Location-based mobile device management of managed devices based on wireless interaction - Patent Application 20070122997

Location-based mobile device management using wireless interactions addresses the issue of securing device access by integrating mobile credentials with hardware readers, ensuring secure entry and immediate configuration adjustments.

JP2025533528APending Publication Date: 2025-10-07JAMF SOFTWARE LLC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2025517301
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-09-23
Filing Date
2023-09-23
Publication Date
2025-10-07

AI Technical Summary

Technical Problem

Existing systems fail to prevent employees from entering secured areas with potentially insecure end-user devices and managing security settings on these devices in real-time, even if a security threat is detected prior to badge authentication.

Method used

Implementing location-based mobile device management using wireless interactions, such as NFC and Bluetooth, to integrate mobile credentials with organization management, allowing immediate security configuration adjustments based on device interactions with hardware readers, including actions like installing drivers, configuring networks, and restricting access.

Benefits of technology

Enables secure access control and immediate management of device settings based on location, preventing unauthorized access and enhancing security by automatically adjusting device configurations and policies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025533528000001_ABST
    Figure 2025533528000001_ABST
Patent Text Reader

Abstract

In certain aspects, a computer-implemented method includes receiving user data and access information for a managed device in response to communication between a managed device and a reader. The method includes identifying device information for the managed device associated with the user data and the access information. The method also includes determining at least one mobile device action to perform on the managed device based on the device information, the user data, and the access information. The method includes, in response to determining the at least one mobile device action, sending a message to a push notification service to initiate communication between the managed device and a mobile device management server. The method includes, in response to the managed device communicating with the mobile device management server, sending a management command to the managed device to perform the at least one mobile device action. A system and media are also provided.
Need to check novelty before this filing date? Find Prior Art

Description

CROSS-REFERENCE TO RELATED APPLICATIONS

[0001] This application claims the benefit of priority under 35 U.S.C. § 119 to U.S. Provisional Application No. 63 / 376,910, filed September 23, 2022, entitled "LOCATION-BASED MOBILE DEVICE MANAGEMENT OF MANAGED DEVICES BASED ON WIRELESS INTERACTIONS," the disclosure of which is incorporated herein by reference in its entirety. [Technical Field]

[0002] FIELD OF THE DISCLOSURE The present disclosure relates generally to mobile device and management systems, and more particularly to location-based mobile device management of managed devices based on wireless interactions. [Background technology]

[0003] Organizations often require configuration or mandatory settings for end-user devices to keep managed devices and the data on them secure. Once devices are under the organization's control, a set-and-forget security configuration is often the standard. Similarly, less desirable methods exist for end users and organization employees to manually configure their devices to specific security specifications. Additionally, some organizations may have special security levels for specific rooms or areas within their buildings, requiring managed devices to be configured or reconfigured with stricter security settings.

[0004] However, in some conventional cases, an employee may use a physical badge (e.g., a white plastic card) with access credentials to enter a secured room or area within a building while carrying an end-user device that unknowingly poses a security threat or requires higher security settings. In such cases, if the employee fails to prevent the entry through badge authentication at the time, or if the employee fails to manage the behavior or security settings on the end-user device even if a security threat is detected on the end-user device immediately prior to badge authentication, the secured room or area within the building may be compromised.

[0005] The material described in the Background section of this specification should not be considered prior art merely because it is described in or associated with the Background section. The Background section may contain information that describes one or more aspects of the subject technology. Summary of the Invention

[0006] In certain aspects, the present disclosure provides systems and methods that enable location-based mobile device management of managed devices based on wireless interactions with a hardware wireless reader via near field communication (NFC), Bluetooth, or other suitable wireless communication. For example, the disclosed systems and methods integrate the managed device's mobile credentials into an organization's management and security lifecycle. When a managed end-user device presents authentication information to a hardware wireless reader located near a protected entrance / exit, specific security settings, end-user device operating environment, and access control actions can be controlled based on the location / context of the managed end-user device's interaction with the hardware wireless reader (e.g., when badge authentication is performed). In certain aspects, if the security status of the managed device's mobile access credentials is determined to be insufficient, the managed device's configuration and / or settings can be immediately managed to, for example, restrict access to secured areas within a building or to a sensitive network. Furthermore, in certain aspects, upon badge authentication with a hardware wireless reader, an organization's mobile device management server can automatically issue or provision specific actions to the managed device based on the location of the hardware wireless reader. These actions may include, but are not limited to, installing device drivers, assisting with location determination, accessing potentially sensitive networks, configuring WiFi profiles, restricting cellular data usage, specifying a virtual private network (VPN), identifying lunch locations, and other appropriate actions. While some of these actions are described in the context of mobile device management (MDM), it should be understood that in other aspects, upon badge authentication, data policies and / or private access may also be used to perform non-MDM actions in some network configurations, such as restricting certain websites, creating data caps, encrypting traffic with private access technology for certain services or apps, and other appropriate network actions.

[0007] According to certain aspects of the present disclosure, a computer-implemented method is provided. The computer-implemented method includes receiving user data and access information for the managed device in response to communication between a managed device and a reader. The computer-implemented method includes identifying device information for the managed device associated with the user data and the access information. The computer-implemented method includes determining at least one mobile device action to perform on the managed device based on the device information, the user data, and the access information. The computer-implemented method includes, in response to determining the at least one mobile device action, sending a message to a push notification service to initiate communication between the managed device and a mobile device management server. The computer-implemented method includes, in response to the managed device communicating with the mobile device management server, sending a management command to the managed device to perform the at least one mobile device action.

