
Improveauthentication timeVSAvoidsecurity vulnerability
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The system performs preliminary determination of endpoint management status during the authentication process itself, before granting access. The intermediary service evaluates management status as part of the authentication sequence, ensuring security decisions are made with complete information while minimizing additional time overhead

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent merges the authentication process with management status determination into a single integrated flow. By combining these two functions, the system eliminates separate detection steps, maintaining quick access approval while ensuring security decisions are based on known endpoint status

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12432205B2Systems and methods for endpoint management
Publication Date: 2025.09.30 CISCO TECHNOLOGY INC
  • US12432205B2 patent drawing
  • US12432205B2 patent drawing
  • US12432205B2 patent drawing

AI summary

A system and method for mitigating security vulnerabilities of a computer network by detecting a management status of an endpoint computing device attempting to authenticate to one or more computing resources accessible via the computer network includes: detecting an authentication attempt by the endpoint computing device to the computer network; during the authentication attempt, collecting management status indicia from the endpoint computing device, wherein the management status indicia comprise data used to determine a management status of the endpoint computing device; using the management status indicia to identify the management status of the endpoint computing device and identifying the management status of the endpoint computing device; and controlling access to the computer network based on (a) whether the authentication attempt by the endpoint computing device is successful and (b) the identified management status of the endpoint computing device.