Endpoint Security Groups for Dynamic Edge Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The adoption of Industry 4.0 with networked computing devices increases the cyberattack surface in manufacturing environments, necessitating scalable and efficient policy enforcement for dynamic and multi-access networks, which conventional IP addressing schemes struggle to manage.

Innovation Solution

Endpoint security groups are utilized to classify computing devices by shared features or characteristics, enabling automated policy application and fine-grained control over network access and data traffic, independent of IP addresses, facilitating centralized policy definition and micro-segmentation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional IP addressing schemes are used for endpoint grouping, then network connectivity is established, but the cyberattack surface increases and policy enforcement becomes unscalable in dynamic multi-access networks

Engineering Contradiction:
Improvenetwork securityVSAvoidscalability in dynamic networks
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments endpoints into security groups based on functional capabilities rather than IP addresses. This segmentation allows for more flexible and scalable policy enforcement by grouping devices according to their roles (e.g., sensors, cameras, robotic systems) rather than their network addresses, thereby reducing the attack surface while maintaining security in dynamic networks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the grouping parameter from IP address to functional capability characteristics. By using parameters such as device type, capability, function, role, or location instead of IP addressing, the system achieves better adaptability to dynamic network conditions while maintaining robust security through automated policy application.

Inventive Principle:
Principle #35Parameter changes

2Extent of automation

If manual IP address allocation is used for policy application, then policy enforcement is possible, but human operator intervention is required and automation is lost

Engineering Contradiction:
Improvepolicy application automationVSAvoidmanual configuration requirement
Core Design Contradiction:
Extent of automationVSEase of operation

Solution Approach 1:

The patent implements self-service through automated policy application. When endpoints join the network, they are automatically classified into security groups based on their functional capabilities, and policies are automatically applied without requiring manual operator intervention. This automation eliminates the need for manual IP address allocation and configuration while maintaining ease of operation through centralized policy definition.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If centralized policy definition is implemented, then fine-grained control is achieved, but device complexity increases for policy enforcement

Engineering Contradiction:
Improvefine-grained control capabilityVSAvoidpolicy enforcement mechanism
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces security groups as an intermediary layer between centralized policy definition and individual endpoints. This intermediary structure enables fine-grained control by allowing policies to be defined once and automatically applied to all endpoints in a security group, reducing the complexity of policy enforcement while maintaining detailed control over data traffic through micro-segmentation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250211620A1Endpoint security groups in private multi-access edge compute networks
Publication Date: 2025.06.26 MICROSOFT TECHNOLOGY LICENSING LLC
  • US20250211620A1 patent drawing
  • US20250211620A1 patent drawing
  • US20250211620A1 patent drawing

AI summary

Endpoint security groups include computing device endpoints that are classified according to commonly shared device features and capabilities including device type, function, role, or location. Endpoint security groups are used as an alternative identity mechanism for endpoints for purposes of security and data traffic policy enforcement rather than using conventional IP (Internet Protocol) addressing. Grouping endpoints reduces the scope of network management to enable dynamic policy enforcement for endpoints as they join, leave, and then rejoin computing networks, which is a common behavior, particularly for IoT (Internet-of-Things) devices in manufacturing environments. In an illustrative example, a private multi-access edge compute (MEC) platform supports a scalable policy definition and enforcement framework that provides consistent endpoint handling independent of network access methodology. Endpoint security groups facilitate improvements in security of network access and utilization and segmentation of data traffic on a fine-grained basis.