[0008] According to certain aspects of the present disclosure, a system is provided, the system including: a memory containing instructions; and a processor configured to execute the instructions, wherein the processor executes the instructions to receive user data and access information for the managed device in response to communication between a managed device and a reader. The processor is configured to execute the instructions, wherein the processor identifies device information for the managed device associated with the user data and the access information. The processor is configured to execute the instructions, wherein the processor executes the instructions to determine at least one mobile device action to perform on the managed device based on the device information, the user data, and the access information. The processor is configured to execute the instructions, wherein the processor is configured to send a message to a push notification service to initiate communication between the managed device and a mobile device management server in response to determining the at least one mobile device action. The processor is configured to execute the instructions, and by executing the instructions, the processor sends a management command to the managed device to cause the managed device to perform the at least one mobile device operation in response to the managed device communicating with a mobile device management server.

[0009] According to certain aspects of the present disclosure, a non-transitory machine-readable storage medium is provided that includes machine-readable instructions for causing a processor to execute a method. The method includes receiving user data and access information for the managed device in response to communication between a managed device and a reader. The method includes identifying device information for the managed device associated with the user data and the access information. The method includes determining at least one mobile device action to perform on the managed device based on the device information, the user data, and the access information. The method includes sending a message to a push notification service in response to determining the at least one mobile device action, the message initiating communication between the managed device and a mobile device management server. The method includes sending a management command to the managed device to perform the at least one mobile device action in response to the managed device communicating with the mobile device management server.

[0010] According to certain aspects of the present disclosure, a computer-implemented method is provided, the computer-implemented method including receiving user data and access information for the managed device in response to communication between a managed device and a reader. The computer-implemented method includes identifying device information for the managed device associated with the user data and the access information. The computer-implemented method includes determining a risk level for the managed device based on the device information, the user data, and the access information. The computer-implemented method includes, in response to determining that the risk level is below a predetermined threshold, sending a risk command to an access management server to revoke access for the managed device.

[0011] According to certain aspects of the present disclosure, a system is provided, including a memory containing instructions and a processor configured to execute the instructions, the processor executing the instructions to receive user data and access information for the managed device in response to communication between a managed device and a reader. The processor is configured to execute the instructions, the processor executing the instructions identifies device information for the managed device associated with the user data and the access information. The processor is configured to execute the instructions, the processor executing the instructions determines a risk level for the managed device based on the device information, the user data, and the access information. The processor is configured to execute the instructions, the processor executing the instructions, the processor executing the instructions, the processor executing the instructions, the processor executing the instructions, in response to determining that the risk level is below a predetermined threshold, sends a risk command to an access management server to revoke access for the managed device.

[0012] According to certain aspects of the present disclosure, a non-transitory machine-readable storage medium is provided that includes machine-readable instructions for causing a processor to execute a method. The method includes receiving user data and access information for the managed device in response to communication between a managed device and a reader. The method includes identifying device information for the managed device associated with the user data and the access information. The method includes determining a risk level for the managed device based on the device information, the user data, and the access information. The method includes sending a risk command to an access management server to revoke access for the managed device in response to determining that the risk level is below a predetermined threshold.

[0013] According to certain aspects of the present disclosure, a computer-implemented method is provided. The computer-implemented method includes receiving user data and access information for the managed device in response to communication between a managed device and a reader. The computer-implemented method includes identifying device information for the managed device associated with the user data and the access information. The computer-implemented method includes determining at least one mobile device action to perform on the managed device based on the device information, the user data, and the access information. The computer-implemented method includes, in response to identifying the at least one mobile device action, authorizing an endpoint management service to perform the at least one mobile device action on the managed device.

[0014] According to certain aspects of the present disclosure, a system is provided, including a memory containing instructions and a processor configured to execute the instructions, the processor executing the instructions to receive user data and access information for the managed device in response to communication between a managed device and a reader. The processor is configured to execute the instructions, the processor executing the instructions to identify device information for the managed device associated with the user data and the access information. The processor is configured to execute the instructions, the processor executing the instructions to determine at least one mobile device action to perform on the managed device based on the device information, the user data, and the access information. The processor is configured to execute the instructions, the processor executing the instructions to allow an endpoint management service to perform the at least one mobile device action on the managed device in response to determining the at least one mobile device action.

[0015] According to certain aspects of the present disclosure, a non-transitory machine-readable storage medium is provided that includes machine-readable instructions for causing a processor to execute a method. The method includes receiving user data and access information for the managed device in response to communication between a managed device and a reader. The method includes identifying device information for the managed device associated with the user data and the access information. The method includes determining at least one mobile device action to perform on the managed device based on the device information, the user data, and the access information. The method includes, in response to identifying the at least one mobile device action, allowing an endpoint management service to perform the at least one mobile device action on the managed device.

[0016] It should be understood that other configurations of the subject technology of the present disclosure will be readily apparent to those skilled in the art upon reading the following detailed description, in which various configurations of the subject technology of the present disclosure are shown and described by way of example. It will be understood that the subject technology is capable of other different configurations and that its several details can be modified in various other respects, all without departing from the scope of the subject technology. While various aspects described herein may be described in the context of medical, retail, educational, or corporate environments, it should be noted that these are merely examples and not limitations. The teachings of the present disclosure may be applied to any mobile device environment, including, but not limited to, residential, medical, retail, educational, corporate, or other suitable environments. Accordingly, the drawings and detailed description are to be regarded as illustrative in nature and not restrictive. [Brief explanation of the drawings]

[0017] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate various exemplary embodiments and, together with the description, serve to explain the principles of the disclosed embodiments.

