Endpoint Policy Change via Dynamic Attribute Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network authentication systems fail to dynamically update policies in response to changes in endpoint device attributes during operation, such as corruption or status changes, which can compromise network security and efficiency.
Innovation Solution
The implementation of a system that utilizes full Boolean expressions and detection engines to identify changes in registered attributes of endpoint devices on a software-defined network (SDN), allowing for automatic policy updates and adaptive management of endpoint device permissions and actions without reauthentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If authentication is performed based on initial device information only, then the authentication process is simple and quick, but the network security is compromised when device attributes change during operation
Solution Approach 1:
The patent implements dynamic policy updates by continuously monitoring endpoint device attributes during network operation. When attribute changes are detected (such as device corruption or status changes), the system automatically updates the applicable policies without requiring reauthentication. This transforms the static authentication approach into a dynamic system that adapts to changing device states, thereby improving network security while maintaining operational simplicity.
Solution Approach 2:
The system establishes a feedback mechanism where the detection engine continuously monitors endpoint device attributes and provides information to the policy management system. This feedback loop enables automatic policy adjustments based on real-time device status, ensuring that security policies remain appropriate even as device attributes change during operation, thus resolving the contradiction between security reliability and system complexity.
2Reliability
If policies are updated in real-time based on attribute changes, then network security is enhanced, but the system complexity and computational overhead increase
Solution Approach 1:
The patent divides the policy management system into distinct functional components: a detection engine that monitors attribute changes, a policy management system that processes changes, and an enforcement mechanism that applies updated policies. This segmentation allows each component to specialize in specific tasks, reducing overall system complexity while enabling real-time security updates. The detection engine handles monitoring, the policy management system handles logic and decision-making, and the enforcement mechanism handles policy application.
Solution Approach 2:
The system implements self-service capabilities where the detection engine automatically identifies attribute changes and triggers policy updates without requiring manual intervention or reauthentication. The policy management system automatically evaluates Boolean expressions and determines appropriate policy changes, reducing the computational overhead associated with manual policy management and enhancing network security through automated real-time updates.
3Measurement precision
If full Boolean expressions are used for policy evaluation, then the precision of attribute change detection is improved, but the computational processing time increases
Solution Approach 1:
The system evaluates full Boolean expressions only when attribute changes are detected, rather than continuously evaluating all policies for all devices. This partial action approach maintains high measurement precision for attribute change detection while reducing computational processing time by limiting full Boolean evaluation to necessary moments. The detection engine monitors attributes continuously but triggers comprehensive policy reevaluation only when changes occur.
Data Source
AI summary
Endpoint device policy change can, in various examples, include detecting a change in a first registered attribute associated with an endpoint device on a network to a second registered attribute and changing a first policy applied to the endpoint device to a second policy associated with the second registered attribute in response to the detected change.


