Network Security Enforcement via Host Information Profiles

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current firewalls do not effectively enforce security policies on mobile devices based on device-specific information, such as software updates and installed apps, leading to vulnerabilities in accessing enterprise networks.

Innovation Solution

Implementing a network-based security system that uses Host Information Profiles (HIP) to monitor and enforce security policies on mobile devices, including receiving HIP reports from mobile devices, matching them against configured profiles, and performing actions such as configuring devices or restricting access based on compliance with enterprise policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional firewalls are used to protect enterprise networks, then network access control is provided, but device-specific security conditions (such as software updates and installed apps) cannot be monitored or enforced

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice-specific policy enforcement
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent changes the parameters of firewall policy enforcement from generic network-level rules to device-specific parameters including software version, app installation status, and security configuration states. This allows the firewall to make access decisions based on granular device conditions rather than blanket network policies.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system implements feedback mechanisms where mobile devices report their security state (software updates, installed apps, configuration) to the enterprise network, and the firewall uses this feedback to dynamically enforce or modify access policies. This creates a closed-loop system where security decisions are based on real-time device information.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If security policies are enforced based on device state information, then granular control over mobile device access is achieved, but system complexity increases due to HIP reporting and matching infrastructure

Engineering Contradiction:
Improvesecurity policy controlVSAvoidsecurity system structure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces Host Information Profile (HIP) reports as an intermediary data structure that standardizes device state information. These HIP reports act as a mediator between the mobile device and the enterprise firewall, translating diverse device states into a unified format that can be efficiently processed and matched against security policies.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary actions by pre-defining Host Information Profile templates and security policy rules before actual device access attempts. This allows the firewall to have ready-made matching criteria and enforcement actions prepared in advance, reducing real-time processing complexity when devices attempt to connect.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If Host Information Profiles are used to monitor mobile devices, then compliance with enterprise security standards is ensured, but processing time and computational resources increase

Engineering Contradiction:
Improvepolicy complianceVSAvoidpolicy enforcement processing
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent uses copying by creating simplified replicas of device state information in the form of HIP reports. Instead of analyzing the entire device ecosystem, the system creates compact copies of relevant security attributes (software versions, app lists, configuration states) that can be quickly transmitted and processed without the overhead of comprehensive device monitoring.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10200412B2Security policy enforcement for mobile devices based on device state
Publication Date: 2019.02.05 PALO ALTO NETWORKS INC
  • US10200412B2 patent drawing
  • US10200412B2 patent drawing
  • US10200412B2 patent drawing

AI summary

Techniques for network-based security for mobile devices based on device state are disclosed. In some embodiments, network-based security for mobile devices based on device state includes receiving a Host Information Profile (HIP) report for a mobile device from a mobile device management (MDM) service at the security device, in which the HIP report includes device state information for the mobile device; applying a policy based on the HIP report for the mobile device and the device state; and performing access control at the security device based on the policy based on the HIP report for the mobile device.