[0018] [Figure 1] FIG. 1 illustrates an exemplary architecture for location-based mobile device management of managed devices based on wireless interaction.

[0019] [Figure 2] FIG. 2 is a block diagram illustrating an example managed device, mobile device management server, wireless reader, access management server, integration server, push notification service, and risk assessment service in the architecture shown in FIG. 1 in accordance with certain aspects of the present disclosure.

[0020] [Figure 3] FIG. 3 illustrates an exemplary process of location-based mobile device management of a managed device through wireless interaction based on the exemplary first managed device, second managed device, mobile device management server, carrier server, and push notification service of FIG. 2 .

[0021] [Figure 4] FIG. 4 illustrates another exemplary process for mobile device management of managed devices owned by an individual with reference to the exemplary first managed device, second managed device, mobile device management server, carrier server, and push notification service shown in FIG. 2 .

[0022] [Figure 5] FIG. 5 is a block diagram illustrating an exemplary computer system in which the mobile device management server, first managed device, second managed device, wireless reader, access management server, integration server, push notification service, and risk assessment service shown in FIG. 2 may be implemented.

[0023] In one or more implementations, not all of the components shown in each figure are required, and one or more implementations may include additional components not shown. Changes in the arrangement and type of components may be made without departing from the scope of the subject matter of the present disclosure. Additional, different, or fewer components may be utilized within the scope of the subject matter of the present disclosure. Detailed Description

[0024] The detailed description set forth below is intended to be a description of various embodiments and is not intended to represent the only embodiments in which the subject technology may be practiced. Those skilled in the art will recognize that the described embodiments may be modified in a variety of different ways without departing from the scope of the present disclosure. Accordingly, the drawings and description should be regarded as illustrative in nature and not restrictive.

[0025] The disclosed system addresses a technical problem related to computer technology that arises in the field of mobile device management, specifically, the inability to prevent employees from entering secured entrances using badge authentication and to manage the behavior and security settings on end-user devices even if a security threat on the end-user device is detected immediately prior to badge authentication. The disclosed system solves this technical problem by providing location-based mobile device management for managed devices based on wireless interaction with a hardware wireless reader.

[0026] 1 illustrates an example architecture 100 for location-based mobile device management of managed devices based on wireless interactions, including, but not limited to, near-field communication (NFC) interactions, Bluetooth interactions, and other suitable interactions. For example, architecture 100 includes a mobile device management server 10, at least one managed device 12, such as a first managed device 12a, a second managed device 12b, through an nth managed device 12n, a wireless reader 14, an access management server 16, an integration server 18, a push notification service 20, and a risk assessment service 22, all connected via a network 24. In certain aspects, mobile device management server 10 may be connected to push notification service 20 via another network.

[0027] The mobile device management server 10 may be any device having a suitable processor, memory, and capable of communicating with at least one managed device 12, the integration server 18, and the push notification service 20. The mobile device management server 10 may include multiple servers for load balancing purposes. The access management server 16 may be any device having a suitable processor, memory, and capable of communicating with the wireless reader 14, the integration server 18, and the risk assessment service 22. The integration server 18 may be any device having a suitable processor, memory, and capable of communicating with the mobile device management server 10, the access management server 16, and the risk assessment service 22. The push notification service 20 may be any device having a suitable processor, memory, and capable of communicating with the mobile device management server 10 and at least one managed device 12. The risk assessment service 22 may be any device having a suitable processor, memory, and capable of communicating with the access management server 16 and the integration server 18. Although the mobile device management server 10 and the integration server 18 are shown as separate servers, in certain embodiments the integration server 18 may be hosted on the mobile device management server 10 and may be integrated with the risk assessment service 22.

[0028] The at least one managed device 12, such as a first managed device 12a and a second managed device 12b, with which the mobile device management server 10 communicates via the network 24 via the push notification service 20 may be, for example, a mobile phone, a tablet computer, a handheld computer, a laptop computer, a portable media player, an eBook reader, or any other device having a suitable processor and memory and capable of communication. The wireless reader 14 may be any device having a suitable processor, memory, and having wireless communication capabilities with the at least one managed device 12 and another communication capability for communication with the access management server 16. In a particular embodiment, the wireless reader 14 is a near field communication (NFC) reader having at least an NFC reading mode. In another embodiment, the wireless reader 14 is a Bluetooth reader. In certain aspects, the mobile device management server 10, the access management server 16, the integration server 18, the push notification service 20, and the risk assessment service 22 may be Infrastructure as a Service (IaaS) cloud computing servers, capable of supporting Platform as a Service (PaaS) and Software as a Service (SaaS).

[0029] It should be noted that in the present disclosure, the at least one managed device 12 as the first managed device 12a, the second managed device 12b to the n-th managed device 12n shown in Fig. 1 is not limited to a specific configuration or number of devices. In certain aspects, there may be a different number of managed devices.

[0030] Network 24 may include, for example, one or more of a personal area network (PAN), a local area network (LAN), a campus area network (CAN), a metropolitan area network (MAN), a wide area network (WAN), a broadband network (BBN), the Internet, etc. Additionally, network 24 may include, but is not limited to, one or more network topologies such as a bus network, a star network, a ring network, a mesh network, a star-bus network, a tree or hierarchical network.

[0031] 2 is a block diagram illustrating an example of a mobile device management server 10, at least one managed device 12, such as a first managed device 12a and a second managed device 12b, a wireless reader 14, an access management server 16, an integration server 18, a push notification service 20, and a risk assessment service 22 in the architecture shown in FIG. 1, in accordance with certain aspects of the present disclosure. For purposes of explanation, a first managed device 12a and a second managed device 12b are described, but it should be understood that any number of at least one managed device 12 may be used.

