Security Policy Prioritization via Device Coefficients

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing device management techniques fail to efficiently respond to changes in the number of user devices connected to a network or their configurations, and they do not provide optimal protection with a limited set of software licenses.

Innovation Solution

A method and system for automatically determining the order of applying security policies to user devices based on available software licenses, where devices are prioritized using a coefficient calculated from various criteria such as user, software, hardware, and location, and security policies are applied accordingly, ensuring optimal protection with limited licenses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security policies are applied to all devices in the network, then the level of protection is improved, but the availability of software licenses is exhausted

Engineering Contradiction:
Improvelevel of protectionVSAvoidavailability of software licenses
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent applies different security policy levels to different devices based on their importance coefficients. High-priority devices receive full security policies while low-priority devices receive reduced or no security policies, allowing limited licenses to be concentrated on critical devices rather than uniformly distributed across all devices.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent segments the device population into priority groups based on coefficients calculated from multiple criteria (device type, user role, data sensitivity, etc.). This segmentation enables differential license allocation where licenses are assigned to specific priority groups rather than being universally applied, resolving the contradiction between comprehensive protection and license availability.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If manual management of user devices is performed, then the control precision is improved, but the device complexity increases

Engineering Contradiction:
Improvecontrol precisionVSAvoiddevice complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system automatically calculates device coefficients and determines security policy assignments without requiring manual administrator intervention. The automated system evaluates multiple criteria (device type, user role, data sensitivity, location) and autonomously prioritizes devices, maintaining precise control while eliminating the complexity of manual management of numerous diverse devices.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent transforms the management approach by introducing a calculated priority coefficient as a new parameter that automatically determines policy assignment. Instead of manually configuring each device, the system uses this derived parameter to automatically stratify devices into priority groups, simplifying management while maintaining precise control over security policy application.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If security policies are applied uniformly to all devices, then the ease of operation is improved, but the adaptability to device changes deteriorates

Engineering Contradiction:
Improveease of operationVSAvoidadaptability to device changes
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent implements a dynamic security policy assignment system where device priority coefficients are continuously evaluated and updated based on changing conditions (new devices, user role changes, data sensitivity changes). The system automatically adapts policy assignments as devices are added or modified, maintaining both ease of operation through automation and adaptability to changes without requiring manual reconfiguration.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9294510B2System and method for automatic control of security policies based on available software licenses
Publication Date: 2016.03.22 AO KASPERSKY LAB
  • US9294510B2 patent drawing
  • US9294510B2 patent drawing
  • US9294510B2 patent drawing

AI summary

Disclosed are system, methods, and computer program product for applying security policies based on available licenses to a plurality of devices. An example method includes determining, by a processor, one or more criteria for a device relating to a priority of the device in the network for application of the security policies; determining numeric values for each of the one of more criteria; determining a coefficient for the device based on the numeric values; determining the priority of the device based on the coefficient of the device and respective coefficients of the plurality of devices; designating a security policy for the device based on the priority of the device; determining availability of a license for a software applying the designated security policy to the device; and when the license for the software that applies the designated security policy is available, applying the designated security polity to the device.