Method for enrolling an operating system, device and associated computer program

The method addresses the limitations of existing operating system enrollment by integrating an enrollment interface and data set into the system image, enabling secure, flexible, and user-specific remote enrollment through a centralized mobile device management system, ensuring data confidentiality and reducing deployment time.

FR3167226A1Pending Publication Date: 2026-04-10ECONOCOM WORKPLACE INFRA INNOVATION
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
FR · FR
Patent Type
Applications
Current Assignee / Owner
ECONOCOM WORKPLACE INFRA INNOVATION
Filing Date
2024-10-04
Publication Date
2026-04-10

AI Technical Summary

Technical Problem

Existing methods for enrolling operating systems impose significant constraints on user data confidentiality, require on-site intervention, and do not account for individual user needs, especially in networks without internet access, leading to lengthy deployments and reduced flexibility.

Method used

A method that modifies a system image by integrating an enrollment interface and data set, allowing remote enrollment through a centralized mobile device management system, ensuring data confidentiality and user-specific customization without an external cloud server, using a customizable enrollment interface for authentication and configuration.

Benefits of technology

Enables secure, flexible, and user-specific enrollment of operating systems without on-site intervention, ensuring data confidentiality and reducing deployment time by integrating enrollment data directly into the system image.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

The invention relates to a method for enrolling an operating system, the method being implemented by computer and comprising the following steps: - modification of a system image by integrating at least one enrollment interface and a set of enrollment data, - installation of the modified system image (2a), - initialization of an operating system (2b) from the modified image, the initialization comprising: enrollment of the operating system by a centralized mobile device management system from at least one authentication data entered in the enrollment interface, and configuration of the operating system from the enrollment data integrated into the modified system image. Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Method for enrolling an operating system, associated computer device and program technical field

[0001] The present invention relates to a method for enrolling an operating system.

[0002] The invention also relates to a computer program and an associated device.

[0003] The invention relates to the field of computer science, more specifically to that of operating systems and software management. The invention also relates to the field of techniques for installing, configuring, managing updates, or securing operating systems on computer devices. Prior art

[0004] Nowadays, advances in the commissioning of workstations are mainly focused on the integration of cloud services.

[0005] However, such methods are not satisfactory.

[0006] Indeed, these solutions impose significant constraints on customers regarding the confidentiality of their data. In particular, users on networks without internet access cannot benefit from these advances, which slows down their implementation.

[0007] The state-of-the-art methods for enrolling an operating system are well known. These methods are commonly used on-premises. However, devices such as workstations must be individually configured and prepared for each user, which often involves the use of Group Policy Objects (GPOs), scripts, registry keys, etc., and deployments that can be lengthy. Furthermore, the pre-established methods do not take into account the specific needs of each user.

[0008] One object of the present invention is to remedy at least one of the drawbacks of the prior art. Description of the invention

[0009] To this end, the invention relates to a method for enrolling an operating system. The method is implemented by computer and comprises the following steps:

[0010] - modification of a system image by integrating at least one interface enrollment and an enrollment data set,

[0011] - installation of the modified system image,

[0012] - initialization of an operating system from the modified image, The initialization process includes: • the enrollment of the operating system by a centralized mobile device management (MDM) system based on at least one authentication data entered in the enrollment interface, and, • a configuration of the operating system based on the enrollment data integrated into the modified system image.

[0013] The invention proposes a method for enrolling an operating system without the need for an external cloud server, thus ensuring the confidentiality of user data. This method according to the invention allows for the remote commissioning of a device integrating the enrolled operating system, without requiring on-site intervention. Furthermore, enrollment can be performed directly by the user from any network, thereby offering great flexibility. The method according to the invention takes into account the specific needs of the user, allowing for the customization of each instance of the operating system through the integration of specific enrollment data into the system image.

[0014] Advantageously, the process according to the invention has one or more of the following characteristics, taken individually or in any technically feasible combination: - the operating system can be a "Windows®" operating system; - the enrollment data may include a response file, the response file including at least one of the following tasks: • creation of a local administrator account, • creation of an automatic login for the local administrator account, • Launch of the enrollment interface. - The initialization of the operating system may include: • sending a request to enter at least one authentication data by the centralized mobile device management system via the enrollment interface; • Enrollment of the operating system by the centralized mobile device management system. - The enrollment interface can be activated when the local administrator account starts up.

