Delegating Endpoint Security to Nearby Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing endpoint security solutions for computing devices require memory- and processor-intensive activities, which can negatively impact device performance, leading users to disable security software and leave devices vulnerable to malware.
Innovation Solution
Delegating endpoint security operations to nearby computing devices based on their state reputation, leveraging their computing capabilities to ensure continuous security protection without hindering the primary device's performance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If endpoint security operations are executed on the computing device, then security protection is provided, but device performance deteriorates due to memory- and processor-intensive activities
Solution Approach 1:
The patent extracts security operations from the endpoint device and relocates them to a cloud-based security server. The endpoint device only needs to communicate security-related data (file hashes, process information, network traffic) to the server, which then performs the computationally intensive security analysis and returns results. This extraction eliminates the performance burden on the endpoint while maintaining continuous security protection.
Solution Approach 2:
The patent introduces a cloud-based security server as an intermediary between the endpoint device and security threats. Instead of the endpoint device directly performing security operations, it communicates with the server which acts as a mediator to perform analysis, detect threats, and provide security decisions. This intermediary handles the computational workload while the endpoint benefits from security protection without performance degradation.
2Reliability
If memory- and processor-intensive security activities are performed, then continuous security protection is achieved, but energy consumption increases draining the battery
Solution Approach 1:
The patent extracts energy-intensive security processing from the mobile endpoint device and relocates it to a cloud-based server with unlimited power supply. The endpoint device only performs lightweight data collection and communication tasks, while the server handles all computationally intensive security operations. This extraction dramatically reduces battery consumption while maintaining continuous security protection.
Solution Approach 2:
The cloud-based security server performs security operations autonomously without requiring continuous active participation from the endpoint device. The server independently analyzes security data, monitors threats, and provides protection decisions, allowing the endpoint device to minimize its energy expenditure while still receiving continuous security services.
3Productivity
If security software is disabled to improve device performance, then device performance improves, but the device becomes vulnerable to malware and malicious attacks
Solution Approach 1:
The patent extracts the security enforcement function from the endpoint device software and relocates it to a cloud-based server. The endpoint device can operate with minimal or no local security software, as security decisions are made by the server based on data the device sends. This extraction allows the device to maintain high performance while the server provides continuous security oversight and protection against malware.
Solution Approach 2:
The cloud-based security server acts as an intermediary that provides security protection without requiring heavy software on the endpoint device. The server receives data from the device, performs security analysis, and returns protection decisions, enabling the device to maintain performance while the intermediary ensures vulnerability protection through continuous remote monitoring and analysis.
Data Source
AI summary
The disclosed computer-implemented method for delegating endpoint security operations to a nearby computing device may include (i) receiving device state data from one or more computing devices, (ii) determining a device state reputation for each of the one or more computing devices based on the device state data, (iii) selecting a device from the one or more computing devices based on the device state reputation for each of the one or more computing devices, and (iv) in response to selecting the device, delegating one or more operations for a security action to the selected device. Various other methods, systems, and computer-readable media are also disclosed.


