Distributed Security Enforcement for Cross-Device Threat Containment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile device management systems face vulnerabilities in enforcing IT security policies across multiple devices, particularly in cross-device and ownership structures, as manual or scheduled updates can create potential points for hostile exploitation, and existing systems often limit control to devices within a common domain, lacking comprehensive protection against the spread of hostile elements.

Innovation Solution

A distributed system that communicates between remote devices and a secured server to enforce application platform security, using a communication server with security layer components to detect and lock down affected devices, analyzing risk factors such as shared security layers, geographic proximity, and user associations to prevent the spread of hostile elements, and employing out-of-band communications for reactivation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual or scheduled updates are used to enforce security policies, then device control is simplified, but security vulnerabilities increase due to potential exploitation points

Engineering Contradiction:
Improvedevice controlVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system enables devices to automatically detect security breaches and trigger lockdown procedures without manual intervention. The distributed system autonomously monitors security states across devices and executes security policies, eliminating the need for manual or scheduled updates while maintaining continuous security enforcement.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements continuous feedback loops where devices report their security state to the distributed network, which then analyzes the information and automatically responds with appropriate security actions. This real-time feedback mechanism ensures security policies are enforced dynamically without manual intervention.

Inventive Principle:
Principle #23Feedback

2Device complexity

If control is limited to devices within a common domain, then system complexity is reduced, but security coverage is insufficient across cross-device and ownership structures

Engineering Contradiction:
Improvesystem control structureVSAvoidsecurity coverage
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The distributed system architecture provides universal security enforcement across diverse device types, ownership structures, and domains. The system can manage security for devices with common domain names as well as those with different domain names or no domain names, making the security framework universally applicable across heterogeneous environments.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system segments security management into independent device-level units that can operate autonomously while contributing to collective security. Each device maintains its own security state and can trigger localized lockdowns, while the distributed network coordinates across segment boundaries to prevent cross-device propagation of threats.

Inventive Principle:
Principle #1Segmentation

3Reliability

If automatic detection and lockdown procedures are implemented across multiple devices, then security coverage is improved, but system complexity and communication requirements increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Each device autonomously detects security breaches on its own system and automatically executes lockdown procedures without requiring complex centralized coordination. This self-service capability reduces system architecture complexity while maintaining comprehensive security coverage across the distributed network.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system pre-configures security policies and lockdown procedures on each device before security events occur. When a breach is detected, the pre-configured actions are automatically executed, eliminating the need for complex real-time decision-making and reducing communication overhead during security incidents.

Inventive Principle:
Principle #10Preliminary action

4Difficulty of detecting and measuring

If comprehensive security monitoring is implemented across all devices, then detection capability is improved, but communication bandwidth and processing requirements increase

Engineering Contradiction:
Improvesecurity breach detectionVSAvoidcommunication and processing resources
Core Design Contradiction:
Difficulty of detecting and measuringVSUse of energy by moving object

Solution Approach 1:

The system implements security monitoring with local quality by focusing detection efforts on devices and network segments where security events are detected. Instead of uniformly monitoring all devices at full intensity, the system adapts monitoring depth and frequency based on local security conditions, reducing overall communication and processing requirements while maintaining effective detection capability.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10601860B2Application platform security enforcement in cross device and ownership structures
Publication Date: 2020.03.24 THE TORONTO DOMINION BANK
  • US10601860B2 patent drawing
  • US10601860B2 patent drawing
  • US10601860B2 patent drawing

AI summary

Methods and systems provide application platform security enforcement. A distributed system communicates between a plurality of remote devices and at least one secured server to facility providing a secured service. The distributed system may comprise a remote communication server and one or more security layer components where the plurality of remote devices connect through ones of the security layer components. Upon detection of a security breach by a first remote device, the distributed system determines potential devices at risk from the plurality of remote devices, analyzing risk factors for commonalities. A lock down and/or quarantine of the first remote device and the devices at risk is instructed. Risk factors may include whether the remote devices communicate via a same security layer component, are geographically proximate; and/or are associated at the user level, for example are proximate users in a social network graph. Reactivation is also provided.