[0015] Advantageously, the response file allows for customization specific to each user request. The tasks included in the response file are modular and adaptable to any user request according to their needs.

[0016] The invention also enables authentication within the centralized mobile device management system via a customizable enrollment interface. This enrollment interface is intuitive, featuring clear visuals, simple instructions, and well-placed buttons. The user should not have to go through several unnecessary steps to authenticate.

[0017] Moreover, since the operating system enrollment is carried out during system initialization, this is transparent to the user because the local administrator account starts automatically.

[0018] According to another aspect of the invention, a device comprising an operating system is proposed, the device comprising at least one control module configured to enroll the operating system of said device according to the steps of the method according to the invention.

[0019] The device according to the invention can be any type of device such as a server, a laptop or desktop computer, a tablet, a telephone or smartphone, a calculator, a processor, a computer chip, programmed to implement the method according to the invention, for example by executing the computer program according to the invention.

[0020] According to another aspect of the invention, a computer program is proposed comprising executable instructions which, when executed by computer, implement the steps of the process according to the invention.

[0021] The computer program can be in any computer language, such as for example in machine language, in C, C++, JAVA, Python, etc. Brief description of the figures

[0022] The invention will be better understood upon reading the following description, given solely by way of non-limiting example and made with reference to the accompanying drawings in which: - Fig. 1 illustrates the commissioning of a device according to the prior art; - Figure [Fig. 2] illustrates the commissioning of a device according to a mode of realization of the invention.

[0023] It is understood that the embodiments described below are in no way limiting. In particular, variants of the invention may be conceived comprising only a selection of the features described below, isolated from the other features described, if this selection of features is sufficient to confer a technical advantage or to differentiate the invention from the prior art. This selection includes at least one preferably functional feature without structural details, or with only a portion of the structural details if this portion is sufficient to confer a technical advantage or to differentiate the invention from the prior art.

[0024] In particular, all the variants and all the embodiments described are combinable with each other if nothing prevents this combination from a technical point of view.

[0025] In the figures and in the rest of the description, elements common to several figures retain the same reference. Detailed description

[0026] The invention relates to a method of enrolling an operating system of a device.

[0027] Preferably, the operating system is a "Windows®" operating system. The "Windows®" operating system is an operating system developed by Microsoft.

[0028] Preferably, the process relates to operating systems with "Windows®" versions 11 and above.

[0029] Figure 1 illustrates the commissioning of a device according to the prior art. The device in Figure 1a, 1b, and Figure 1b correspond to the same device but at different stages of operating system configuration. According to Figure 1, the device corresponds to a laptop computer. The operating system used is "Windows®".

[0030] In particular, [Fig. 1] illustrates the steps necessary to enroll a workstation without the method according to the invention. Initially, the operating system of device 1a is initialized by adding it to a directory or by using a local account. The operating system (device 1a) is then initialized by installing a system image via Microsoft Endpoint Configuration Manager (MECM), which is a process commonly used to deploy operating systems and applications on multiple devices in a corporate environment.

[0031] A "system image" in this context is a complete copy of an operating system (such as "Windows®"), which may include pre-installed software, specific configurations, security settings, etc. This image is prepared in advance for deployment on multiple devices.

[0032] The system image is then configured via a task sequence in Microsoft Endpoint Configuration Manager. This task sequence can be customized to meet specific needs, including the application of settings specific to the system image being used. A task sequence is defined as a set of predefined steps in Microsoft Endpoint Configuration Manager that are executed sequentially on the device to install the system. operating system, applications and / or configurations for example. The operating system (device 1b) is then initialized.

[0033] The operating system is then enrolled in a centralized mobile device management (MDM) system using various mechanisms. These mechanisms include, for example, configuration via a configuration application, a file, or a set of pre-configured settings known as a "provisioning package," or a specific application installed on the device and developed by the MDM system provider. These operations must be performed by qualified administrators or technicians. The operating system (device) is then ready for use by a user. Operating system configuration is performed using Group Policy Objects (GPOs), which allow administrators to configure the operating system and define general and specific settings. For example, a general setting might be the creation of a user session.

[0034] General settings are configurations that apply globally, for example, to all users or devices within an organizational unit, a site, or even an entire domain. "Specific" settings are user-specific and correspond to configurations that apply only to user accounts. These "specific" settings can be customized to meet the specific needs of users or user groups.

