Enterprise Security Profile Automation via Network Concordance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The complexity of enterprise security software installation and management in large networks is time- and cost-prohibitive due to the need for detailed security definitions, user-specific permissions, and the lack of simplified control over security policies, making it difficult for administrators to deploy and maintain effective security configurations.

Innovation Solution

An enterprise security management configuration server that associates IP addresses and classifications with profiles, determining common security policies and automatically grouping nodes based on network concordance data, allowing for simplified security policy deployment and management across the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If enterprise security software is deployed with detailed security definitions, user-specific permissions, and encryption policies for each node, then security reliability is improved, but device complexity and deployment time increase significantly

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsoftware complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the enterprise network into multiple profiles based on node characteristics (IP addresses, classifications, network concordance data). Each profile contains a subset of nodes that share common security requirements, allowing security policies to be applied at the profile level rather than individually to each node. This segmentation reduces the complexity of managing security definitions while maintaining comprehensive security coverage across all nodes.

Inventive Principle:
Principle #1Segmentation

2Manufacturing precision

If custom provisioning is performed for each endpoint to meet specific security requirements, then security precision is improved, but deployment time and cost increase prohibitively

Engineering Contradiction:
Improvesecurity configuration precisionVSAvoiddeployment time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The system performs automated profile assignment by evaluating node characteristics (IP addresses, classifications, network concordance data) and automatically adding nodes to appropriate profiles. This self-service mechanism eliminates the need for manual custom provisioning of each endpoint while maintaining precise security configuration matching specific node requirements, dramatically reducing deployment time and cost.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If network security administrators create and deploy detailed security policies manually, then security adaptability to specific network conditions is improved, but ease of operation deteriorates due to required substantial knowledge and training

Engineering Contradiction:
Improvesecurity policy adaptabilityVSAvoidadministration ease
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary system (the enterprise security management system with automated profile assignment) that bridges the gap between network administrators and complex security policy requirements. The system automatically evaluates node characteristics and assigns nodes to appropriate profiles based on network concordance data, enabling administrators to deploy adaptive security policies without requiring substantial knowledge of network specifics or extensive training.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Ease of manufacture

If template images are created and customized for each server or endpoint, then ease of manufacture is improved, but productivity remains low due to required custom provisioning for each endpoint

Engineering Contradiction:
Improveprovisioning easeVSAvoiddeployment productivity
Core Design Contradiction:
Ease of manufactureVSProductivity

Solution Approach 1:

The patent merges the concepts of templating and custom provisioning by creating profiles that represent templates for groups of nodes with similar characteristics. Instead of creating and customizing template images for each individual endpoint, the system creates profile templates that automatically apply to multiple nodes based on their characteristics, combining the ease of template-based provisioning with the efficiency of bulk deployment.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11063982B2Object scope definition for enterprise security management tool
Publication Date: 2021.07.13 UNISYS CORP
  • US11063982B2 patent drawing
  • US11063982B2 patent drawing
  • US11063982B2 patent drawing

AI summary

Methods and systems for configuring a common security policy for a plurality of nodes included within an enterprise network. Example methods can include grouping nodes within profiles based on IP address, in addition to concordance data. Additionally, nodes may be added to profiles based on a classification of the node being common to classifications of nodes within the profile. Still further, profiles may be grouped into a solution based at least in part on classification of the profile, in addition to grouping of profiles into solutions based on affinitization using concordance data. The methods described also include determining a common security policy to apply to each of the nodes within the profile.