Embedding Security Posture in Network Traffic Messages
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for validating mobile device security posture at service nodes result in increased load on device management servers and service delays due to the need for frequent communication to retrieve and verify security information.
Innovation Solution
Embedding security posture information directly into network traffic messages sent from mobile devices to service nodes, allowing the service nodes to extract and analyze this information without relying on device management servers, thereby reducing communication overhead and improving access speeds.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If service nodes retrieve security posture information from device management servers, then security validation can be performed, but server load increases and service delays occur
Solution Approach 1:
Security posture information is embedded in network traffic messages before the service node needs to validate the device. The device includes its security posture information in the network traffic it sends to the service node, eliminating the need for the service node to query the device management server at validation time. This preliminary inclusion of security information resolves the contradiction by enabling fast validation without server queries.
Solution Approach 2:
The network traffic message acts as an intermediary carrier that transports security posture information from the device to the service node. Instead of direct communication between service node and device management server, the security information is embedded in the existing network traffic flow, serving as a mediator that conveys validation data without requiring additional server queries.
2Reliability
If service nodes frequently query device management servers for security information, then security posture can be validated, but communication overhead increases
Solution Approach 1:
The security posture information is extracted from the device management server and embedded directly into the network traffic messages sent by the device. This extraction eliminates the need for repeated queries to the device management server, as the service node receives all necessary security validation information directly within the network traffic flow.
Solution Approach 2:
The device autonomously includes its own security posture information in the network traffic it sends to the service node. This self-service approach allows the device to provide its validation data without external queries, eliminating communication overhead with the device management server while maintaining reliable security validation.
Data Source
AI summary
Embedding security posture in network traffic is disclosed. Security posture information is received. The security posture information is embedded into a message. The message including the security posture information is sent from a mobile device to a service node. The service node uses the security posture information to validate the mobile device to access a service. The service accesses the service based at least in part on the validation.