[0032] The mobile device management server 10, at least one managed device 12, such as a first managed device 12a and a second managed device 12b, the wireless reader 14, the access management server 16, the integration server 18, the push notification service 20, and the risk assessment service 22 are connected over a network 24 via respective communication modules 26, 28, 30, 32, 34, 36, 38, and 40. The communication modules 26, 28, 30, 32, 34, 36, 38, and 40 are configured to interface with the network 24 to send and receive information, such as data, requests, responses, and instructions, to other devices on the network 24. The communication modules 26, 28, 30, 32, 34, 36, 38, and 40 may be, for example, modems or Ethernet cards.

[0033] The mobile device management server 10 includes a processor 42, a communications module 26, and a memory 44. The processor 42 of the mobile device management server 10 is configured to execute instructions, such as instructions physically coded on the processor 42, instructions received from software in the memory 44, or a combination thereof. In certain aspects, the processor 42 of the mobile device management server 10 is configured to receive user data 74 and access information 76 of the first managed device 12a in response to the first managed device 12a communicating with the wireless reader 14. In certain aspects, the processor 42 of the mobile device management server 10 is configured to identify device information 78 of the first managed device 12a associated with the user data 74 and the access information 76. In certain aspects, the processor 42 of the mobile device management server 10 is configured to determine at least one mobile device action 80 to perform on the first managed device 12a based on the device information 78, the user data 74, and the access information 76. The at least one mobile device action 80 may be installing a device driver, assisting with location determination, accessing a potentially sensitive network, configuring a WiFi profile, restricting cellular data usage, identifying a virtual private network (VPN), modifying a device configuration, restricting access to a protected area, identifying a lunch location, managing network configuration using data policies and / or private access, restricting certain websites, creating a data cap, encrypting traffic with private access technology for a particular service or app, or any other suitable action.

[0034] In certain embodiments, the processor 42 of the mobile device management server 10 is configured to, in response to determining at least one mobile device action 80, send a message 82 to the push notification service 20 to initiate communication between the first managed device 12a and the mobile device management server 10. In certain embodiments, in response to the first managed device 12a communicating with the mobile device management server 10, the processor 42 of the mobile device management server 10 sends a management command 84 to the first managed device 12a to cause it to perform the at least one mobile device action 80. The mobile device action 80 may include, but is not limited to, installing a device driver, location assistance, accessing a potentially sensitive network, configuring a WiFi profile, restricting cellular data usage, identifying a virtual private network (VPN), changing a device configuration, restricting access to a secure area, turning off the device camera, identifying a lunch location, or other suitable action. In another particular aspect, in response to determining the at least one mobile device action 80, the processor 42 of the mobile device management server 10 enables an endpoint management service, such as unified endpoint management (UEM), to perform the at least one mobile device action 80. The mobile device action 80 may include, but is not limited to, managing network configuration using data policies and / or private access, restricting certain websites, creating data caps, encrypting traffic with private access technology for certain services or apps, or other suitable network action.

[0035] The access management server 16 includes a processor 46, a communications module 34, and a memory 48. The processor 46 of the access management server 16 is configured to execute instructions, such as instructions physically coded into the processor 46, instructions received from software in the memory 48, or a combination thereof.

[0036] The integration server 18 includes a processor 50, a communications module 36, and a memory 52. ​​The processor 50 of the integration server 18 is configured to execute instructions, such as instructions physically coded on the processor 50, instructions received from software in the memory 52, or a combination thereof. In certain embodiments, the processor 50 of the integration server 18 is configured to receive user data 74 and access information 76 of the first managed device 12a in response to the first managed device 12a communicating with the wireless reader 14. In certain embodiments, the processor 50 of the integration server 18 is configured to transmit the user data 74, the access information 76, and the device information 78 to the mobile device management server 10.

[0037] The push notification service 20 includes a processor 54, a communications module 38, and a memory 56. The processor 54 of the push notification service 20 is configured to execute instructions, such as instructions physically coded into the processor 54, instructions received from software in the memory 56, or a combination thereof.

[0038] The risk assessment service 22 includes a processor 58, a communications module 40, and a memory 60. The processor 46 of the risk assessment service 22 is configured to execute instructions, such as instructions physically coded on the processor 58, instructions received from software in the memory 60, or a combination thereof. In certain embodiments, the processor 46 of the risk assessment service 22 is configured to receive user data 74 and access information 76 of the first managed device 12a in response to the first managed device 12a communicating with the wireless reader 14. In certain embodiments, the processor 46 of the risk assessment service 22 is configured to identify device information 78 of the first managed device 12a associated with the user data 74 and the access information 76. In certain embodiments, the processor 46 of the risk assessment service 22 is configured to determine a risk level of the managed device based on the device information, the user data, and the access information.

[0039] The first managed device 12a includes a processor 62, a communications module 28, and a memory 64. The processor 62 of the first managed device 12a is configured to execute instructions, such as instructions physically coded into the processor 62, instructions received from software in the memory 64, or a combination thereof.

[0040] The second managed device 12b includes a processor 66, a communications module 30, and a memory 68. The processor 66 of the second managed device 12b is configured to execute instructions, such as instructions physically coded into the processor 66, instructions received from software in the memory 68, or a combination thereof.

[0041] The wireless reader 14 includes a processor 70, a communications module 32, and a memory 72. The processor 70 of the wireless reader 14 is configured to execute instructions, such as instructions physically coded into the processor 70, instructions received from software in the memory 72, or a combination thereof. The wireless reader 14 may be located near a secured entry point, such as a building, a room within a building, or other suitable entry point. The wireless reader 14 is configured to control a locking mechanism of the secured entry point.

