Cloud Device Management Arbitration for Bandwidth Optimization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Information Handling Systems (IHSs) face challenges in managing and securing a wide range of devices across various locations and users, with malicious actors potentially accessing these systems to download or upload data, necessitating robust device management and security measures.
Innovation Solution
A cloud-delivered device management service enables client-initiated check-in and arbitration, allowing local eventing with defined maximum events per time period, reporting compliance failures, and ceasing alerts when exceeding event limits to prevent overload and ensure secure operation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the device management service monitors and reports all security events from multiple devices, then security monitoring capability is improved, but network bandwidth and cloud service resources are overwhelmed
Solution Approach 1:
The patent implements local arbitration at edge devices (workstations, gateways) that filters and prioritizes security events before transmission to the cloud. Different locations and devices apply different filtering criteria based on their specific security contexts, reducing unnecessary event transmission while maintaining comprehensive security monitoring where needed.
Solution Approach 2:
The patent segments the centralized event reporting function into distributed arbitration nodes at multiple levels (workstation level, gateway level, cloud level). Each segment handles local event filtering and prioritization, dividing the overall event management load and reducing bandwidth consumption on any single network path.
2Reliability
If the system implements comprehensive device management across diverse locations and users, then device security control is improved, but system complexity increases
Solution Approach 1:
The patent implements a universal arbitration framework that operates consistently across diverse device types, locations, and user contexts. The same core arbitration logic adapts to different scenarios through configurable policies, providing comprehensive security control without requiring separate management systems for each device category or location.
Solution Approach 2:
The patent employs dynamic arbitration policies that automatically adjust event filtering and reporting behavior based on current security contexts, device states, and threat levels. The system transitions between different monitoring intensities and reporting strategies without manual intervention, simplifying management while maintaining adaptive security control.
3Speed
If the cloud service processes and arbitrates all security events in real-time, then threat response speed is improved, but cloud processing resources are overwhelmed
Solution Approach 1:
The patent implements preliminary arbitration and filtering at local devices and gateways before events reach the cloud. High-value security events are identified and prioritized in advance, while routine or low-severity events are filtered locally, ensuring that cloud resources focus processing capacity on critical threats that require centralized analysis.
Solution Approach 2:
The patent introduces intermediate arbitration nodes (local workstations, gateways) that mediate between event sources and the cloud service. These intermediaries perform initial event validation, filtering, and prioritization, reducing the volume of events requiring cloud processing while maintaining real-time response capability for critical security incidents.
Data Source
AI summary
Client initiated cloud-delivered device management check-in allowance and arbitration may include registering an application as a cloud-based unified endpoint management and antimalware eventing-entitled application, assigning an eventing identification to the application, and deploying the application to a client Information Handling System (IHS). A cloud-delivered device management agent on the IHS is enabled to allow local eventing and a maximum number of events per time period(s) from the application are defined. The agent checks in to a cloud-delivered device management service, upon a compliance failure event, keyed by the application, and passes an alert of the compliance failure with a reason and the application's name. The agent reports excess alerting over the maximum number of events per time period as compliance failure by the client IHS, with the application's name. Also, the agent may cease passing alerts from the application in response to triggering such a report of excess alerting.


