Adaptive Offline Policy Enforcement for BYOD Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for enforcing enterprise security policies on client devices in a BYOD environment require a network connection to a management system, limiting flexibility and effectiveness, especially in situations without reliable network access.

Innovation Solution

The implementation of adaptive offline policies that adjust the stringency of software and hardware restrictions on client devices based on situational contexts, such as location and usage patterns, without the need for a network connection or management agent, allowing for local enforcement of security measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If enterprise security policies are enforced on client devices through a management system, then security control is improved, but network connectivity requirement increases system complexity and reduces adaptability

Engineering Contradiction:
Improvesecurity controlVSAvoidoffline operation capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies preliminary action by pre-configuring security policies and restrictions on the client device before network disconnection occurs. The device stores security policy definitions and context data locally, enabling it to enforce security measures offline without needing real-time management system communication.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The client device is empowered to autonomously evaluate its own context (location, device state, user identity) and enforce appropriate security policies without external intervention. The device independently determines whether to apply restrictions based on pre-configured policies and current context, eliminating the need for continuous network connectivity to a management system.

Inventive Principle:
Principle #25Self-service

2Device complexity

If binary security policies are applied to client devices, then security enforcement is simplified, but flexibility to adapt to different situations is reduced

Engineering Contradiction:
Improvepolicy enforcement mechanismVSAvoidsituational adaptability
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic security policies that automatically adjust restriction stringency based on the client device's evaluated context. Instead of fixed binary policies, the system dynamically modifies security measures according to situational factors such as location, device state, and user identity, allowing the same policy framework to adapt to different scenarios without manual intervention.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes security parameters (restriction stringency levels) based on context evaluation results. The client device adjusts policy enforcement parameters dynamically, transitioning between different security states (e.g., from permissive to restrictive) according to evaluated context conditions, enabling flexible adaptation while maintaining a relatively simple underlying policy structure.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11736529B2Adaptive offline policy enforcement based on coniext
Publication Date: 2023.08.22 OMNISSA LLC
  • US11736529B2 patent drawing
  • US11736529B2 patent drawing
  • US11736529B2 patent drawing

AI summary

Disclosed are various examples that relate to adjusting a stringency of offline policy restrictions based on a situational context of a computing device. In one example, a system can receive an offline restriction policy for an application. The system can identify a request to execute an application during the offline period of time. A situational context of the computing device can be determined. A first application restriction can be enforced for the application on the computing device based on the identification of the computing device being in the offline period of time and the situational context. A change in the situational context of the computing device can be identified during the offline period of time based on a detection of a second condition. A second application restriction can be enforced for the application on the computing device during the offline period of time.