Unmanaged Device Security via Network Intermediary Test Links

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Providing effective security services to unmanaged devices is challenging due to their connection to multiple networks and lack of control by business administrators, as existing solutions struggle to enforce security policies and manage data routing effectively.

Innovation Solution

A communication system that uses a reverse proxy to intercept interactions, insert test links, and enforce security policies by routing traffic through a network services platform, which coaches users to configure their devices to meet desired security standards, and takes remedial actions if non-compliant.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security policies are enforced on unmanaged devices, then network security is improved, but device complexity and user control are worsened

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a network service platform as an intermediary between unmanaged devices and the network. This platform intercepts device interactions, inserts test links, and enforces security policies without requiring direct modification of the unmanaged device. The intermediary handles the complexity of security enforcement while keeping the end device simple and user-friendly.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security enforcement system is segmented into separate functional components: a network service platform that handles policy enforcement, a reverse proxy that intercepts traffic, and a test link insertion mechanism. This segmentation allows security policies to be enforced at the network layer rather than requiring complex device-level configurations.

Inventive Principle:
Principle #1Segmentation

2Reliability

If traffic is routed through a network services platform, then security policy enforcement is improved, but network latency and complexity are worsened

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidnetwork latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-configuring test links and security policies in the network service platform before actual device interactions occur. This allows the platform to quickly match and enforce appropriate security policies without real-time analysis delays, reducing latency while maintaining enforcement effectiveness.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If unmanaged devices are monitored and classified, then network security visibility is improved, but privacy concerns and user control are worsened

Engineering Contradiction:
Improvenetwork security visibilityVSAvoiduser control
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements self-service mechanisms where devices automatically undergo classification and testing through the network service platform. The classification process is transparent and automated, with devices being evaluated based on their interactions with test links rather than requiring manual user input or revealing sensitive user information.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11641355B2Security service for an unmanaged device
Publication Date: 2023.05.02 SKYHIGH SECURITY LLC
  • US11641355B2 patent drawing
  • US11641355B2 patent drawing
  • US11641355B2 patent drawing

AI summary

Particular embodiments described herein provide for a network element that can be configured to receive, from an electronic device, a request to access a network service. In response to the request, the network element can send data related to the network service to the electronic device and add a test link to the data related to the network service. The network element can also be configured to determine if the test link was successfully executed and classify the electronic device as untrusted if the test link was not successfully executed.