Device Management Broker for Multi-Domain App Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In a BYOD environment, managing applications and data across multiple management domains is complex due to limitations in existing technologies that allow only one device management server to manage a device, leading to conflicts and security concerns when multiple entities need to manage different apps and data sets on a shared device.
Innovation Solution
A device management broker system that delegates authority to multiple independent entities, allowing each to manage their respective apps and data without exposing it to other entities, using techniques such as app wrapping, enterprise containers, and secure data storage to maintain security and separate app lifecycles across different identities and domains.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a device allows only one device management server to manage it, then device management is simplified and conflicts are avoided, but multiple independent entities cannot manage different apps and data on the device
Solution Approach 1:
The patent segments device management authority into multiple independent management domains, where each domain can manage specific apps and data without interfering with others. This is achieved through creating separate management contexts that partition the device management space, allowing multiple entities to coexist with distinct control boundaries.
Solution Approach 2:
The patent introduces a device management broker as an intermediary layer between multiple management servers and the device. This broker receives management requests from multiple entities, routes them to appropriate apps or data, and coordinates conflicts, enabling multi-entity management while maintaining system simplicity.
2Adaptability or versatility
If multiple entities manage different apps and data on a device, then adaptability and versatility are improved, but device management complexity and security risks increase
Solution Approach 1:
The patent segments device management authority into multiple independent management domains, where each domain can manage specific apps and data without interfering with others. This is achieved through creating separate management contexts that partition the device management space, allowing multiple entities to coexist with distinct control boundaries.
Solution Approach 2:
The patent introduces a device management broker as an intermediary layer between multiple management servers and the device. This broker receives management requests from multiple entities, routes them to appropriate apps or data, and coordinates conflicts, enabling multi-entity management while maintaining system simplicity.
3Adaptability or versatility
If multiple entities manage different apps and data on a device, then adaptability is improved, but security and privacy protection become more difficult
Solution Approach 1:
The patent segments device management authority into multiple independent management domains, where each domain can manage specific apps and data without interfering with others. This is achieved through creating separate management contexts that partition the device management space, allowing multiple entities to coexist with distinct control boundaries.
Solution Approach 2:
The patent applies local quality by giving each management entity authority only over specific apps and data within its designated domain, while other entities have no access. This localized authority ensures that security policies can be tailored to each entity's needs and that privacy is protected by limiting each entity's scope to only what it requires.
Data Source
AI summary
Techniques to manage applications, such as mobile apps, across multiple management domains are disclosed. In various embodiments, a set of one or more application management policies to be enforced with respect to a mobile device is received from a management entity to which a scope of authority to manage applications with respect to the mobile device has been delegated. A management agent on the mobile device is used to enforce the one or more application management policies with respect to applications and application data that are within the scope of authority delegated to the management entity.