[0042] The mobile device management server 10 may represent hardware and / or software that implements mobile device management functionality (e.g., a device management framework). For example, in enterprise, healthcare, and education, to name a few, the mobile device management server 10 may register, monitor, and manage managed devices, such as a first managed device 12 a and a second managed device 12 b, and utilize their mobile access credentials to change the configuration of the managed devices, perform actions, add restrictions, remove restrictions, and revoke access credentials based on location data. In certain aspects, the mobile device management server 10 may store (or access) registration and grouping data 90. The registration and grouping data 90 may include registration target data identifying all mobile devices managed by the mobile device management server 10, such as data related to the first managed device 12 a, the second managed device 12 b, through the nth managed device 12 n.

[0043] While some of the operations are described in the context of mobile device management (MDM), it should be understood that in other aspects, upon badge authentication to wireless reader 14, data policies and / or private access may be used to perform non-MDM operations in some network configurations, such as restricting certain websites, creating data caps, encrypting traffic with private access technology for certain services or apps, or other appropriate network actions.

[0044] It should be noted that while various embodiments described herein may be described in the context of enterprise, healthcare, and educational environments, these are by way of example only and not limitation, and the teachings of the present disclosure may be applied to any mobile device environment, including, but not limited to, residential, enterprise, educational, healthcare, retail, government, organizational, and other suitable environments.

[0045] Figure 3 illustrates an example of a process 300 that may utilize the mobile device management server 10, at least one managed device 12, such as a first managed device 12a and a second managed device 12b, the wireless reader 14, the access management server 16, the integration server 18, the push notification service 20, and the risk assessment service 22 shown in Figure 2. Although Figure 3 refers to Figure 2, it should be understood that the process steps of Figure 3 may be performed by other systems.

[0046] Process 300 begins by proceeding to step 310, where processor 42 of mobile device management server 10 or processor 50 of integration server 18 receives user data 74 and access information 76 of the first managed device 12a in response to the first managed device 12a communicating with wireless reader 14. As shown in step 312, processor 42 of mobile device management server 10 identifies device information 78 of the first managed device 12a that is associated with user data 74 and access information 76.

[0047] As shown in step 314, the processor 30 of the mobile device management server 10 determines at least one mobile device action 80 to perform on the first managed device 12a based on the device information 78, the user data 74, and the access information 76. At step 318, the processor 30 of the mobile device management server 10, in response to determining the at least one mobile device action 80, sends a message 82 to the push notification service 20. The message 82 initiates the first managed device 12a to communicate with the mobile device management server 10. At step 318, in response to the first managed device 12a communicating with the mobile device management server 10, the processor 30 of the mobile device management server 10 sends a management command 84 to the first managed device 12a to cause the first managed device 12a to perform the at least one mobile device action 80. Mobile device operations 80 may include, but are not limited to, installing device drivers, location assistance, accessing potentially sensitive networks, configuring WiFi profiles, limiting cellular data usage, identifying virtual private networks (VPNs), identifying lunch locations, and other suitable operations.

[0048] Figure 4 illustrates an example of a process 400 that may utilize the mobile device management server 10, at least one managed device 12, such as a first managed device 12a and a second managed device 12b, the wireless reader 14, the access management server 16, the integration server 18, the push notification service 20, and the risk assessment service 22 shown in Figure 2. Although Figure 4 refers to Figure 2, it should be understood that the process steps of Figure 4 may be performed by other systems.

[0049] Process 400 begins by proceeding to step 410, where processor 58 of risk assessment service 22 receives user data 74 and access information 76 of the first managed device 12a in response to the first managed device 12a communicating with wireless reader 14. As shown in step 412, processor 58 of risk assessment service 22 identifies device information 78 of the first managed device 12a that is associated with user data 74 and access information 76.

[0050] As shown in step 414, the processor 58 of the risk assessment service 22 determines a risk level 86 of the first managed device 12a based on the device information 78, the user data 74, and the access information 76. In step 418, in response to determining that the risk level 86 is below a predetermined threshold, the processor 58 of the risk assessment service 22 sends a risk command 88 to the access management server 16 to revoke access for the first managed device 12a.

[0051] An embodiment will now be described with reference to the exemplary process 300 of FIG. 3 and the exemplary process 400 of FIG.

[0052] As an example, an end user associated with a first managed device 12a attempts to gain access to a protected entrance by bringing the first managed device 12a close to a wireless reader 14 located near the protected entrance. The protected entrance may be an entrance to a room in a research and development (R&D) facility where mobile device cameras are required to be turned off. When communication is initiated between the first managed device 12a and the wireless reader 14, user data 74 of the first managed device 12a is transmitted to the wireless reader 14 and then to the access management server 16. The access management server 16 determines access information 76 associated with the user data 74 and transmits both the user data 74 and the access information 76 to the integration server 18 or, in some aspects, to the mobile device management server 10, which hosts the functionality of the integration server 18. The integration server 18 or the mobile device management server 10 determines device information 78 associated with the user data 74 and the access information 76. The mobile device management server 10 then determines, based on the user data 74, the access information 76, and the device information 78, that the camera of the first managed device 12a needs to be turned off when entering the room at the R&D facility. In response to this determination, the mobile device management server 10 sends a message 82 to the push notification service 20, thereby initiating communication between the first managed device 12a and the mobile device management server 10. Once in communication, the mobile device management server 10 sends a management command 84 to the first managed device 12a to turn off the camera.

