Network Security System for Mobile Device Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current firewalls do not effectively enforce security policies on mobile devices based on device-specific information, such as software updates and installed applications, leading to potential security breaches when accessing enterprise networks.

Innovation Solution

Implementing a network-based security system that uses Host Information Profiles (HIP) to monitor and enforce policies on mobile devices, including receiving HIP reports from mobile devices, matching them against configured profiles, and performing actions such as removing malware or enforcing encryption based on device state.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional firewalls are used to filter network traffic, then basic network security is provided, but device-specific security policies cannot be enforced on mobile devices

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoiddevice-specific policy adaptation
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent changes the parameters of firewall filtering from generic network traffic parameters to device-specific parameters including software version, installed applications, and device state information. This allows the firewall to enforce security policies based on specific device characteristics rather than applying uniform rules to all devices.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system implements feedback mechanisms where mobile devices report their state information (software updates, installed applications) to the network-based security system. The security system processes this feedback and dynamically adjusts security policies and firewall rules based on the current device state, creating a closed-loop control system.

Inventive Principle:
Principle #23Feedback

2Reliability

If manual security policy configuration is used for mobile devices, then security control is possible, but it is time-consuming and difficult to maintain

Engineering Contradiction:
Improvesecurity complianceVSAvoidpolicy configuration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Mobile devices automatically report their own state information (software versions, installed applications, security settings) to the network-based security system without requiring manual intervention. The security system automatically processes this information and applies appropriate policies, enabling self-service security management.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system pre-configures security policies based on potential device states and automatically matches reported device information against these pre-defined policies. This preliminary preparation of policy frameworks enables rapid automatic enforcement without time-consuming manual configuration for each device.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If comprehensive device monitoring is implemented to enforce security policies, then security compliance is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity policy complianceVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a network-based security system as an intermediary between mobile devices and the corporate network. This intermediary collects device state information, processes security policy compliance, and manages firewall rules, thereby simplifying the architecture compared to implementing complex monitoring and enforcement mechanisms directly on each mobile device.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Speed

If automatic configuration based on device state is implemented, then security response time is improved, but information processing requirements increase

Engineering Contradiction:
Improvesecurity policy application speedVSAvoiddevice state information
Core Design Contradiction:
SpeedVSQuantity of substance

Solution Approach 1:

The system extracts only the critical device state information necessary for security policy enforcement (software versions, installed applications, key security settings) from the complete device state. This selective extraction reduces the volume of information that needs to be processed while maintaining the effectiveness of automatic security configuration.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10104128B2Automatically configuring mobile devices and applying policy based on device state
Publication Date: 2018.10.16 PALO ALTO NETWORKS INC
  • US10104128B2 patent drawing
  • US10104128B2 patent drawing
  • US10104128B2 patent drawing

AI summary

Techniques for network-based security for mobile devices based on device state are disclosed. In some embodiments, automatically configuring mobile devices and applying policies based on a Host Information Profile (HIP) report includes receiving a Host Information Profile (HIP) report for a mobile device; performing a policy match based on the HIP report for the mobile device; and performing an action based on the policy match based on the HIP report for the mobile device.