Endpoint Security Configuration via Network State Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In a Bring Your Own Device (BYOD) environment, managing endpoint security configurations automatically based on network environments is challenging, as devices often need manual configuration changes when transitioning between on-net and off-net states, posing a risk to network security and user convenience.

Innovation Solution

A client security application determines the network connection state of a client device and selects appropriate configurations, launching corresponding security functions automatically by retrieving identification information from a network appliance, such as a DHCP server, to manage security settings accordingly.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual configuration changes are required when transitioning between on-net and off-net states, then user control over security settings is maintained, but network security risk increases and user convenience deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The client security application automatically detects network connection state changes and selects appropriate configurations without requiring user intervention. The system self-adjusts security settings based on whether the device is on-net or off-net, eliminating the need for manual configuration changes while maintaining security reliability.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously monitors network connection state and uses this feedback to automatically select and apply the appropriate security configuration. When the network state changes (on-net to off-net or vice versa), the application receives feedback about the new state and automatically adjusts settings, creating a closed-loop control system that maintains security without user input.

Inventive Principle:
Principle #23Feedback

2Manufacturing precision

If manual configuration changes are required when transitioning between network states, then configuration accuracy is maintained, but productivity deteriorates due to time loss

Engineering Contradiction:
Improveconfiguration accuracyVSAvoiduser productivity
Core Design Contradiction:
Manufacturing precisionVSProductivity

Solution Approach 1:

Multiple security configurations are pre-configured for different network states (on-net and off-net) before the user needs them. The client security application stores these configurations in advance and automatically selects the appropriate one when a network state change occurs, eliminating the need for users to manually configure settings and thus preventing productivity loss.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If automatic configuration selection is implemented based on network state, then user convenience is improved, but device complexity increases

Engineering Contradiction:
Improveuser convenienceVSAvoidapplication complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The security configuration is segmented into distinct, pre-defined configurations for different network states (on-net configuration and off-net configuration). Each segment contains specific settings appropriate for its network environment. The client security application maintains these separate segments and automatically selects the correct one based on current network state, managing complexity through structured division rather than complex real-time calculations.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10129341B2Automated configuration of endpoint security management
Publication Date: 2018.11.13 FORTINET INC
  • US10129341B2 patent drawing
  • US10129341B2 patent drawing
  • US10129341B2 patent drawing

AI summary

Systems and methods for managing configuration of a client security application based on a network environment in which the client device is operating are provided. According to one embodiment, a network connection state of a client device with respect to a private network is determined by a client security application running on the client device. The client security application, then selects a configuration based on the determined network connection state. Finally, the client security application launches one or more functions of the client security application that are designated by the selected configuration.