Conditional Security Policy Activation via Segmented Deployment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge lies in the delayed and potentially risky distribution of patches and security policies in software systems, as administrators hesitate due to concerns about unintended side effects, leading to staggered enforcement and increased vulnerability to attacks.

Innovation Solution

A conditional activation system that allows security policies to be distributed and activated separately, with an option for simulation mode to assess effects before full activation, enabling controlled and staggered enforcement to minimize adverse impacts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of time

If security policies are distributed and activated simultaneously across all systems, then security response time is improved, but systems may experience unintended side effects and instability

Engineering Contradiction:
Improvesecurity response timeVSAvoidsystem stability
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The patent segments the security policy deployment process into two distinct phases: distribution phase and activation phase. During distribution, policies are installed on all systems but remain inactive. Activation occurs separately and can be controlled on a per-system or per-group basis, allowing administrators to activate policies gradually across different systems rather than all at once, thus preventing widespread instability from a single problematic policy update.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary installation of security policies before their activation. Policies are distributed and installed on target systems in advance, but their enforcement is delayed until a specified activation time or condition is met. This allows systems to prepare for policy changes without immediately experiencing their effects, enabling testing and verification before full enforcement.

Inventive Principle:
Principle #10Preliminary action

2Loss of time

If security policies are activated immediately upon distribution, then security enforcement is timely, but administrators cannot assess potential side effects

Engineering Contradiction:
Improvepolicy enforcement timeVSAvoidpolicy testing capability
Core Design Contradiction:
Loss of timeVSEase of manufacture

Solution Approach 1:

The patent enables preliminary installation of security policies before activation. Policies are distributed and installed on target systems in advance, but their enforcement is delayed until a specified activation time or condition is met. This allows administrators to test policies in a controlled manner and assess potential side effects before committing to full enforcement across the enterprise.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces dynamic control over policy activation through multiple mechanisms: scheduled activation at specific times, conditional activation based on system states or events, and selective activation for different system groups. This dynamic approach allows administrators to adjust activation timing and scope based on testing results and operational requirements, rather than forcing immediate universal activation.

Inventive Principle:
Principle #15Dynamics

3Stability of the object's composition

If all systems activate security policies at the same time, then security consistency is improved, but staggered system readiness causes enforcement variability

Engineering Contradiction:
Improvesecurity policy consistencyVSAvoidenforcement uniformity
Core Design Contradiction:
Stability of the object's compositionVSReliability

Solution Approach 1:

The patent segments the activation process to occur at different times for different systems or system groups. Rather than forcing simultaneous activation across the entire enterprise, administrators can define activation schedules or conditions that account for varying system readiness. This segmented approach maintains security consistency within each activated group while accommodating staggered readiness across the broader infrastructure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic activation control that adapts to system readiness states. Activation can be triggered by scheduled times, system events, or administrative decisions, allowing the system to dynamically adjust when policies become enforceable on different machines. This dynamic timing mechanism ensures that each system activates policies when ready, achieving uniform enforcement within operational constraints.

Inventive Principle:
Principle #15Dynamics

4Reliability

If administrators delay patch installation due to testing concerns, then system stability is maintained, but vulnerability exposure increases

Engineering Contradiction:
Improvesystem stabilityVSAvoidvulnerability exposure
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent enables preliminary installation of security patches and policies before their activation. Updates are distributed and installed on systems in advance, but their enforcement is delayed until a specified time or condition. This allows administrators to have patches ready and tested on individual systems without immediately applying them enterprise-wide, reducing vulnerability exposure while maintaining system stability through controlled activation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the patch deployment process into distribution and activation phases. Patches can be installed on specific systems or system groups and activated selectively, allowing administrators to test and validate updates on a limited basis before broader deployment. This segmented approach reduces the risk of enterprise-wide instability while progressively reducing vulnerability exposure.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS7591002B2Conditional activation of security policies
Publication Date: 2009.09.15 MICROSOFT TECHNOLOGY LICENSING LLC
  • US7591002B2 patent drawing
  • US7591002B2 patent drawing
  • US7591002B2 patent drawing

AI summary

A conditional activation system distributes a security policy to the computer systems of an enterprise. Upon receiving a security policy at a computer system, the computer system may install the received security policy without activation. When a security policy is installed without activation, it is loaded onto a computer system but is not used to process security enforcement events. The computer system may then determine whether a security policy activation criterion has been satisfied and, if so, activate the security policy.