Managing Unpatched User Devices via Virtual Machine Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users with outdated browsers or unpatched devices are susceptible to malware, posing a security risk for both themselves and financial institution networks when attempting to access their accounts.

Innovation Solution

A management system that checks the security status of user devices before granting access, offering updates or redirecting to a virtual machine to protect against malware, ensuring the device is up to date and secure before allowing network access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users access networks without security checks, then ease of access is improved, but network security deteriorates

Engineering Contradiction:
Improveease of accessVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary security checks of user devices before granting network access. The management system checks whether user devices are up to date with security patches and browser updates, and only allows access if the device passes the security check or if the user consents to the security risk

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The management system acts as an intermediary between users and the network. It mediates by checking device security status, offering updates, and controlling access rights based on the security assessment results

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If users are forced to update software, then network security is improved, but user convenience deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system provides self-service update mechanisms where users can voluntarily update their browsers and software through the management system. Users are notified of security updates and can choose to install them without manual intervention from the system administrator

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The access control policy is dynamic rather than static. The system adjusts access rights based on real-time security status of user devices, allowing flexible adaptation to different user situations and security levels

Inventive Principle:
Principle #15Dynamics

3Adaptability or versatility

If unpatched devices are allowed access, then user accessibility is improved, but malware transfer risk increases

Engineering Contradiction:
Improveuser accessibilityVSAvoidmalware transfer risk
Core Design Contradiction:
Adaptability or versatilityVSObject-generated harmful factors

Solution Approach 1:

The system takes preliminary anti-action by detecting unpatched devices and unsecured browsers before they can access the network. The management system identifies security vulnerabilities and prevents access or offers remediation measures to eliminate the harmful factors

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The management system serves as a protective intermediary that sits between unsecured user devices and the network. It monitors device security status and controls access to prevent malware from transferring to the network while still allowing legitimate users to access services

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11038918B1Managing unpatched user devices
Publication Date: 2021.06.15 WELLS FARGO BANK NA
  • US11038918B1 patent drawing
  • US11038918B1 patent drawing
  • US11038918B1 patent drawing

AI summary

The innovation disclosed and claimed herein, in one aspect thereof, comprises a management system and method of handling unpatched users. When a user requests to access their user account or a network, the user is checked for type of browser the user is being used and which version of the browser is being used. If the user is using an unsecured or unpatched browser, the system offers to update the browser software or provide a virtual machine through the browser so that malware cannot transfer from the user computer to the network. The virtual machine can provide a virtual keyboard to protect the user's login credentials from a key logger. The user logs into the user account within the virtual machine.