Remote Management System Dynamic Policy Deployment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional management systems fail to dynamically update security policies for information handling systems in response to changes in context, such as network connections, physical locations, and security postures, leading to vulnerabilities and reduced user productivity.

Innovation Solution

A system comprising information handling systems (IHSs) managed by a remote management system (RMS), where IHSs monitor contextual changes and transmit notifications to the RMS, which selects and applies appropriate policy sets, including more restrictive policies when necessary, to ensure security and productivity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If initial policies are applied to IHS when first registered, then security requirements are met, but policies remain static over the system's lifetime until manual updates, reducing adaptability to context changes

Engineering Contradiction:
Improvesecurity requirements conformanceVSAvoidpolicy adaptability to context changes
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic policy management by enabling the RMS to automatically update and deploy new policies to IHS in real-time based on changing contextual factors such as network conditions, device state, and security threats, transforming the static policy application model into a dynamic one that adapts continuously

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system establishes a feedback loop where the RMS continuously monitors contextual changes and IHS status, receives notifications from policy enforcement engines, and automatically selects and deploys appropriate policies, creating a closed-loop control system that responds to changing conditions

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If manual policy updates are performed by system administrators, then policy changes can be applied, but this increases operational complexity and response time

Engineering Contradiction:
Improvepolicy update capabilityVSAvoidmanual management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system implements self-service automation where the RMS autonomously monitors contextual changes, selects appropriate policies from the policy repository, and deploys them to IHS without requiring manual administrator intervention, eliminating operational complexity while maintaining policy update capability

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The RMS performs preliminary actions by proactively monitoring contextual factors and preparing policy updates before security incidents occur, automatically selecting and deploying preventive policies based on predicted or detected changes in device context or threat landscape

Inventive Principle:
Principle #10Preliminary action

3Device complexity

If static policies are applied to IHS throughout its lifetime, then system simplicity is maintained, but security vulnerabilities arise when contextual changes occur

Engineering Contradiction:
Improvepolicy management simplicityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The system uses feedback mechanisms where the RMS continuously receives notifications from policy enforcement engines about contextual changes and IHS status, automatically selecting and deploying updated policies to address security vulnerabilities without increasing operational complexity

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The RMS acts as an intermediary that manages the complexity of dynamic policy selection and deployment, shielding individual IHS from complexity while providing enhanced security through automated context-aware policy updates

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If real-time policy updates are implemented, then security is enhanced through dynamic adaptation, but system complexity increases

Engineering Contradiction:
Improvereal-time policy adaptationVSAvoidpolicy management system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The RMS implements self-service automation that handles the complexity of real-time policy monitoring, selection, and deployment autonomously, enabling dynamic adaptation without proportionally increasing operational complexity through manual processes

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The RMS serves multiple functions including contextual monitoring, policy selection, policy deployment, and enforcement verification within a single integrated platform, consolidating complexity rather than distributing it across multiple separate systems

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10944794B2Real-time policy selection and deployment based on changes in context
Publication Date: 2021.03.09 DELL PROD LP
  • US10944794B2 patent drawing
  • US10944794B2 patent drawing
  • US10944794B2 patent drawing

AI summary

A system is disclosed herein including a plurality of information handling systems (IHSs) coupled to and managed by a remote management system (RMS). According to one embodiment, each IHS may be configured to monitor data pertaining to the IHS, determine if the data triggers one or more events, and transmit a notification to the RMS if one or more events are triggered. The RMS may be configured to receive a notification transmitted from at least one IHS, select a policy to be applied to one or more of the IHSs based on the received notification, and transmit the selected policy to the one or more IHS s. The one or more IHSs may be further configured to receive the selected policy from the RMS, store the selected policy, and perform actions specified by the selected policy when policy rules specified by the selected policy are violated.