Enterprise Security Agent with Peer-to-Peer Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer systems are vulnerable to attacks, particularly from internal and external sources, due to inadequate detection of non-destructive parasites and unauthorized access, as existing protection software only recognizes known parasites and operates after damage is inflicted, leaving systems exposed to mapping attacks and data theft.

Innovation Solution

Implementing a method that authenticates devices within an enterprise system using an agent that analyzes device profiles against a defined policy, issuing trust credentials for compliant devices and preventing communication for non-compliant ones, while utilizing a realm controller with high reliability and availability to ensure continuous operation and restore devices to policy compliance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If current protection software is used to detect parasites, then known parasites can be detected, but new parasites and mapping attacks remain undetected

Engineering Contradiction:
Improveparasite detection accuracyVSAvoidsystem security
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The system performs preliminary actions by proactively scanning and analyzing devices before they can execute malicious activities. The security agent continuously monitors device profiles, behaviors, and configurations to detect potential threats in advance, rather than waiting for damage to occur. This includes pre-evaluating device compliance with security policies and identifying suspicious patterns before they manifest as confirmed attacks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where security agents collect data from devices, analyze it against known parasite signatures and behavioral patterns, and continuously update detection capabilities. The system learns from detected threats and adjusts its detection algorithms, creating a closed-loop security system that improves over time. This feedback loop enables the system to adapt to new parasite variants and attack methods.

Inventive Principle:
Principle #23Feedback

2Reliability

If protection software monitors for damage, then detected attacks can be identified, but detection occurs after damage is inflicted

Engineering Contradiction:
Improveattack detection capabilityVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The security system performs preliminary monitoring and analysis of device behaviors, configurations, and network activities to identify potential threats before they cause damage. By continuously evaluating device profiles and comparing them against security policies and known attack patterns, the system can detect and respond to threats in their early stages, preventing damage rather than detecting it afterward.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system rushes through the detection and response process by implementing real-time monitoring and automated response mechanisms. When a potential threat is detected, the system immediately takes action to contain or eliminate it, skipping the delays associated with traditional post-damage detection methods. This includes automated isolation of compromised devices and rapid deployment of countermeasures.

Inventive Principle:
Principle #21Skipping (Rushing through)

3Adaptability or versatility

If devices are manually configured with network keys, then wireless network access can be provided, but setup is arduous and time consuming

Engineering Contradiction:
Improvewireless network accessVSAvoiddeployment complexity
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The system enables self-service by allowing devices to automatically obtain and configure their own security credentials and network access parameters. When a device joins the wireless network, the security agent automatically retrieves the device profile, evaluates it against security policies, and configures appropriate access rights without requiring manual intervention. This self-configuration process eliminates the need for administrators to manually enter keys and settings for each device.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system introduces an intermediary security agent that mediates between devices and the wireless network infrastructure. This agent automatically manages the authentication and configuration process by communicating with the security policy server, retrieving device profiles, and configuring network access parameters. The intermediary handles the complexity of secure device onboarding, allowing devices to join the network seamlessly without manual key distribution.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If authentication is performed to verify device compliance, then unauthorized access can be prevented, but additional verification steps are required

Engineering Contradiction:
Improveaccess control securityVSAvoidauthentication process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system achieves universality by implementing a multi-functional security agent that combines device monitoring, profile evaluation, authentication, and compliance verification into a single integrated component. This agent performs multiple security functions simultaneously, eliminating the need for separate authentication systems and reducing overall system complexity. The same agent that monitors device behavior also handles authentication and policy enforcement.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system merges authentication with ongoing device monitoring and compliance checking. Instead of treating authentication as a separate step, the system combines it with continuous profile evaluation and security policy verification. This integration allows the system to authenticate devices based on their current compliance status rather than requiring separate credential verification, simplifying the authentication process while maintaining security.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8239917B2Systems and methods for enterprise security with collaborative peer to peer architecture
Publication Date: 2012.08.07 BURSTIQ INC
  • US8239917B2 patent drawing
  • US8239917B2 patent drawing
  • US8239917B2 patent drawing

AI summary

Systems and methods authenticate a device to operate within an enterprise system with an enterprise policy. An agent, installed on the device, analyzes the device to determine profile information of the device. The determined profile information is sent to a type 2 super peer that verifies whether the profile information conforms to the enterprise policy. If the profile information conforms to the enterprise policy, an agent trust credential is generated, within the type 2 super peer, for the agent, based upon the profile information, and issued to the agent. Authenticity of the device is verified based upon the agent trust credential. If the device is authenticated, communications with the device are permitted. If the device is not authenticated, communications with the device is prevented. In another embodiment, a method restores a device to conform to a system policy. A snapshot of critical components of the device is taken while the device is in compliance with the system policy. The critical components are monitored to identify critical components that differ from the critical components of the snapshot. If differing critical components are detected, the device is restored to conform with system policy by replacing differing critical components based upon the snapshot.