Centralized Security Configuration Service for Multi-Device Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing diversity of personal computing devices, such as desktops, smartphones, and tablets, poses challenges in managing and configuring their security and application settings uniformly, as different devices have varying hardware and software capabilities, making it difficult for individuals to ensure consistent security policies across multiple devices.

Innovation Solution

A computer-implemented configuration service that hosts a user interface for selective adjustment of security and application settings, maintaining mappings of security objectives to tasks and devices, and generating configuration instructions based on device capabilities to ensure consistent security and operational objectives across diverse computing devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security settings are configured separately on each device, then device-specific security requirements can be met, but user management time and complexity increase significantly

Engineering Contradiction:
Improvesecurity configurationVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the configuration management into two parts: a centralized service that handles high-level security policy definition and device capability assessment, and local components that handle device-specific implementation. This segmentation allows security settings to be defined once centrally while automatically adapting to each device's specific requirements, reducing configuration time while maintaining security reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary actions by automatically assessing device capabilities and pre-determining appropriate security configurations before actual deployment. The centralized service evaluates each device's hardware and software characteristics in advance, pre-configures suitable security policies, and then deploys them automatically, eliminating the need for manual configuration on each device.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If uniform security policies are applied across all devices, then configuration simplicity is improved, but device capability constraints cannot be accommodated

Engineering Contradiction:
Improveconfiguration simplicityVSAvoiddevice capability adaptation
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent applies local quality by enabling the centralized service to define uniform security policies at the highest level, then automatically adapt these policies to local device characteristics. Each device receives a customized configuration that maintains the core security objectives while adjusting implementation details to match device-specific capabilities, thus achieving both simplicity and adaptability.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system changes parameters dynamically by adjusting security configuration parameters based on device capability assessments. The centralized service modifies configuration parameters such as heuristic analysis settings, virtual environment allocation, and resource allocation according to each device's processing power, memory, and available security modules, allowing uniform policies to be adapted to diverse device constraints.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If resource-intensive security operations like heuristic analysis are performed on all devices, then security coverage is improved, but device performance and battery life deteriorate

Engineering Contradiction:
Improvesecurity coverageVSAvoiddevice energy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies partial action by enabling resource-intensive security operations only on devices that have the necessary capabilities. The centralized service assesses each device's processing power, memory, and battery status, then selectively enables features like heuristic analysis and virtual environment execution only on devices that can handle them without excessive energy consumption, while providing alternative security mechanisms for resource-constrained devices.

Inventive Principle:
Principle #16Partial or excessive action

4Reliability

If device-specific security configurations are implemented, then security effectiveness is improved, but system complexity and coordination difficulty increase

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidconfiguration management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The centralized service acts as an intermediary between security policy definition and device-specific implementation. It receives high-level security requirements, assesses device capabilities, determines appropriate configurations, and automatically deploys them to individual devices. This intermediary eliminates the need for users to manually coordinate configurations across multiple devices, maintaining security effectiveness while reducing management complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2819377B1Multi-platform operational objective configurator for computing devices
Publication Date: 2018.09.05 AO KASPERSKY LAB
  • EP2819377B1 patent drawingFigure 1
  • EP2819377B1 patent drawingFigure 2
  • EP2819377B1 patent drawingFigure 3

AI summary

Application configuration settings are managed for a plurality of diverse computing devices having different resources including independent applications. An operational objective defining certain behaviors for a plurality of applications executable on computing devices is received via a user input. Configuration and resource information is obtained for each computing device. A determination is made of applications on each of the computing devices for which the specified operational objective can be at least partially achieved. The determination is based on the user input, on the configuration and resource information for each of the computing devices, and on a predefined set of resource mappings that defines requirements for meeting various operational objectives and resources needed for meeting each of the requirements. Configuration instructions particularized to one or more of the computing devices is generated in response to the determination that the operational objective can be at least partially achieved.