Host-Based Device Management System for Enterprise Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The rapid introduction of new devices poses a threat to data security, as existing device management systems struggle to enforce security policies and prevent unauthorized device connections, leading to potential data loss and malicious intrusions.

Innovation Solution

A method and system for enterprise device management that uses host-based agents and rule-based policies to monitor and control device connections, allowing administrators to set policies for forbidden devices, detect unknown devices, and enforce security protocols by blocking or limiting access based on predefined rules and parameters.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If generic device management is implemented to manage unfamiliar devices, then adaptability to new devices is improved, but device complexity increases due to the need for rule-based policies and parameter evaluation

Engineering Contradiction:
Improveadaptability to new devicesVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The device management system implements a universal rule-based policy framework that can manage any device type through generic parameters (vendor ID, product ID, device class) rather than device-specific management logic. The software agent evaluates device parameters against predefined rules to determine appropriate reactions, making the system adaptable to unfamiliar devices without requiring device-specific programming.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system manages device diversity by evaluating and comparing device parameters (vendor ID, product ID, device class, serial number) against policy rules. By changing the management approach from device-specific to parameter-based evaluation, the system achieves adaptability to new devices while maintaining a consistent management framework that does not significantly increase complexity.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If security policies are enforced to prevent unauthorized devices, then data security is improved, but ease of operation deteriorates due to restricted device access

Engineering Contradiction:
Improvedata securityVSAvoiddevice access convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary evaluation of device parameters against security policies before allowing device access. The software agent detects device connection, retrieves parameters, and evaluates them against predefined rules to determine the reaction (allow, block, or limit access) before the device can access organizational resources. This preliminary security check ensures data security while maintaining ease of operation for authorized devices.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system provides feedback to users about device connection status and policy violations. When a device connects, the software agent evaluates it against security policies and communicates the outcome to the user and administrator. This feedback mechanism maintains security by enforcing policies while informing users about the status of their device connections, reducing confusion and improving operational clarity.

Inventive Principle:
Principle #23Feedback

3Reliability

If device monitoring and blocking capabilities are implemented, then data security is improved, but productivity decreases due to additional monitoring overhead

Engineering Contradiction:
Improvedata securityVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system implements partial monitoring by evaluating only the necessary device parameters (vendor ID, product ID, device class, serial number) against security policies, rather than进行全面 analysis of all device functions. The software agent performs selective parameter retrieval and evaluation, blocking only the specific reactions that violate policies while allowing legitimate device operations to proceed. This partial action approach maintains data security through targeted monitoring while minimizing productivity impact by avoiding excessive analysis of authorized devices.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS8484327B2Method and system for generic real time management of devices on computers connected to a network
Publication Date: 2013.07.09 MAGENTA SECURITY HOLDINGS LLC
  • US8484327B2 patent drawing
  • US8484327B2 patent drawing
  • US8484327B2 patent drawing

AI summary

A method and system for enterprise device management allows the administrator to set a policy of forbidden devices, monitor devices used in the organization, provide alerts and notification incase an unknown device is connected to a computer, and monitor or block connections of devices which do not comply with the said security policy. A method for device management in a computer system comprises detecting connection of a device to the computer system and determining a reaction to perform in response to the connection of the device to the computer system based on parameters related to the device and on device management rules.