Endpoint Policy Change via Dynamic Attribute Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network authentication systems fail to dynamically update policies in response to changes in endpoint device attributes during operation, such as corruption or status changes, which can compromise network security and efficiency.

Innovation Solution

The implementation of a system that utilizes full Boolean expressions and detection engines to identify changes in registered attributes of endpoint devices on a software-defined network (SDN), allowing for automatic policy updates and adaptive management of endpoint device permissions and actions without reauthentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication is performed based on initial device information only, then the authentication process is simple and quick, but the network security is compromised when device attributes change during operation

Engineering Contradiction:
Improvenetwork securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic policy updates by continuously monitoring endpoint device attributes during network operation. When attribute changes are detected (such as device corruption or status changes), the system automatically updates the applicable policies without requiring reauthentication. This transforms the static authentication approach into a dynamic system that adapts to changing device states, thereby improving network security while maintaining operational simplicity.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system establishes a feedback mechanism where the detection engine continuously monitors endpoint device attributes and provides information to the policy management system. This feedback loop enables automatic policy adjustments based on real-time device status, ensuring that security policies remain appropriate even as device attributes change during operation, thus resolving the contradiction between security reliability and system complexity.

Inventive Principle:
Principle #23Feedback

2Reliability

If policies are updated in real-time based on attribute changes, then network security is enhanced, but the system complexity and computational overhead increase

Engineering Contradiction:
Improvenetwork securityVSAvoidpolicy management system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the policy management system into distinct functional components: a detection engine that monitors attribute changes, a policy management system that processes changes, and an enforcement mechanism that applies updated policies. This segmentation allows each component to specialize in specific tasks, reducing overall system complexity while enabling real-time security updates. The detection engine handles monitoring, the policy management system handles logic and decision-making, and the enforcement mechanism handles policy application.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements self-service capabilities where the detection engine automatically identifies attribute changes and triggers policy updates without requiring manual intervention or reauthentication. The policy management system automatically evaluates Boolean expressions and determines appropriate policy changes, reducing the computational overhead associated with manual policy management and enhancing network security through automated real-time updates.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If full Boolean expressions are used for policy evaluation, then the precision of attribute change detection is improved, but the computational processing time increases

Engineering Contradiction:
Improveattribute change detection precisionVSAvoidpolicy update processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system evaluates full Boolean expressions only when attribute changes are detected, rather than continuously evaluating all policies for all devices. This partial action approach maintains high measurement precision for attribute change detection while reducing computational processing time by limiting full Boolean evaluation to necessary moments. The detection engine monitors attributes continuously but triggers comprehensive policy reevaluation only when changes occur.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9923924B2Endpoint policy change
Publication Date: 2018.03.20 HEWLETT PACKARD ENTERPRISE DEV LP
  • US9923924B2 patent drawing
  • US9923924B2 patent drawing
  • US9923924B2 patent drawing

AI summary

Endpoint device policy change can, in various examples, include detecting a change in a first registered attribute associated with an endpoint device on a network to a second registered attribute and changing a first policy applied to the endpoint device to a second policy associated with the second registered attribute in response to the detected change.