[0053] In another example related to a second managed device 12b, an end user associated with the second managed device 12b similarly attempts to gain access to a protected entrance (e.g., a room) of an R&D facility. Similarly, when communication is initiated between the second managed device 12b and the wireless reader 14, user data 74 of the second managed device 12b is transmitted to the wireless reader 14 and then to the risk assessment service 22. The risk assessment service 22 identifies access information 76 associated with the user data 74 and transmits both the user data 74 and the access information 76 to the integration server 18. The integration server 18, or the risk assessment service 22, identifies device information 78 associated with the user data 74 and the access information 76. Here, the risk assessment service 22 determines a risk level 86 of the second managed device 12b based on the device information 78, the user data 74, and the access information 76. If the risk assessment service 22 determines that the risk level 86 is below a predetermined threshold, the risk assessment service 22 sends a risk command 88 to the access management server 16 to revoke access for the second managed device 12b, thereby preventing the end user associated with the second managed device 12b from entering the protected room (e.g., the protected entrance is kept locked). In another example, the digital access credentials for the second managed device are suspended, revoked, or denied provisioning by the access management server 16.

[0054] While certain embodiments and workflows are described herein with respect to performing mobile device management on a managed device, it should be understood that mobile device management may also be performed on multiple devices, such as a first managed device 12a, a second managed device 12b, through an nth managed device 12n. In certain aspects, for example, the mobile device management server 10 may be configured to select multiple managed devices or a group of managed devices. A management message, such as message 82, may identify multiple managed devices or a group of managed devices, and the push notification service 20 may send a push notification to each managed device.

[0055] In some embodiments, the processes illustrated in Figures 3 and 4 can be performed in parallel or simultaneously.

[0056] 5 is a block diagram illustrating an exemplary computer system 500 that enables implementation of the mobile device management server 10, at least one managed device 12, such as the first managed device 12a and the second managed device 12b shown in FIG. 2, the wireless reader 14, the access management server 16, the integration server 18, the push notification service 20, and the risk assessment service 22. In certain aspects, the computer system 500 may be implemented in hardware or a combination of software and hardware, on a dedicated server, integrated with other entities, or distributed across multiple entities.

[0057] The computer system 500 (e.g., the mobile device management server 10, at least one managed device 12, such as a first managed device 12a and a second managed device 12b, the wireless reader 14, the access management server 16, the integration server 18, the push notification service 20, and the risk assessment service 22) includes a bus 508 or other communication mechanism for communicating information, and a processor 502 (e.g., processors 42, 46, 50, 54, 58, 62, 66, 70) connected to the bus 508 for processing information. In one aspect, the computer system 500 can be an IaaS cloud computing server capable of supporting PaaS and SaaS services.

[0058] In addition to the hardware, computer system 500 may include code that establishes an execution environment for a subject computer program, i.e., code comprising processor firmware, a protocol stack, a database management system, an operating system, or one or more combinations thereof, stored in memory 504 (e.g., memories 44, 48, 52, 56, 60, 64, 68, 72) coupled to bus 508 and providing storage for information and instructions executed by processor 502. Memory 504 may include random access memory (RAM), flash memory, read-only memory (ROM), programmable read-only memory (PROM), erasable PROM (EPROM), registers, a hard disk, a removable disk, a CD-ROM, a DVD, or other suitable storage device. Processor 502 and memory 504 may be supplemented by, or incorporated in, dedicated logic circuitry.

[0059] The instructions may be stored in memory 504 or may be implemented as a computer program product, for example, as one or more modules of computer program instructions encoded on a computer-readable medium for execution by or control the operation of computer system 500.

[0060] Computer programs discussed herein do not necessarily correspond to files in a file system. A program may be stored as part of a file that holds other programs or data (e.g., one or more scripts stored in a markup language document), in a single file dedicated to the program, or in multiple cooperating files (e.g., a file storing one or more modules, subprograms, or code portions). A computer program may be deployed to run on a single computer, or on multiple computers located at a single site, or on multiple computers distributed across multiple sites and interconnected via a communications network, such as in a cloud computing environment. The processes and logic flows described herein may be performed by one or more programmable processors executing one or more computer programs, which perform functions by manipulating input data and generating output.

[0061] The computer system 500 further includes a data storage device 506, such as a magnetic disk or optical disk, coupled to the bus 508 for storing information and instructions. The computer system 500 may be connected to various devices via an input / output module 510. The input / output module 510 may be any input / output module. An example of the input / output module 510 is a data port, such as a USB port. Additionally, the input / output module 510 may be provided in communication with the processor 502 to enable short-range communication between the computer system 500 and other devices. For example, the input / output module 510 may be provided for wired communication in some implementations, for wireless communication in other implementations, or may use multiple interfaces. The input / output module 510 is configured to connect to a communication module 512. An example of the communication module 512 (e.g., communication modules 26, 28, 30, 32, 34, 36, 38, 40) is a network interface card, such as an Ethernet card or a modem.

[0062] In certain embodiments, the input / output module 510 is configured to connect to multiple devices, such as input devices 514 and / or output devices 516. Examples of input devices 514 include a keyboard and pointing devices, such as a mouse or trackball, that allow a user to provide input to the computer system 500. Other types of input devices 514, such as tactile input devices, visual input devices, audio input devices, brain-computer interface devices, etc., can also be used to facilitate user interaction.

