IP Library Granted Patent US 12676891
Granted Patent B2
US 12676891 · App. 18/391,249 · Granted Jul 7, 2026

Endpoint security groups in private multi-access edge compute networks

Inventor: Bhushan Mangesh Kanekar (Saratoga, CA)
Assignee: Microsoft Technology Licensing, LLC
H04L63/20H04L63/0876H04L63/104
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12676891
App. No.
18/391,249
Granted
Jul 7, 2026
Kind
B2
Abstract

Endpoint security groups include computing device endpoints that are classified according to commonly shared device features and capabilities including device type, function, role, or location. Endpoint security groups are used as an alternative identity mechanism for endpoints for purposes of security and data traffic policy enforcement rather than using conventional IP (Internet Protocol) addressing. Grouping endpoints reduces the scope of network management to enable dynamic policy enforcement for endpoints as they join, leave, and then rejoin computing networks, which is a common behavior, particularly for IoT (Internet-of-Things) devices in manufacturing environments. In an illustrative example, a private multi-access edge compute (MEC) platform supports a scalable policy definition and enforcement framework that provides consistent endpoint handling independent of network access methodology. Endpoint security groups facilitate improvements in security of network access and utilization and segmentation of data traffic on a fine-grained basis.

Claims (37)

1 . A computer-implemented method using a multi-access edge compute (MEC) platform for managing security for a plurality of endpoints, wherein the endpoints are computing devices operable in a networked computing environment, comprising:

communicating with the endpoints from a computing server in the MEC platform, in which the endpoints are dynamically operable to join, leave, and rejoin the networked computing environment through an access network supporting multiple different access protocols;

classifying the endpoints based on functional capabilities associated with physical attributes of the endpoint computing devices defined by one or more of computing device type, role, function, or location;

associating the endpoints according to the classification by functional capabilities with different endpoint security groups;

applying security policies to the endpoints based on their association with the different endpoint security groups, in which different IP (Internet Protocol) addresses are assigned to network connections utilized by endpoints upon each instance of joining or rejoining the networked computing environment, in which the security policies are applied to the endpoints independent of the assigned IP addresses; and

independently of the assigned IP addresses, automatically reapplying the security policies to endpoints upon rejoining the networked computing environment subsequent to leaving the networked computing environment.

2 . The computer-implemented method of claim 1 further comprising using an authentication process with the endpoints in which an endpoint role or profile provided by the authentication process is mapped to an endpoint security group.

3 . The computer-implemented method of claim 1 in which an endpoint supports multiple applications operating thereon, and each application uses a discrete network connection having a unique IP address assigned thereto.

4 . The computer-implemented method of claim 1 in which the endpoints are unassociated with an identification of a human user.

5 . The computer-implemented method of claim 1 in which the security policies govern access of the endpoints in each endpoint security group to the networked computing environment or govern utilization of the networked computing environment by the endpoints in each security group, wherein the networked computing environment supports services and resources relating to one of compute, storage, or network.

6 . The computer-implemented method of claim 1 in which the access network comprises one or more of Wi-Fi, fourth generation (4G) mobile network, or fifth generation (5G) mobile network.

7 . One or more hardware-based non-transitory computer-readable memory devices storing computer-executable instructions which, upon execution by one or more processors disposed in a computing server, cause the server to:

receive requests through an access network from a plurality of Internet-of-Things (IoT) endpoints to join an enterprise computing environment, in which the access network supports multiple different access protocols, wherein the IoT endpoints are computing devices;

authenticate the IoT endpoints using an authentication process, the authentication process being dependent on the access protocol used by the IoT endpoints;

in response to the requests, assign membership of the IoT endpoints to endpoint security groups, in which a plurality of different endpoint security groups is utilized and membership of the IoT endpoints in the endpoint security groups is based on features and functions supported by physical attributes of the IoT endpoints; and

enforce security policies on the IoT endpoints based on endpoint security group membership, the enforcement of the security policies being independent from the access protocol used by the IoT endpoints.

8 . The one or more hardware-based non-transitory computer-readable memory devices of claim 7 in which each of the endpoints excludes a locally-implemented human-machine interface.

9 . The one or more hardware-based non-transitory computer-readable memory devices of claim 7 in which the authentication process is adapted to map security policies to an endpoint security group.

10 . The one or more hardware-based non-transitory computer-readable memory devices of claim 7 in which an endpoint is further grouped into a network security group and the security policies are enforced on the endpoint based on network security group membership.

11 . The one or more hardware-based non-transitory computer-readable memory devices of claim 7 in which an endpoint is further grouped into an application security group and the security policies are enforced on the endpoint based on application security group membership.

12 . The one or more hardware-based non-transitory computer-readable memory devices of claim 7 in which membership of the IoT endpoints in the endpoint security groups is based on physical location of the IoT endpoints within an area served by the access network.

13 . The one or more hardware-based non-transitory computer-readable memory devices of claim 7 in which the server is operated in a operated in a multi-access edge compute (MEC) platform.

14 . A computing device endpoint, comprising:

at least one processor;

a network interface;

a memory operatively coupled to the at least one processor; and

at least one hardware-based non-transitory computer-readable storage device having computer-executable instructions stored thereon which, when executed by the at least one processor, cause the endpoint to:

operate dynamically in a cyclical manner to interact with a computing network controlled by an enterprise, the operations of the endpoint being based on physical attributes of the endpoint in the enterprise;

establish membership in one or a plurality of endpoint security groups, in which membership in a given endpoint security group is based on the physical attributes of the endpoint; and

using the network interface, communicate through a locally-implemented access network to instantiate a computing session with the computing network, in which a new session is established with each instance of operation of the endpoint,

wherein the interactions of the endpoint with the computing network are controlled according to policies enforced on the endpoint based on endpoint security group membership, in which the policies are consistently enforced during each of a plurality of computing sessions established between the endpoint and the computing network.

15 . The endpoint of claim 14 in which the policies comprise one or more of security policy, identity-based policy, or role-based policy.

16 . The endpoint of claim 14 in which the endpoint comprises an Internet-of-Things (IoT) device.

17 . The endpoint of claim 14 in which the endpoint comprises a multi-function device and each function of the endpoint has membership with a different endpoint security group.

18 . The endpoint of claim 14 in which the executed instructions further cause the endpoint to be authenticated in accordance with an access protocol dependent on an access network type, in which membership in an endpoint security group is determined during authentication.

19 . The endpoint of claim 14 in which the computing network is at least partially instantiated in a cloud-computing platform.

20 . The endpoint of claim 19 in which the cloud-computing platform includes a multi-access edge compute (MEC) platform.