[0035] Next, the user logs into their user session using a predefined username and password (device le). The operating system begins loading the user profile. Group policies that apply to the user are executed at this time. This may include logon scripts, specific security configurations, or environmental settings defined by the administrator. Once the user profile is loaded and the group policies are applied, a user session is created. This user session represents the user's working environment, with access to all the applications, files, and network resources to which they are entitled.

[0036] Figure 2 illustrates the steps in the process of enrolling a workstation according to one embodiment of the invention. Devices 2a, 2b, and 2c correspond to the same device but at different stages of operating system configuration. According to Figure 2, the device corresponds to a laptop computer. The operating system used in this embodiment is Windows®.

[0037] In the context of the present invention, a process is applied to the system image of the operating system before it is initialized (device 2a). Specifically, the system image is modified by integrating at least one enrollment interface. and an enrollment data set. An enrollment data set is a set of files and scripts for the enrollment interface. The enrollment data includes a response file containing a list of specific tasks to be performed. The response file is added to the system image. The response file might include, for example, the following tasks:

[0038] - workstation initialization,

[0039] - creation of a local administrator account,

[0040] - creation of an automatic connection for the local administrator account,

[0041] - Launching the enrollment interface.

[0042] The enrollment interface is launched when the local administrator account session starts. In some embodiments, the system image includes a manufacturer's driver, if required, such as a network driver or touchpad driver. Preferably, the system image is stored on a server accessible from the network on which the devices for remotely enrolling the operating system are used.

[0043] When the system image is modified, it is installed on the device (device 2a). Then, the operating system (device 2a) is initialized from this modified system image. During the initialization of the operating system according to the invention, enrollment is performed by a centralized mobile device management (MDM) system using authentication data entered in the enrollment interface, and the operating system is configured using the enrollment data embedded in the modified system image (device 2b).

[0044] Indeed, when device 2a is started, the user is automatically taken to the enrollment interface (device 2b) after a warm-up period. The user enters authentication data, for example, a username or email address and a password or numeric code or other identification methods. Entering this authentication data in the enrollment interface automatically initiates the enrollment of the operating system (device 2b).

[0045] The installation of applications and / or settings inherent to the centralized mobile device management system begins. Information on the various installation steps is provided to the user via a display device on device 2b, for example, a screen. The installation includes the installation of an application client. The application client is software or an application that is installed on the user's device to enable interaction with the centralized mobile device management system. The installation also includes the installation of critical applications such as software or services that are essential to the operation of a business.

[0046] Preferably, device 2b restarts when operating system enrollment is complete. When device 2b restarts, the user can directly use their device 2c. The user logs into their user session using a predefined username and password.

[0047] Of course, the invention is not limited to the examples just described.

Claims

Demands

1. Method for enrolling an operating system, the method being implemented by computer and comprising the following steps: - modifying a system image by integrating therein at least one enrollment interface and a set of enrollment data, - installing the modified system image (2a), - initializing an operating system (2b) from the modified image, the initialization comprising: • enrollment of the operating system by a centralized mobile device management system from at least one authentication data entered in the enrollment interface, and, • configuration of the operating system from the enrollment data integrated into the modified system image.

2. An enrollment method according to claim 1, wherein the operating system is a "Windows®" operating system.

3. An enrollment method according to any one of the preceding claims, wherein the enrollment data includes a response file, the response file comprising at least one of the following tasks: - creation of a local administrator account, - creation of an automatic connection of the local administrator account, - launching of the enrollment interface.

4. An enrollment method according to any one of the preceding claims, wherein the initialization of the operating system comprises: - sending a request to enter at least one authentication data by the centralized mobile device management system via the enrollment interface; - enrollment of the operating system by the centralized mobile device management system.

5. An enrollment method according to claims 3 and 4, wherein the enrollment interface is activated at startup of the local administrator account.

6. A computer program comprising executable instructions which, when executed by a computer, implement the steps of the process according to any one of claims 1 to

7. J. Device comprising an operating system, the device comprising at least one control module configured to enroll the operating system of said device according to the steps of the method according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Persistent enrollment of a computing device using vendor autodiscovery

    EP3596595B1

  • Management of a stateless device environment

    US10929147B1