[0063] According to one aspect of the present disclosure, the mobile device management server 10, at least one managed device 12, such as a first managed device 12a and a second managed device 12b, the wireless reader 14, the access management server 16, the integration server 18, the push notification service 20, and the risk assessment service 22 can be implemented using a computer system 500 by a processor 502 executing one or more sets of instructions stored in a memory 504. Such instructions may be read into the memory 504 from another machine-readable medium, such as a data storage device 506. Execution of the sets of instructions stored in the main memory 504 causes the processor 502 to perform the process steps described herein. One or more processors in a multi-processor configuration may be used to execute the sequences of instructions stored in the memory 504. The processor 502 may process the executable instructions and / or data structures by remotely accessing the computer program product or by downloading the executable instructions and / or data structures from a remote server via a communication module 512 (e.g., in a cloud computing environment). In alternative aspects, hard-wired circuitry may be used in place of or in combination with software instructions to implement various aspects of the present disclosure, and thus aspects of the present disclosure are not limited to any particular combination of hardware circuitry and software.

[0064] Various aspects of the subject matter described herein may be implemented in a computing system including a back-end component (e.g., a data server), a middleware component (e.g., an application server), or a front-end component (e.g., a client computer equipped with a graphical user interface or web browser through which a user can interact with an implementation of the subject matter described herein), or any combination of one or more of these back-end, middleware, or front-end components. For example, some aspects of the subject matter described herein may be performed by a cloud computing environment. Thus, in certain aspects, a user of the systems and methods disclosed herein may perform at least some steps by accessing a cloud server via a network connection. Furthermore, data files, circuit diagrams, performance specifications, etc. generated due to the present disclosure may be stored on a database server within the cloud computing environment or downloaded from the cloud computing environment to private storage.

[0065] As used herein, the terms "machine-readable storage medium" or "computer-readable medium" refer to any medium that participates in providing instructions or data for execution by processor 502. As used herein, "storage medium" refers to a non-transitory medium that stores data and / or instructions that cause a machine to operate in a specific fashion. Such media may take many forms, including but not limited to, volatile and non-volatile media, and transmission media.

[0066] As used herein, the terms "computer-readable storage medium" and "computer-readable medium" are strictly limited to tangible, physical objects that store information in a form readable by a computer. These terms do not include wireless signals, wired download signals, or other transitory signals. Storage media are distinct from transmission media, although they may be used interchangeably. Transmission media involve the transfer of information between storage media. For example, transmission media include coaxial cable, copper wire, and optical fiber, including the wiring that comprises bus 508. Transmission media can also take the form of acoustic or light waves, such as those generated in radio wave or infrared data communications. Furthermore, as used herein, the terms "computer," "server," "processor," and "memory" all refer to electronic or other technological devices. These terms exclude persons or groups of persons. As used herein, the terms "display" or "display" refer to a display on an electronic device.

[0067] In one aspect, a method may be an act, an instruction, or a function, or vice versa. In one aspect, a clause or claim may be amended to include some or all of any one or more clauses, one or more words, one or more sentences, one or more phrases, one or more paragraphs, and / or one or more claims recited terms (e.g., instructions, operations, functions, or components).

[0068] To illustrate the interchangeability of hardware and software, various illustrative blocks, modules, components, methods, operations, instructions, algorithms, etc. have been described generally in terms of their functionality. Whether such functionality is implemented as hardware, software, or a combination of hardware and software depends upon the particular application and design constraints imposed on the overall system. Those skilled in the art may implement the described functionality in a variety of ways for each particular application.

[0069] As used herein, the phrase "at least one" preceding a series of items, where the term "and" or "or" separates any of the items, modifies the list as a whole, rather than each member (e.g., each item) of the list. The phrase "at least one" does not require the selection of at least one item; rather, the phrase allows for the inclusion of any one of the items, and / or at least one of any combination of the items, and / or at least one of each of the items. As an example, the phrase "at least one of A, B, and C" or "at least one of A, B, and C" refers to A only, B only, or C only, any combination of A, B, and C, and / or at least one of each of A, B, and C, respectively.

[0070] The word "exemplary" is used herein to mean "serving as an example, instance, or illustration." Any embodiment described herein as "exemplary" should not necessarily be construed as preferred or advantageous over other embodiments. Phrases such as "one aspect," "the aspect," "another aspect," "some aspects," "one or more aspects," "one implementation," "the implementation," "another implementation," "some implementations," "one or more implementations," "one embodiment," "the embodiment," "another embodiment," "some embodiments," "one or more embodiments," "one configuration," "the configuration," "another configuration," "some configurations," "one or more configurations," "subject technology," "disclosure," "the disclosure," and other variations thereof and similar expressions are used for convenience and do not imply that disclosure associated with such phrases is essential to the subject technology or that such disclosure applies to all configurations of the subject technology. Disclosure associated with such phrases may apply to all configurations, or to one or more configurations. Disclosure associated with such phrases may provide one or more examples. Phrases such as "aspects" and "some aspects" may refer to one or more aspects, and vice versa, as with other such phrases.

[0071] When referring to an element in the singular, it means "one or more," not "only one," unless specifically stated as "one." The term "some" refers to one or more. Underlined and / or italicized headings and subheadings are used for convenience only and do not limit the subject technology, and should not be referenced in connection with interpreting the description of the subject technology. Relational terms such as "first," "second," and the like may be used to distinguish one entity or operation from another, and do not necessarily require or imply an actual relationship or order between them. All structural and functional equivalents of the elements of the various configurations described throughout this disclosure, which are or later become known to those skilled in the art, are expressly incorporated herein by reference and are intended to be encompassed by the subject technology. Furthermore, nothing disclosed herein is intended to be made publicly available, regardless of whether such disclosure is expressly set forth in the above description. No claim element shall be construed under the provisions of 35 U.S.C. § 112, sixth paragraph, unless the element is expressly recited as "means for" (or, in the case of a method claim, as "step for").

