Security Policy Prioritization via Device Coefficients
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing device management techniques fail to efficiently respond to changes in the number of user devices connected to a network or their configurations, and they do not provide optimal protection with a limited set of software licenses.
Innovation Solution
A method and system for automatically determining the order of applying security policies to user devices based on available software licenses, where devices are prioritized using a coefficient calculated from various criteria such as user, software, hardware, and location, and security policies are applied accordingly, ensuring optimal protection with limited licenses.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security policies are applied to all devices in the network, then the level of protection is improved, but the availability of software licenses is exhausted
Solution Approach 1:
The patent applies different security policy levels to different devices based on their importance coefficients. High-priority devices receive full security policies while low-priority devices receive reduced or no security policies, allowing limited licenses to be concentrated on critical devices rather than uniformly distributed across all devices.
Solution Approach 2:
The patent segments the device population into priority groups based on coefficients calculated from multiple criteria (device type, user role, data sensitivity, etc.). This segmentation enables differential license allocation where licenses are assigned to specific priority groups rather than being universally applied, resolving the contradiction between comprehensive protection and license availability.
2Measurement precision
If manual management of user devices is performed, then the control precision is improved, but the device complexity increases
Solution Approach 1:
The system automatically calculates device coefficients and determines security policy assignments without requiring manual administrator intervention. The automated system evaluates multiple criteria (device type, user role, data sensitivity, location) and autonomously prioritizes devices, maintaining precise control while eliminating the complexity of manual management of numerous diverse devices.
Solution Approach 2:
The patent transforms the management approach by introducing a calculated priority coefficient as a new parameter that automatically determines policy assignment. Instead of manually configuring each device, the system uses this derived parameter to automatically stratify devices into priority groups, simplifying management while maintaining precise control over security policy application.
3Ease of operation
If security policies are applied uniformly to all devices, then the ease of operation is improved, but the adaptability to device changes deteriorates
Solution Approach 1:
The patent implements a dynamic security policy assignment system where device priority coefficients are continuously evaluated and updated based on changing conditions (new devices, user role changes, data sensitivity changes). The system automatically adapts policy assignments as devices are added or modified, maintaining both ease of operation through automation and adaptability to changes without requiring manual reconfiguration.
Data Source
AI summary
Disclosed are system, methods, and computer program product for applying security policies based on available licenses to a plurality of devices. An example method includes determining, by a processor, one or more criteria for a device relating to a priority of the device in the network for application of the security policies; determining numeric values for each of the one of more criteria; determining a coefficient for the device based on the numeric values; determining the priority of the device based on the coefficient of the device and respective coefficients of the plurality of devices; designating a security policy for the device based on the priority of the device; determining availability of a license for a software applying the designated security policy to the device; and when the license for the software that applies the designated security policy is available, applying the designated security polity to the device.


