Management Platform for Automated Security Configuration Deployment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprises face challenges in implementing and maintaining security policies across computing devices due to high costs, resource constraints, and the risk of security breaches from improper implementations, exacerbated by the potential loss of institutional knowledge when IT resources leave the organization.
Innovation Solution
A system and method that utilize a management platform to deploy and validate security configurations on computing devices, allowing for customizable security policies, automatic compliance enforcement, and real-time reporting, without requiring extensive IT resources, using a pre-built library of configurations and a local agent for ongoing compliance monitoring.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If enterprises internally institute security policies and create custom security software, then security compliance can be tailored to specific enterprise needs, but the cost and resource requirements increase significantly
Solution Approach 1:
The patent introduces a management platform as an intermediary between security policy creators and computing devices. This platform provides pre-built configuration templates and automated deployment capabilities, allowing enterprises to implement customized security policies without building complex security software from scratch. The platform mediates between the need for customization and the complexity of implementation by offering configurable templates that can be adapted to specific enterprise needs while automating the deployment and compliance validation processes.
2Reliability
If enterprises use internal IT resources to build and maintain security software, then control over security implementations is improved, but the burden on finite IT resources increases
Solution Approach 1:
The patent implements self-service capabilities where computing devices automatically retrieve, apply, and validate their own security configurations from the management platform. Local agents on devices autonomously check compliance status and report back without requiring manual intervention from IT staff. This self-service approach maintains enterprise control over security policies while significantly reducing the ongoing maintenance burden on IT resources, as the system automatically handles deployment updates and compliance monitoring.
3Adaptability or versatility
If multiple different security policies are implemented for different computing devices, then security coverage is improved, but the effort and cost in developing security software multiplies
Solution Approach 1:
The patent segments security policies into modular configuration templates that can be independently created, stored, and applied to different computing devices. Each template represents a discrete security requirement that can be configured and deployed separately. This segmentation allows enterprises to implement multiple different security policies across various devices without multiplying development effort, as the modular templates can be reused and combined through the management platform's automated deployment system.
4Reliability
If security software is updated over time to address new vulnerabilities, then security effectiveness is improved, but the feasibility of maintaining updates with scarce resources decreases
Solution Approach 1:
The patent implements a dynamic security configuration system where the management platform can automatically update configuration templates in response to new security vulnerabilities or changing requirements. These updates are automatically propagated to computing devices through the existing agent infrastructure. This dynamic approach allows security software to evolve and address new threats over time without requiring manual intervention or complex maintenance processes, as the system automatically retrieves and applies updated configurations from the central platform.
Data Source
AI summary
Deploying configurations on computing devices and validating compliance with the configurations during scheduled intervals. Particular embodiments described herein include computing devices that send a requests to a management platform at different time periods for lists of configurations that are assigned to those computing devices at those different time periods. Received lists include identifiers of the configurations that are assigned to the those computing devices during the different time periods. Local agents on the computing devices use the received lists to determine if each of the configurations in that list are implemented. If a configuration is not implemented on a computing device, the local agent on that computing device implements that configuration or alerts the management platform that the configuration could not be implemented.


