Authentication Server Policy Enforcement for Mobile Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Hand-held mobile devices often fail to adhere to corporate data security policies, making sensitive information susceptible to unauthorized access, especially if they are not password-protected and lost, allowing anyone to access corporate resources.

Innovation Solution

A system where a client device sends an access request to an authentication server, which determines compliance with administrative policies; if non-compliant, the server provides instructions for installing a client application to enforce policies, such as password protection and remote wiping, ensuring only compliant devices access administered resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If employees use personal mobile devices to access corporate resources, then accessibility and convenience are improved, but data security and policy compliance deteriorate

Engineering Contradiction:
ImproveaccessibilityVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an authentication server as an intermediary between mobile devices and corporate resources. This server acts as a mediator that evaluates device compliance with security policies before granting access, thereby maintaining both accessibility and data security. The authentication server receives access requests, assesses device attributes against policy requirements, and selectively permits or denies resource access based on compliance status.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If strict access control policies are enforced, then data security is improved, but ease of access and user convenience deteriorate

Engineering Contradiction:
Improvedata securityVSAvoidease of access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements self-service by enabling mobile devices to automatically assess their own compliance status with security policies. Devices can self-evaluate their security attributes (such as password protection, encryption status, and software versions) and present this information to the authentication server, eliminating the need for manual security checks and reducing user burden while maintaining strict security enforcement.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The authentication server performs preliminary compliance verification before granting access to corporate resources. By evaluating device attributes and policy compliance in advance of resource access, the system ensures security requirements are met beforehand, allowing seamless access for compliant devices without interrupting users during resource usage.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If devices must comply with security policies to access resources, then unauthorized access is prevented, but device complexity and compliance management deteriorate

Engineering Contradiction:
Improveaccess controlVSAvoidcompliance management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system applies partial compliance verification by focusing assessment on critical security attributes rather than requiring full device compliance with all possible policies. The authentication server evaluates specific security-relevant attributes (such as password protection and encryption) to determine access eligibility, avoiding overly complex comprehensive audits while maintaining effective access control for the most important security requirements.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP3605375B1Policy enforcement of client devices
Publication Date: 2022.12.07 GOOGLE LLC
  • EP3605375B1 patent drawingFigure 1
  • EP3605375B1 patent drawingFigure 2
  • EP3605375B1 patent drawingFigure 3

AI summary

A method may include sending, by a client device, an access request to an authentication server device. The access request may include a request to access an administered resource. The method may include in response to the client device not complying with an administrative policy associated with the administered resource, receiving, from the authentication server device, one or more instructions regarding installation of a client application, receiving, by the client device, a client application in accordance with the instructions, and installing the client application on the client device.