Device Posture Token for Security Checkpoint Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Security personnel face challenges in verifying the compliance of devices with security policies at facilities, as they lack easy access to administrative consoles or management services, leading to delays and inefficiencies in processing individuals at security checkpoints, especially when dealing with devices from other enterprises or managed by foreign management services.

Innovation Solution

A device posture token system is introduced, where a management service generates a token indicating compliance with security policies, which can be visually represented or transmitted to a verification device, allowing security personnel to quickly determine compliance without needing direct access to management services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If security personnel manually verify device compliance by accessing administrative consoles or management services, then verification accuracy can be maintained, but processing time increases significantly causing delays at security checkpoints

Engineering Contradiction:
Improveverification accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The device posture token is generated in advance by the management service, containing pre-verified compliance information. This preliminary action allows security personnel to simply present and verify the token without needing to access administrative consoles or perform time-consuming compliance checks during the security checkpoint process

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The device posture token acts as an intermediary that carries compliance verification information from the management service to security personnel. Instead of security personnel directly accessing complex management systems, they verify the token which has already been authenticated, significantly reducing verification time while maintaining accuracy

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If security personnel have direct access to management services for verification, then compliance checking can be performed, but system complexity and access requirements increase

Engineering Contradiction:
Improveverification processVSAvoidsystem access requirements
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The compliance verification information is extracted from the complex management service system and encapsulated into a simple device posture token. Security personnel only need to verify this token without needing access to or understanding of the underlying management service infrastructure

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of requiring security personnel to access the original management service system, a copy of the compliance verification data is created in the form of a token. This token can be independently verified without requiring connection to or authorization from the management service, simplifying the verification process

Inventive Principle:
Principle #26Copying

Data Source

PatentUS12126654B2Determining a device posture using a device posture token
Publication Date: 2024.10.22 OMNISSA LLC
  • US12126654B2 patent drawing
  • US12126654B2 patent drawing
  • US12126654B2 patent drawing

AI summary

Disclosed are various approaches for generating a device posture token corresponding to a client device. The device posture token can be used by a verification computing device to determine whether the client device complies with the security policies of a particular facility.