Endpoint Security Policy Control for Mobile Network Stability

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security measures for endpoint computing devices in mobile and ad hoc environments, such as WiMAX and Mesh, are inadequate, leading to poor security control and instability due to variable signal strength and mobility, with current solutions failing to enforce robust security policies across diverse hardware platforms and virtual environments.

Innovation Solution

Implementing pre-defined security policies that can be enforced on endpoint devices to govern connections, specifying security features for components and carriers, and dynamically adjusting policies to maintain stable connections while ensuring security, using a policy control module integrated with the operating system and hypervisor for multi-domain management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If pre-defined security policies are enforced on endpoint devices to govern connections, then security control is improved, but connection stability deteriorates due to rigid enforcement in variable signal environments

Engineering Contradiction:
Improvesecurity controlVSAvoidconnection stability
Core Design Contradiction:
ReliabilityVSStability of the object's composition

Solution Approach 1:

The patent implements dynamic policy adjustment mechanisms that allow security policies to adapt their enforcement strictness based on connection conditions. The system monitors signal strength, connection stability, and security risk levels, then dynamically modifies policy enforcement to maintain appropriate security while preventing unnecessary connection disruptions in challenging wireless environments.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes security policy parameters dynamically based on environmental conditions. When signal strength decreases or connection instability is detected, the system adjusts policy parameters such as authentication requirements, encryption levels, or policy enforcement strictness to maintain both security and connection stability.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If robust security policies are enforced across diverse hardware platforms and virtual environments, then security is improved, but device complexity increases due to multi-domain management requirements

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal policy control module that operates across multiple domains including physical hardware, virtual machines, and containerized environments. This single multi-functional component handles security policy enforcement for diverse hardware platforms and virtualization layers, eliminating the need for separate security management systems for each domain and reducing overall device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The policy control module serves as an intermediary layer between the operating system, hypervisor, and network stack. It provides a centralized interface for security policy management that translates high-level security requirements into domain-specific enforcement actions, simplifying multi-domain security management by abstracting the complexity from users and applications.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Stability of the object's composition

If security policies dynamically adjust to maintain stable connections, then connection stability is improved, but security control deteriorates due to flexible enforcement

Engineering Contradiction:
Improveconnection stabilityVSAvoidsecurity control
Core Design Contradiction:
Stability of the object's compositionVSReliability

Solution Approach 1:

The patent applies different security policy enforcement levels to different aspects of connection management. Critical security functions such as authentication and encryption maintain strict enforcement, while non-critical parameters such as reconnection timing or alternative path selection allow dynamic adjustment. This localized differentiation maintains both security control and connection stability.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system implements feedback mechanisms that continuously monitor both security compliance and connection stability metrics. When dynamic policy adjustments are made to maintain connection stability, the system verifies that security requirements remain satisfied through continuous feedback loops, ensuring that flexibility does not compromise security control.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8838804B2Securing a network connection by way of an endpoint computing device
Publication Date: 2014.09.16 MICRO FOCUS SOFTWARE INC
  • US8838804B2 patent drawing
  • US8838804B2 patent drawing
  • US8838804B2 patent drawing

AI summary

Methods and apparatus involve securing a network connection by way of mobile, endpoint computing assets. The endpoints have one or more pre-defined security policies governing the connection that are balanced against competing interests of actually maintaining connections between devices, especially in WiMAX, MANET, MESH, or other ad hoc computing environments where poor security, signal strength, fragile connections or mobility issues are of traditional concern. In this manner, connections will not be lost over security enforcement in an otherwise hostile environment. The security policies are enforced in a variety of ways, but may be altered to lesser policies or not-so-strictly enforced so as to maintain satisfactory connections between devices. Other embodiments contemplate analyzing connectivity components before connection and selecting only those components that enable full or best compliance with the policies. Still other embodiments contemplate altering connections in order to maintain full enforcement of policies. Computer program products are also disclosed.