Enterprise Security Policy Generation via Group Ranking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises face challenges in managing and configuring numerous devices with overlapping or conflicting policy requirements, leading to analysis and management complexities in information processing systems.

Innovation Solution

A method that ranks end-user device groups based on priorities and performs partial policy determinations across these groups to dynamically define security-related settings for each device, ensuring all required settings are defined and outputted to the device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If enterprises manage and configure numerous devices with overlapping policy requirements, then device coverage and policy comprehensiveness are improved, but analysis and management complexity increases

Engineering Contradiction:
Improvedevice coverageVSAvoidmanagement complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the policy management process into distinct components: device group definition, policy requirement identification, conflict detection, and resolution. By dividing the complex task of managing overlapping policies into manageable segments, the system reduces overall complexity while maintaining comprehensive device coverage

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary policy management system that acts as a mediator between multiple device groups and their conflicting policies. This intermediary automatically analyzes conflicts, applies resolution rules, and generates unified policy configurations, thereby reducing management complexity without sacrificing policy comprehensiveness

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If enterprises configure different devices according to multiple enterprise needs and policy requirements, then policy compliance is improved, but time and labor requirements increase

Engineering Contradiction:
Improvepolicy complianceVSAvoidconfiguration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-defining device groups with their specific policy requirements before actual device configuration. The system pre-analyzes potential conflicts and pre-determines resolution strategies, so that when devices are assigned to groups, compliance is automatically ensured without time-consuming manual configuration

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables self-service through automated policy assignment and conflict resolution. When devices are added or moved between groups, the system automatically applies the appropriate policies and resolves any conflicts without requiring manual intervention, thereby maintaining high compliance while minimizing time investment

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11050794B2Generating security policies for end-user devices using group rankings and partial policy determinations
Publication Date: 2021.06.29 EMC IP HLDG CO LLC
  • US11050794B2 patent drawing
  • US11050794B2 patent drawing
  • US11050794B2 patent drawing

AI summary

Methods, apparatus, and processor-readable storage media for generating security policies for end-user devices using group rankings and partial policy determinations are provided herein. An example computer-implemented method includes ranking end-user device groups within an enterprise, wherein each of the groups is associated with one or more security-related policy settings; assigning a given end-user device to two or more of the groups based on device parameters attributed to the given end-user device; generating a policy for the given end-user device by performing partial policy determinations across the two or more groups to which the given end-user device is assigned, wherein performing the partial policy determinations comprises defining, in an order based at least in part on the ranking of the groups, security-related settings from the two or more groups, until all security-related settings required by the policy are defined; and outputting the policy to the given end-user device.