Secure Configuration for Managed Nodes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for managing and protecting sensitive information on computer networks are inadequate, as they fail to efficiently prevent unauthorized access, deletion, or transfer of data, especially in scenarios like employee termination or malware detection, while maintaining system operability.

Innovation Solution

A secure configuration is deployed on managed nodes that disables functionality compromising sensitive data, such as modifying, deleting, or copying, while allowing read-only access and maintaining system operability, using administrative systems, management servers, data security clients, and triggers to monitor events and apply configurations remotely or locally.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current security systems are used to protect sensitive information, then data security is maintained to some extent, but system operability is compromised and productivity decreases due to freezing or locking the system

Engineering Contradiction:
Improvedata securityVSAvoidsystem operability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies dynamics by transitioning the system from a static frozen state to a dynamic read-only state. The secure configuration dynamically restricts write operations while maintaining read access and system operability, allowing the system to remain functional rather than being completely locked. This resolves the contradiction by making the security measure adaptable rather than absolute.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent segments the system operations into read operations (allowed) and write operations (restricted). By dividing the operational capabilities into these distinct segments, the system can maintain read access for productivity while restricting write access for security, thus resolving the contradiction between system operability and data security.

Inventive Principle:
Principle #1Segmentation

2Reliability

If a secure configuration is applied to prevent data compromise, then data security is improved, but system flexibility and ease of operation deteriorate

Engineering Contradiction:
Improvedata securityVSAvoidsystem flexibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies local quality by implementing security restrictions specifically at the data protection level rather than system-wide. The secure configuration locally restricts write operations to protected data while leaving other system functions unaffected, maintaining ease of operation for non-protected activities while ensuring data security.

Inventive Principle:
Principle #3Local quality

3Reliability

If read-only access is granted to maintain security, then data protection is improved, but the ability to modify and update data is lost

Engineering Contradiction:
Improvedata protectionVSAvoiddata modification capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent resolves this contradiction by making the read-only restriction dynamic rather than permanent. The secure configuration can be applied temporarily based on triggers (e.g., employee termination, malware detection) and removed when no longer needed, allowing data modification capability to be restored. This dynamic approach maintains data protection when needed while preserving adaptability when the threat is gone.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9552491B1Systems and methods for securing data
Publication Date: 2017.01.24 IVANTI INC
  • US9552491B1 patent drawing
  • US9552491B1 patent drawing
  • US9552491B1 patent drawing

AI summary

Systems and methods for securing data are disclosed. An administrative system may create a secure configuration. The secure configuration may disable functionality of a managed node that compromises sensitive data. However, the secure configuration may not prevent all user access to the managed node. The administrative system may deploy the secure configuration to at least one managed node. The administrative system may cause the secure configuration to be applied to the at least one managed node.