Clean Group Security Management via Self-Governance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security management systems face complexity and impracticality in implementing quarantine mechanisms across large networks with numerous access points, such as corporate wireless or Ethernet systems, due to high costs and complexity.

Innovation Solution

The system utilizes 'clean groups' where computers or users are automatically assigned based on compliance with security requirements, with self-governance capabilities to maintain compliance, including periodic checks and self-restricting actions if compromised, and temporary membership renewal.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If quarantine mechanisms are implemented at each access point in large networks, then network security is improved, but system complexity and cost increase significantly

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the network into clean groups and unclean groups, allowing quarantine mechanisms to be applied at the group level rather than at each individual access point. This segmentation enables security management to be scaled to large networks without proportionally increasing complexity at every access point.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces clean group membership as an intermediary mechanism between access control and individual device security status. Instead of directly managing quarantine at each access point, the system uses clean group membership status as a mediator to determine whether devices can access the network, thereby reducing the complexity burden on access points themselves.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If manual security compliance checking is performed for each device, then security management precision is improved, but administrative burden and time consumption increase

Engineering Contradiction:
Improvesecurity compliance checking accuracyVSAvoidadministrative time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements self-service mechanisms where devices automatically determine their own clean group membership status based on their security compliance state. Devices can autonomously join or leave clean groups without manual administrator intervention, thereby maintaining precise security compliance tracking while eliminating the time-consuming manual checking process.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements feedback mechanisms where devices continuously report their security compliance status to the network, and clean group membership is dynamically adjusted based on this feedback. This automated feedback loop maintains high measurement precision for security compliance while reducing administrative time requirements.

Inventive Principle:
Principle #23Feedback

3Ease of operation

If clean group membership is permanently assigned, then administrative overhead is reduced, but security responsiveness to compromise decreases

Engineering Contradiction:
Improvesecurity management simplicityVSAvoidsecurity responsiveness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements dynamic clean group membership where devices can automatically join or leave clean groups based on their real-time security compliance status. This dynamic approach maintains ease of operation by automating membership management while preserving security responsiveness, as devices are automatically removed from clean groups when compromises are detected.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system employs periodic security compliance checks and automatic re-evaluation of clean group membership. Rather than permanent assignment, devices undergo periodic assessment to determine continued eligibility for clean group status, thereby maintaining simple automated management while ensuring rapid response to security compromises through regular re-evaluation.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS7673326B2System and method utilizing clean groups for security management
Publication Date: 2010.03.02 MICROSOFT TECHNOLOGY LICENSING LLC
  • US7673326B2 patent drawing
  • US7673326B2 patent drawing
  • US7673326B2 patent drawing

AI summary

A system and method that utilizes clean groups for reducing security management complexity. The system reduces the complexity of managing security technologies by automatically assigning objects such as computers or persons to clean groups which are defined by existing management infrastructure. In an embodiment where members are computers, ongoing automatic efforts ensure that clean groups include only computers that satisfy specified security principles, which allows administrators to treat all computers that are in compliance as a group. Separately, the members of the clean group are required to implement self-governance, which is an ability to detect being compromised and to take steps to remove themselves from the clean group when they are compromised. In addition to attempting to remove itself from the clean group, a compromised computer may take additional steps aimed at minimizing further damage, such as erasing or hiding computer domain credentials, hiding/protecting/disabling cryptographic (e.g. EFS) keys, or logging out a user.