Coordinated Endpoint Updates for Lower Edge Security Complexity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computing devices at edge installations are susceptible to malicious attacks due to fewer security mechanisms and multiple attack vectors, increasing the risk of compromise during software updates.

Innovation Solution

Implementing a security framework that groups endpoint devices with a coordinating endpoint device to manage updates, using encryption and trusted keys to secure distribution, reducing the need for granular security functions across all devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security mechanisms are implemented on each endpoint device to protect against malicious attacks during updates, then security reliability is improved, but device complexity and computational overhead increase

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a coordinating endpoint device as an intermediary between the update source and managed endpoint devices. This coordinator handles security verification, update validation, and distribution coordination, allowing managed devices to receive updates without implementing complex security mechanisms themselves. The coordinator acts as a trusted intermediary that reduces security complexity at the edge devices while maintaining overall system security reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the security functionality by separating it into two groups: coordinating endpoint devices that perform security verification and validation, and managed endpoint devices that receive updates. This segmentation allows security-critical operations to be concentrated on specific devices with appropriate capabilities, while other devices can remain simpler and focus on service provision.

Inventive Principle:
Principle #1Segmentation

2Reliability

If granular security functions are implemented across all endpoint devices, then security coverage is improved, but computing resource availability for services decreases

Engineering Contradiction:
Improvesecurity coverageVSAvoidcomputing resource availability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The coordinating endpoint device serves as an intermediary that centralizes security verification functions. Managed endpoint devices can dedicate their computing resources to providing services since the coordinator handles security verification, update validation, and distribution coordination. This intermediary approach maintains comprehensive security coverage while preserving computing resource availability at the edge devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements security functions partially at the managed endpoint devices (basic update reception and application) and excessively at the coordinating device (comprehensive verification, validation, and coordination). This partial/excessive distribution ensures security coverage is achieved without requiring all devices to have full security capabilities, thus maintaining computing resource availability for services.

Inventive Principle:
Principle #16Partial or excessive action

3Loss of time

If update distribution is performed directly from central source to each endpoint device, then update freshness is improved, but network overhead and attack surface increase

Engineering Contradiction:
Improveupdate freshnessVSAvoidattack surface
Core Design Contradiction:
Loss of timeVSObject-affected harmful factors

Solution Approach 1:

The coordinating endpoint device acts as an intermediary in the update distribution chain, receiving updates from the central source and distributing them to managed devices. This intermediary approach maintains update freshness by enabling efficient local distribution while reducing the attack surface by limiting direct exposure of managed devices to external update sources. The coordinator validates and verifies updates before local distribution, creating a security buffer.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the update distribution process into two phases: centralized update acquisition and validation by the coordinator, and local distribution to managed devices. This segmentation allows update freshness to be maintained through efficient local propagation while reducing the attack surface by minimizing direct connections between managed devices and external update sources.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12436776B2Distributing endpoint devices configuration via coordinator device
Publication Date: 2025.10.07 DELL PROD LP
  • US12436776B2 patent drawing
  • US12436776B2 patent drawing
  • US12436776B2 patent drawing

AI summary

Methods and systems for managing operation of endpoint devices are disclosed. The operation of the endpoint devices may be managed by distributing updates to the endpoint devices. To facilitate distribution, some endpoint devices may be grouped and one of the group may be selected to serve as a coordinating endpoint device. The coordinating endpoint device may serve as a single source of contact for a coordinator tasked with distributing updates to endpoint devices of the group. The coordinating endpoint device may obtain and distribute copies of the updates to recipient endpoint devices.