Endpoint Health Enforcement via Inline Frame Intelligence

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing endpoint health enforcement methods face challenges in ensuring compliance across diverse devices, as they are difficult to implement and maintain, particularly in ensuring that host agents are up-to-date, leading to vulnerabilities that can compromise network security despite two-factor authentication.

Innovation Solution

A method that evaluates endpoint health by collecting data through various means such as inline frames, proxy services, and third-party collections, generating health intelligence, and notifying administrators to enforce network access policies, thereby ensuring devices meet security standards without requiring manual addition of endpoint health enforcement services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If host agents are mandated for endpoint health monitoring, then endpoint security monitoring capability is improved, but device complexity and compliance difficulty increase

Engineering Contradiction:
Improveendpoint security monitoring capabilityVSAvoidcompliance difficulty
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a network-based intermediary service that mediates between endpoints and security administrators. This service collects endpoint health data through standard network protocols without requiring complex host agents on each device, thereby maintaining security monitoring capability while reducing device complexity and compliance burden.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a universal endpoint health service that can monitor multiple endpoint types (desktops, laptops, mobile devices) through a single standardized interface. This multi-functional approach eliminates the need for device-specific agents, reducing compliance difficulty while maintaining comprehensive security monitoring across diverse endpoints.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If manual host agent installation is required, then endpoint health data collection accuracy is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveendpoint health data collection accuracyVSAvoidease of deployment
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The patent implements a self-service endpoint health monitoring system where endpoints automatically register and report their health status through standard network protocols. This eliminates manual agent installation while maintaining data collection accuracy, as endpoints self-configure and self-report to the centralized health service.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary configuration of endpoint health monitoring through standardized network services that are already present on most endpoints. By leveraging pre-existing network infrastructure and protocols, the system achieves accurate health data collection without requiring manual installation or configuration actions by users.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If comprehensive endpoint health monitoring is implemented, then network security is improved, but device complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a network-based intermediary service that handles the complexity of comprehensive health monitoring centrally, rather than distributing complex monitoring functionality to each endpoint. This intermediary collects detailed health data through simple standardized interfaces, maintaining network security while reducing device complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent moves endpoint health monitoring from the device dimension to the network dimension by implementing a centralized service that collects health data through network protocols. This dimensional shift allows comprehensive monitoring capability while keeping individual endpoints simple, as the monitoring complexity resides in the network service rather than on-device software.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS10542030B2Method for enforcing endpoint health standards
Publication Date: 2020.01.21 CISCO TECHNOLOGY INC
  • US10542030B2 patent drawing
  • US10542030B2 patent drawing
  • US10542030B2 patent drawing

AI summary

An approach for enforcing standards regarding security vulnerabilities for an endpoint user device associated with a user includes collecting, at an inline frame implemented with a web application, endpoint health data of the endpoint user device in response to the user interfacing with the web application through the endpoint user device, generating endpoint health intelligence from the endpoint health data, the endpoint health intelligence indicating endpoint security health of the endpoint user device, generating a first endpoint health notification comprising the endpoint health intelligence, and notifying an administrator of network with the first endpoint health notification.