Adaptive Device Enrollment via Localized Security Policies

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Enterprise Mobility Management (EMM) and Mobile Device Management (MDM) systems are inefficient due to blanket enrollment requirements that do not account for varying security needs of different user groups and require a dedicated agent application for enrollment, which slows down the process and can discourage employees from enrolling.

Innovation Solution

The system dynamically determines enrollment requirements based on the user device's operating system and organizational group, allowing direct enrollment without an agent application when possible, and provides a portal application for streamlined enrollment and management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If blanket enrollment requirements are applied to all devices, then security needs are met, but employee productivity decreases due to unnecessary enrollment steps

Engineering Contradiction:
ImprovesecurityVSAvoidemployee productivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies different enrollment requirements to different organizational groups based on their specific security needs. High-security groups require full enrollment while low-security groups can use streamlined enrollment without dedicated agent applications, making the security approach localized to each group's actual requirements rather than applying a uniform blanket policy

Inventive Principle:
Principle #3Local quality

2Reliability

If a dedicated agent application is required for enrollment, then enrollment can be performed, but the enrollment process becomes slower and more complex

Engineering Contradiction:
Improveenrollment capabilityVSAvoidenrollment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts the dedicated agent application requirement from the enrollment process for low-security organizational groups. Instead of requiring all devices to download and install separate enrollment applications, the system allows streamlined enrollment through existing applications for groups that don't require full management capabilities, eliminating unnecessary steps and time loss

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent makes the enrollment system universal by enabling enrollment to occur through different pathways depending on needs: high-security groups use dedicated agent applications while low-security groups use existing applications. This multi-functionality allows the same enrollment infrastructure to serve both requirements without forcing all users through the more complex dedicated application path

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If dedicated agent applications are injected into the enrollment process, then device management is enabled, but device complexity increases

Engineering Contradiction:
Improvedevice management capabilityVSAvoidenrollment process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies device management complexity locally rather than universally. High-security organizational groups receive full device management capabilities through dedicated agent applications, while low-security groups receive streamlined management through existing applications, reducing the complexity burden on devices that don't require full management functionality

Inventive Principle:
Principle #3Local quality

4Reliability

If blanket enrollment requirements are applied, then security needs are met, but adaptability to different user groups decreases

Engineering Contradiction:
ImprovesecurityVSAvoidadaptability to different user groups
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent makes the enrollment system adaptive by applying localized security policies to different organizational groups. The system identifies which group a device belongs to and applies the appropriate enrollment requirements - full enrollment for high-security groups, streamlined enrollment for low-security groups - thereby adapting the security approach to each user group's actual needs rather than applying a one-size-fits-all policy

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP3669495B1Adaptive device enrollment
Publication Date: 2022.08.10 VMWARE INC
  • EP3669495B1 patent drawingFigure 1
  • EP3669495B1 patent drawingFigure 2
  • EP3669495B1 patent drawingFigure 2

AI summary

Examples described herein include systems and methods for dynamically determining enrollment requirements and enrolling a user device into a management system. The systems and methods can differ based on the type and version of operating system executing on the user device. With some operating systems, enrollment can be completed through a single application that performs other functionality, such providing single-sign-on access to enterprise resources. With other operating systems, enrollment can be completed by pausing the first application and requiring installation of an agent application to complete enrollment. The determination of how and when to enroll a user device can be done automatically and can be based on an organizational group to which the user belongs.