Endpoint Security Configuration Automation for Network State Adaptation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In a Bring Your Own Device (BYOD) environment, managing endpoint security configurations automatically based on the network environment is challenging, as users need to manually adjust settings when switching between on-net and off-net states, increasing the risk of security vulnerabilities and inconvenience.

Innovation Solution

A client security application determines the network connection state by retrieving identification information from a network appliance, selecting and launching appropriate security configurations and functions based on whether the device is on-net or off-net, thereby automating the security management process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If users manually adjust security settings when switching between on-net and off-net states, then security configuration flexibility is improved, but user convenience deteriorates and time loss increases

Engineering Contradiction:
Improvesecurity configuration flexibilityVSAvoiduser convenience
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The client security application automatically detects network connection state changes and applies appropriate security configurations without requiring user intervention. The system monitors network state and self-adjusts security settings based on whether the device is on-net or off-net, eliminating manual configuration steps while maintaining security adaptability

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously monitors network connection state and uses this feedback to automatically trigger configuration changes. When the network state changes (on-net to off-net or vice versa), the application receives feedback about the new state and automatically applies the corresponding security configuration, creating a closed-loop control system

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If users manually adjust security settings when switching between on-net and off-net states, then security configuration flexibility is improved, but time loss increases

Engineering Contradiction:
Improvesecurity configuration flexibilityVSAvoidtime loss
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

Multiple security configurations are pre-configured for different network states (on-net and off-net). When a network state change is detected, the corresponding pre-prepared configuration is immediately applied without requiring user selection or manual adjustment, reducing time loss while maintaining configuration flexibility

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system automatically performs the configuration application process without waiting for user action. Upon detecting network state changes, the application autonomously selects and applies the appropriate pre-configured security settings, eliminating the time users would otherwise spend manually configuring security parameters

Inventive Principle:
Principle #25Self-service

3Ease of operation

If automatic configuration is implemented based on network environment, then ease of operation is improved, but device complexity increases

Engineering Contradiction:
Improveuser convenienceVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

A single client security application provides multiple security configurations for different network states, making the software multi-functional. The same application handles both on-net and off-net security requirements, managing complexity within a unified system rather than requiring separate configurations or tools

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The client security application acts as an intermediary between the network environment and the security configuration system. It monitors network state changes and automatically translates these changes into appropriate configuration applications, shielding users from complexity while maintaining ease of operation

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9894034B2Automated configuration of endpoint security management
Publication Date: 2018.02.13 FORTINET INC
  • US9894034B2 patent drawing
  • US9894034B2 patent drawing
  • US9894034B2 patent drawing

AI summary

Systems and methods for managing configuration of a client security application based on a network environment in which the client device is operating are provided. According to one embodiment, a network connection state of a client device with respect to a private network is determined by a client security application running on the client device. The client security application, then selects a configuration based on the determined network connection state. Finally, the client security application launches one or more functions of the client security application that are designated by the selected configuration.