Managed Device Policy Strength Clustering for Security Alignment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise mobility management administrators lack guidance on configuring security settings for managed devices, as they cannot access peers' specific security configurations, and aggregated information does not provide actionable insights for aligning settings with industry standards.

Innovation Solution

A system that identifies clusters of managed devices based on policy strength scores and categorizations, providing recommendations or automatically adjusting security settings to align with peer organizations within the same category, ensuring stronger security configurations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If administrators share specific security settings with peer organizations, then administrators can obtain detailed guidance for configuring security settings, but organizations risk exposing their specific security configurations to competitors

Engineering Contradiction:
Improvesecurity settings informationVSAvoidsecurity risk from exposure
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The system extracts only the necessary aggregation level of security settings information (cluster-level statistics) without exposing individual organization's specific configurations. This allows administrators to obtain guidance from peer groups while maintaining confidentiality of their exact security settings.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary aggregation layer that mediates between individual organization security settings and peer comparison needs. The system uses cluster-based aggregation to provide comparative feedback without direct exposure of specific organizational configurations, acting as a protective intermediary.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If aggregated security settings information is provided to administrators, then administrators can see general trends, but the information does not provide specific actionable guidance for aligning with peer organizations

Engineering Contradiction:
Improveaccess to security informationVSAvoidactionable guidance
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The system applies local quality by providing differentiated information at different levels: aggregated cluster-level statistics for general awareness, and specific actionable recommendations tailored to each organization's gap analysis. This allows administrators to receive both broad trends and targeted guidance.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements feedback mechanisms that provide administrators with actionable recommendations based on their organization's security settings compared to peer clusters. The system analyzes gaps and provides specific guidance on what settings to adjust, creating a closed-loop feedback system.

Inventive Principle:
Principle #23Feedback

3Reliability

If administrators manually configure security settings based on best practices, then security can be strengthened, but it requires significant time and expertise

Engineering Contradiction:
Improvesecurity configurationVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-analyzing security settings across multiple organizations to establish cluster-based best practices. This allows individual administrators to receive ready-made recommendations based on peer performance, eliminating the need for them to conduct extensive research and analysis themselves.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables self-service by providing administrators with automated analysis of their security settings and actionable recommendations generated by the system. The automated gap analysis and recommendation engine allows administrators to improve security without requiring deep expertise or significant manual effort.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10931716B2Policy strength of managed devices
Publication Date: 2021.02.23 OMNISSA LLC
  • US10931716B2 patent drawing
  • US10931716B2 patent drawing
  • US10931716B2 patent drawing

AI summary

Various examples for identifying clusters of instances of managed devices within a management service are described. Clusters are identified based upon a policy strength score of the respective instances. The policy strength scores can be generated based upon the security settings of the instance within the management service.