Bootstrap Loader for Automatic EMM Enrollment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In the PC ecosystem, there is no centralized method for easily enrolling computing devices into Enterprise Mobility Management (EMM) systems, tracking device ownership, or configuring operating systems and applications uniformly, leading to inefficient and resource-intensive initial setup processes, security vulnerabilities, and difficulties in managing device configurations and ownership.

Innovation Solution

The implementation of a bootstrap loader in the firmware of computing devices, which enables automatic enrollment with an EMM server upon first boot, allowing for the initialization of hardware, loading of the operating system, and installation of management agents and policies before user login, using a Windows Platform Binary Table (WPBT) to connect to a server for necessary software and configurations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If manual device setup and enrollment processes are used in the PC ecosystem, then administrators can configure individual devices, but the process becomes time-consuming and resource-intensive

Engineering Contradiction:
Improvedevice setup processVSAvoidinitial setup time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent implements preliminary action by enabling automatic device enrollment and configuration to occur during the boot process before the operating system fully loads. The bootstrap loader executes enrollment code that communicates with EMM servers to provision devices automatically, eliminating the need for manual administrator intervention during initial setup.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies self-service by designing a system where computing devices automatically enroll with EMM servers and configure themselves without requiring manual administrator actions. The device uses its unique identifier to autonomously retrieve enrollment tokens and configuration data, performing self-provisioning during the boot process.

Inventive Principle:
Principle #25Self-service

2Reliability

If administrators manually enroll each device with EMM system, then device security can be ensured, but IT manpower requirements increase

Engineering Contradiction:
Improvedevice securityVSAvoidIT manpower efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements self-service by enabling devices to automatically enroll with EMM servers using their unique identifiers. The bootstrap loader executes code that autonomously communicates with EMM servers to obtain enrollment tokens and configure security policies, eliminating the need for administrator intervention while maintaining security enforcement.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent applies preliminary action by performing security enrollment and policy configuration during the boot process before the operating system becomes fully operational. This ensures security measures are in place prior to user access, maintaining reliability while automating the process to improve IT productivity.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If device configurations are customized by OEMs, then device-specific optimizations can be achieved, but tracking configuration evolution becomes impractical

Engineering Contradiction:
Improvedevice configuration flexibilityVSAvoidconfiguration tracking
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary EMM server that acts as a mediator between diverse device configurations and centralized management. The server receives enrollment requests from devices with various configurations, processes them through a standardized protocol using unique device identifiers, and returns appropriate enrollment tokens and policy data, thereby simplifying the tracking of configuration evolution.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies universality by designing a standardized enrollment mechanism that works across diverse PC device configurations from different OEMs. The bootstrap loader and EMM server interaction uses a universal protocol that adapts to different hardware and software configurations without requiring OEM-specific customization logic, simplifying configuration tracking.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Ease of operation

If users can login to OS before EMM enrollment, then user access is enabled, but security policies may be circumvented

Engineering Contradiction:
Improveuser accessVSAvoidsecurity policy enforcement
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements preliminary action by reversing the traditional sequence: EMM enrollment and security policy installation occur during the boot process before the operating system allows user login. The bootstrap loader executes enrollment code that provisions security measures prior to user access, preventing policy circumvention while enabling subsequent user operations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10635819B2Persistent enrollment of a computing device based on a temporary user
Publication Date: 2020.04.28 OMNISSA LLC
  • US10635819B2 patent drawing
  • US10635819B2 patent drawing
  • US10635819B2 patent drawing

AI summary

Systems and methods are included for causing a computing device to implement a management policy prior to a user logging into an operating system on initial boot. As part of initial boot, the computing device contacts a management server for enrollment. Installation of the operating system is paused while the management server synchronizes the software and policies on the computing device. To do this prior to login, the management server can create a temporary user account to associate with the computing device and apply a default management policy. After the installation is complete, an installed management agent can gather user inputs made during login. The management agent can send these inputs to the management server for use in creating an actual user account to associate with the computing device.