Management Platform for Automated Security Configuration Deployment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises face challenges in implementing and maintaining security policies across computing devices due to high costs, resource constraints, and the risk of security breaches from improper implementations, exacerbated by the potential loss of institutional knowledge when IT resources leave the organization.

Innovation Solution

A system and method that utilize a management platform to deploy and validate security configurations on computing devices, allowing for customizable security policies, automatic compliance enforcement, and real-time reporting, without requiring extensive IT resources, using a pre-built library of configurations and a local agent for ongoing compliance monitoring.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If enterprises internally institute security policies and create custom security software, then security compliance can be tailored to specific enterprise needs, but the cost and resource requirements increase significantly

Engineering Contradiction:
Improvecustomizability of security policiesVSAvoidcomplexity of security software development and maintenance
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a management platform as an intermediary between security policy creators and computing devices. This platform provides pre-built configuration templates and automated deployment capabilities, allowing enterprises to implement customized security policies without building complex security software from scratch. The platform mediates between the need for customization and the complexity of implementation by offering configurable templates that can be adapted to specific enterprise needs while automating the deployment and compliance validation processes.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If enterprises use internal IT resources to build and maintain security software, then control over security implementations is improved, but the burden on finite IT resources increases

Engineering Contradiction:
Improvecontrol over security implementationsVSAvoidIT resource efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements self-service capabilities where computing devices automatically retrieve, apply, and validate their own security configurations from the management platform. Local agents on devices autonomously check compliance status and report back without requiring manual intervention from IT staff. This self-service approach maintains enterprise control over security policies while significantly reducing the ongoing maintenance burden on IT resources, as the system automatically handles deployment updates and compliance monitoring.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If multiple different security policies are implemented for different computing devices, then security coverage is improved, but the effort and cost in developing security software multiplies

Engineering Contradiction:
Improvecoverage of security policiesVSAvoidease of security software development
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The patent segments security policies into modular configuration templates that can be independently created, stored, and applied to different computing devices. Each template represents a discrete security requirement that can be configured and deployed separately. This segmentation allows enterprises to implement multiple different security policies across various devices without multiplying development effort, as the modular templates can be reused and combined through the management platform's automated deployment system.

Inventive Principle:
Principle #1Segmentation

4Reliability

If security software is updated over time to address new vulnerabilities, then security effectiveness is improved, but the feasibility of maintaining updates with scarce resources decreases

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidcomplexity of software maintenance
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a dynamic security configuration system where the management platform can automatically update configuration templates in response to new security vulnerabilities or changing requirements. These updates are automatically propagated to computing devices through the existing agent infrastructure. This dynamic approach allows security software to evolve and address new threats over time without requiring manual intervention or complex maintenance processes, as the system automatically retrieves and applies updated configurations from the central platform.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12010151B2Systems and methods for deploying configurations on computing devices and validating compliance with the configurations during scheduled intervals
Publication Date: 2024.06.11 IRU INC
  • US12010151B2 patent drawing
  • US12010151B2 patent drawing
  • US12010151B2 patent drawing

AI summary

Deploying configurations on computing devices and validating compliance with the configurations during scheduled intervals. Particular embodiments described herein include computing devices that send a requests to a management platform at different time periods for lists of configurations that are assigned to those computing devices at those different time periods. Received lists include identifiers of the configurations that are assigned to the those computing devices during the different time periods. Local agents on the computing devices use the received lists to determine if each of the configurations in that list are implemented. If a configuration is not implemented on a computing device, the local agent on that computing device implements that configuration or alerts the management platform that the configuration could not be implemented.