Clean Group Security Management via Self-Governance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security management systems face complexity and impracticality in implementing quarantine mechanisms across large networks with numerous access points, such as corporate wireless or Ethernet systems, due to high costs and complexity.
Innovation Solution
The system utilizes 'clean groups' where computers or users are automatically assigned based on compliance with security requirements, with self-governance capabilities to maintain compliance, including periodic checks and self-restricting actions if compromised, and temporary membership renewal.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If quarantine mechanisms are implemented at each access point in large networks, then network security is improved, but system complexity and cost increase significantly
Solution Approach 1:
The patent segments the network into clean groups and unclean groups, allowing quarantine mechanisms to be applied at the group level rather than at each individual access point. This segmentation enables security management to be scaled to large networks without proportionally increasing complexity at every access point.
Solution Approach 2:
The patent introduces clean group membership as an intermediary mechanism between access control and individual device security status. Instead of directly managing quarantine at each access point, the system uses clean group membership status as a mediator to determine whether devices can access the network, thereby reducing the complexity burden on access points themselves.
2Measurement precision
If manual security compliance checking is performed for each device, then security management precision is improved, but administrative burden and time consumption increase
Solution Approach 1:
The patent implements self-service mechanisms where devices automatically determine their own clean group membership status based on their security compliance state. Devices can autonomously join or leave clean groups without manual administrator intervention, thereby maintaining precise security compliance tracking while eliminating the time-consuming manual checking process.
Solution Approach 2:
The system implements feedback mechanisms where devices continuously report their security compliance status to the network, and clean group membership is dynamically adjusted based on this feedback. This automated feedback loop maintains high measurement precision for security compliance while reducing administrative time requirements.
3Ease of operation
If clean group membership is permanently assigned, then administrative overhead is reduced, but security responsiveness to compromise decreases
Solution Approach 1:
The patent implements dynamic clean group membership where devices can automatically join or leave clean groups based on their real-time security compliance status. This dynamic approach maintains ease of operation by automating membership management while preserving security responsiveness, as devices are automatically removed from clean groups when compromises are detected.
Solution Approach 2:
The system employs periodic security compliance checks and automatic re-evaluation of clean group membership. Rather than permanent assignment, devices undergo periodic assessment to determine continued eligibility for clean group status, thereby maintaining simple automated management while ensuring rapid response to security compromises through regular re-evaluation.
Data Source
AI summary
A system and method that utilizes clean groups for reducing security management complexity. The system reduces the complexity of managing security technologies by automatically assigning objects such as computers or persons to clean groups which are defined by existing management infrastructure. In an embodiment where members are computers, ongoing automatic efforts ensure that clean groups include only computers that satisfy specified security principles, which allows administrators to treat all computers that are in compliance as a group. Separately, the members of the clean group are required to implement self-governance, which is an ability to detect being compromised and to take steps to remove themselves from the clean group when they are compromised. In addition to attempting to remove itself from the clean group, a compromised computer may take additional steps aimed at minimizing further damage, such as erasing or hiding computer domain credentials, hiding/protecting/disabling cryptographic (e.g. EFS) keys, or logging out a user.


