Configuration Management System for Secure Parameter Changes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security systems for computer devices are either overly complex, requiring specialized knowledge for setup and management, or overly simplistic, lacking fine-tuning capabilities and access to critical parameters, leading to potential security breaches during configuration changes.

Innovation Solution

A system and method that allows for simultaneous changes to system parameters while verifying their correctness and consistency to prevent security breaches, ensuring that changes do not lower the security level of the system, using a processor to initiate transactions and analyze potential impacts on security policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If comprehensive security control mechanisms are implemented to prevent security breaches during configuration changes, then security reliability is improved, but system complexity increases and requires specialized knowledge for operation

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a configuration management system that acts as an intermediary between users and the security system. This intermediary automatically verifies configuration changes against security policies, preventing security breaches without requiring users to have specialized security knowledge. The system mediates between the user's configuration requests and the security requirements, automatically resolving the contradiction between security reliability and ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements self-service by automatically analyzing configuration changes, verifying their consistency with security policies, and preventing potentially harmful changes without human intervention. The configuration management system autonomously performs security verification, eliminating the need for users to manually check security implications or possess specialized security knowledge, thus maintaining high security reliability while simplifying operation.

Inventive Principle:
Principle #25Self-service

2Reliability

If comprehensive security control mechanisms are implemented to verify configuration changes, then security reliability is improved, but ease of operation deteriorates due to specialized knowledge requirements

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The configuration management system serves as an intermediary that shields users from complex security verification tasks. It automatically analyzes configuration changes, checks them against security policies, and provides guidance or prevents changes that would compromise security. This intermediary function maintains high security reliability while keeping the system easy to operate by handling complexity behind the scenes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms that provide users with information about the security implications of their configuration changes. When a user attempts to modify a configuration parameter, the system analyzes the change, determines its impact on security policies, and provides feedback - either approving the change, requesting modifications, or preventing it altogether. This feedback loop maintains security reliability while guiding users through the process without requiring specialized knowledge.

Inventive Principle:
Principle #23Feedback

3Productivity

If automated verification of configuration changes is implemented, then productivity is improved through faster setup, but measurement precision of security properties may be compromised

Engineering Contradiction:
ImproveproductivityVSAvoidmeasurement precision of security properties
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The system performs preliminary verification of configuration changes before they are applied. The configuration management system analyzes proposed changes against security policies in advance, identifying potential security issues before they can affect system security. This preliminary action enables automated verification to proceed quickly and accurately, maintaining both high productivity and precise security measurement by catching issues before implementation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The verification process is segmented into distinct analytical steps: identifying configuration parameters, determining their security relevance, checking against security policies, and making approval decisions. This segmentation allows the automated system to methodically verify each aspect of configuration changes with precision while maintaining overall productivity through efficient automated processing of each segment.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11126729B2System and method of ensuring secure changing of system configurations
Publication Date: 2021.09.21 AO KASPERSKY LAB
  • US11126729B2 patent drawing
  • US11126729B2 patent drawing
  • US11126729B2 patent drawing

AI summary

A system and method is provided for changing parameter values of a computer system without changing security properties. An exemplary method includes receiving a request to change a system configuration of the computer system and identifying a parameter relating to system configurations based on the received request. Furthermore, based on the identified parameter, the method includes receiving instructions to change the identified at least one parameter and initiating a transaction to change the identified at least one parameter based on the received instructions. The initiated transaction is then analyzed to determine whether the change to the parameter will lower a security level of the computer system. If not, the method will execute the change of the identified parameter related to the system configuration.