[0072] While this specification contains many specific details, these should not be construed as limitations on the scope of the claimed invention, but rather as descriptions of particular embodiments of the subject matter. Certain features described in this specification in separate embodiments may also be implemented in combination in a single embodiment. Conversely, various features described in a single embodiment may also be implemented in multiple embodiments separately or in any suitable subcombination. Furthermore, even if features are described above as functioning in a particular combination and are initially claimed in such a combination, one or more features included in the claimed combination may, in some cases, be excluded from that combination, and the claims may therefore be directed to subcombinations or variations thereof.

[0073] Although the subject matter herein has been described in particular embodiments, other embodiments are possible and are within the scope of the following claims. For example, while acts are depicted in the figures in a particular order, this should not be understood as requiring that such acts be performed in the particular order or sequential order depicted, or that all of the depicted acts be performed, to achieve desirable results. The acts recited in the claims can be performed in a different order to achieve desirable results. As an example, the processes depicted in the accompanying figures do not necessarily require the particular order or sequential order depicted to achieve desirable results. In some situations, multitasking or parallel processing may be advantageous. Furthermore, the separation of various system components in the above-described embodiments should not be understood as requiring such separation in all embodiments, and it should be understood that the described program components and systems may generally be integrated together in a single software product or packaged in multiple software products.

[0074] The title, background, brief description of the drawings, abstract, and drawings are incorporated into this disclosure and are provided as examples, not as a limiting description of the disclosure. They are provided with the understanding that they will not be used to limit the scope or meaning of the claims. Furthermore, in the detailed description, it will be appreciated that the specification provides illustrative examples, and that various features are grouped together in various embodiments for the purpose of streamlining the disclosure. This method of disclosure should not be interpreted as reflecting an intention that the claimed subject matter requires more features than are expressly recited in each claim. Rather, as the claims reflect, inventive subject matter lies in less than all features of a single disclosed structure or operation. The claims are incorporated herein, with each claim standing on its own as independent claim subject matter.

[0075] The claims are not intended to be limited to the embodiments described herein, but are to be accorded full scope consistent with the language of the claims and encompass all legal equivalents. However, no claim is intended, and should not be interpreted, to cover subject matter that does not comply with applicable patent law requirements.

Claims

1. 1. A computer-implemented method comprising: receiving user data and access information for the managed device in response to communication between the managed device and the reader; identifying device information of the managed device associated with the user data and the access information; determining at least one mobile device action to perform on the managed device based on the device information, the user data, and the access information; In response to determining the at least one mobile device action, sending a message to a push notification service to initiate communication between the managed device and a mobile device management server; In response to the managed device communicating with the mobile device management server, sending a management command to the managed device to perform the at least one mobile device operation.

2. The computer-implemented method of claim 1 , wherein the receipt of the user data and the access information for the managed device is received by the mobile device management server.

3. The computer-implemented method of claim 2 , wherein the mobile device management server hosts the functionality of an integration server.

4. The computer-implemented method of claim 1 , wherein the receipt of the user data and the access information of the managed device is received by an integration server.

5. 2. The computer-implemented method of claim 1, wherein the at least one mobile device action is one of installing a device driver, location assistance, accessing a potentially sensitive network, configuring a Wi-Fi profile, restricting cellular data usage, identifying a virtual private network (VPN), changing a device configuration, restricting access to a protected area, turning off a device camera, and identifying a lunch location.

6. The computer-implemented method of claim 1 , wherein the managed device communicates with the reader wirelessly.

7. The computer-implemented method of claim 5 , wherein the managed device communicates with the reader via one of near field communications and Bluetooth.

8. 1. A computer-implemented method comprising: receiving user data and access information for the managed device in response to communication between the managed device and the reader; identifying device information of the managed device associated with the user data and the access information; determining a risk level of the managed device based on the device information, the user data, and the access information; In response to determining that the risk level is below a predetermined threshold, sending a risk command to an access management server to revoke access for the managed device.

9. The computer-implemented method of claim 8 , wherein the managed device communicates with the reader wirelessly.

10. 10. The computer-implemented method of claim 9, wherein the managed device communicates with the reader via one of near field communications and Bluetooth.

11. 10. The computer-implemented method of claim 8, wherein the user data and the access information of the managed device are received by a risk assessment service via the reader.

12. The computer-implemented method of claim 11 , wherein the identification of the device information of the managed device is performed by the risk assessment service.

13. The computer-implemented method of claim 12 , wherein the risk level of the managed device is determined by the risk assessment service.

14. 1. A computer-implemented method comprising: receiving user data and access information for the managed device in response to communication between the managed device and the reader; identifying device information of the managed device associated with the user data and the access information; determining at least one mobile device action to perform on the managed device based on the device information, the user data, and the access information; In response to identifying at least one mobile device action, authorizing an endpoint management service to perform the at least one mobile device action on the managed device.

15. 15. The computer-implemented method of claim 14, wherein receipt of the user data and the access information for the managed device is received by the mobile device management server.

16. The computer-implemented method of claim 15 , wherein the mobile device management server hosts the functionality of an integration server.

17. 15. The computer-implemented method of claim 14, wherein the receipt of the user data and the access information for the managed device is received by an integration server.

18. 15. The computer-implemented method of claim 14, wherein the at least one mobile device action is one of restricting certain websites, creating a data cap, and encrypting traffic with private access technology for certain services or apps.

19. The computer-implemented method of claim 14 , wherein the managed device communicates with the reader wirelessly.

20. 20. The computer-implemented method of claim 19, wherein the managed device communicates with the reader via one of near field communications and Bluetooth.