Enterprise Security Configuration Server Simplifies Policy Deployment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The complexity of enterprise security software makes it time- and cost-prohibitive to install and fully exploit its capabilities across large networks, particularly due to the need for detailed security definitions and user permissions, which can be overwhelming for network security administrators.

Innovation Solution

A method and system for an enterprise security management configuration server that groups nodes into profiles based on network concordance data, automatically identifies solutions, and collapses them into single icons in a user interface, simplifying the configuration process by allowing for graphical grouping and simplification of security settings.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If enterprise security software is deployed across large networks with detailed security definitions and user permissions, then security level is improved, but installation time and cost increase significantly

Engineering Contradiction:
Improvesecurity levelVSAvoidinstallation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the enterprise network into multiple zones with different security requirements. Each zone can be configured independently with appropriate security policies, allowing phased deployment rather than requiring network-wide installation at once. This reduces the overall installation time and cost while maintaining high security levels in critical areas.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by providing automated security policy generation and template-based configurations. Security administrators can pre-configure security policies and user permissions using standardized templates, which are then automatically deployed across the network. This eliminates the time-consuming manual configuration process while maintaining comprehensive security coverage.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If detailed security definitions and user permissions are configured for each user and system, then security control is improved, but configuration complexity increases

Engineering Contradiction:
Improvesecurity controlVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements universality by creating reusable security policy templates and role-based access control configurations. A single security policy template can be applied across multiple users and systems with similar requirements, eliminating the need to configure each user and system individually. This maintains comprehensive security control while dramatically reducing configuration complexity through standardized, multi-functional templates.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent enables self-service by allowing users to automatically receive appropriate security permissions based on their role and the security policies configured for their department or function. The system automatically assigns and manages user permissions without requiring manual intervention from administrators for each user, reducing configuration complexity while maintaining detailed security control.

Inventive Principle:
Principle #25Self-service

3Manufacturing precision

If custom provisioning is performed for each endpoint, then security policy accuracy is improved, but deployment time increases

Engineering Contradiction:
Improvesecurity policy accuracyVSAvoiddeployment speed
Core Design Contradiction:
Manufacturing precisionVSProductivity

Solution Approach 1:

The patent implements copying by using standardized security policy templates that can be replicated across multiple endpoints. Instead of manually configuring each endpoint from scratch, administrators create a master security policy configuration that is then automatically copied and applied to all endpoints in a zone or department. This maintains security policy accuracy through consistent templating while enabling rapid deployment across the entire network.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent merges individual endpoint configurations into centralized security policy groups. Multiple endpoints with similar security requirements are combined into single policy groups, allowing a single configuration to apply to all members. This maintains accurate security policies for each endpoint while dramatically reducing deployment time through batch processing and centralized management.

Inventive Principle:
Principle #5Merging (Combining)

4Adaptability or versatility

If network security administrators create and deploy security policies manually, then policy customization is improved, but training requirements and implementation time increase

Engineering Contradiction:
Improvepolicy customizationVSAvoidease of deployment
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary layer in the form of automated policy generation tools and templates. These intermediaries translate high-level security requirements into detailed, ready-to-deploy security policies. Administrators can specify customization parameters through simple forms or templates, and the system automatically generates the detailed policy configurations. This maintains policy customization capabilities while eliminating the need for extensive administrator training and manual configuration work.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10979455B2Solution definition for enterprise security management
Publication Date: 2021.04.13 UNISYS CORP
  • US10979455B2 patent drawing
  • US10979455B2 patent drawing
  • US10979455B2 patent drawing

AI summary

Methods and systems for defining a solution within an enterprise security management configuration server is disclosed. One method includes, based on network concordance data, grouping a plurality of nodes within an enterprise network into a plurality of profiles and identifying one or more channels among the plurality of profiles within a project of an enterprise security management configuration tool. The method also includes displaying the plurality of profiles in a configuration user interface, and automatically identifying one or more solutions among the plurality of profiles. The method further includes collapsing each of the one or more solutions into a single icon within the configuration user interface, each single icon representing a solution.