PC Security Configuration Management via Automated Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional PC-security check programs only output vulnerability check results, leaving users to manually configure security settings across a network, which is inefficient and dependent on individual user knowledge, failing to collectively manage security configurations.

Innovation Solution

An apparatus and method that includes a check module to assess PC security configurations based on a received policy and a control module to automatically adjust these settings according to a control policy, managed by a security check server, enabling centralized management and configuration of security settings across multiple PCs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If conventional PC-security check programs only output vulnerability check results, then users can see security status, but users must manually configure security settings which is inefficient and dependent on individual user knowledge

Engineering Contradiction:
Improvesecurity configuration informationVSAvoidmanual security configuration
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The control module automatically performs security configuration changes based on check results and control policies, enabling the system to self-correct security vulnerabilities without requiring user intervention or manual configuration actions

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements a closed-loop feedback mechanism where check results are automatically analyzed and fed back to the control module, which then adjusts security configurations accordingly, creating a continuous improvement cycle for security management

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If users manually configure security settings, then individual PC security can be adjusted, but centralized management of security configurations across the network is not achieved

Engineering Contradiction:
Improvesecurity configuration flexibilityVSAvoidnetwork security management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system divides security management into two independent modules: a check module that assesses security status and a control module that implements configuration changes. This segmentation allows centralized management while maintaining the flexibility of individual PC security settings through policy-based control

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The control module acts as an intermediary between the check module and the operating system security settings. It receives check results, applies control policies, and automatically adjusts security configurations, thereby centralizing management without requiring direct user intervention at each PC

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If security configuration depends on user's manual setting, then user control is maintained, but the level of PC security is determined according to user's security knowledge which varies

Engineering Contradiction:
Improvesecurity configuration accessibilityVSAvoidsecurity configuration consistency
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system changes the fundamental parameter of security configuration from user-dependent manual settings to automated policy-driven configurations. Control policies define standardized security parameters that are consistently applied across all PCs, eliminating variability based on user knowledge while maintaining accessibility through automatic operation

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8234711B2Apparatus and method for checking PC security
Publication Date: 2012.07.31 ELECTRONICS & TELECOMM RES INST
  • US8234711B2 patent drawing
  • US8234711B2 patent drawing
  • US8234711B2 patent drawing

AI summary

Provided are an apparatus and method for checking Personal Computer (PC) security. The apparatus includes a check module for checking a security configuration of a PC on the basis of a check policy received from a security check server and outputting check results, and a control module for changing the security configuration of the PC on the basis of a control policy received from the security check server and the check results received from the check module. According to the apparatus, a security check agent installed in each PC performs security check and changes a security configuration according to a control policy, such that the security configurations of PCs in a network can be managed collectively.