Certificate Enrollment for Unmanaged App Communication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile device management platforms struggle to ensure secure inter-application communications, especially between applications that are not fully enrolled for management, as they rely on both applications being managed, which poses challenges for unmanaged applications.
Innovation Solution
The approach employs certificate enrollment to enable secure communication between unmanaged and managed applications using a management agent that verifies identities, obtains and manages certificates, and facilitates secure data sharing through a cloud sharing service with TLS mutual authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If mobile device management platforms use traditional management mechanisms requiring both applications to be enrolled, then secure communication between managed applications is achieved, but unmanaged applications cannot participate in secure communication
Solution Approach 1:
The patent introduces a management agent as an intermediary component that runs within the unmanaged application process. This agent acts as a bridge, allowing the unmanaged application to participate in secure communication without requiring full enrollment. The management agent handles certificate enrollment and communication management, enabling the unmanaged application to securely communicate with other managed applications while maintaining its unmanaged status.
Solution Approach 2:
The patent segments the management functionality from the application itself by introducing a separate management agent component. This segmentation allows the unmanaged application to retain its independence while the management agent handles security-related tasks. The management agent can be independently enrolled and managed, while the unmanaged application continues to operate without full management enrollment.
2Ease of operation
If both applications must be fully enrolled for secure communication, then comprehensive management control is maintained, but the system loses flexibility to work with unmanaged applications
Solution Approach 1:
The management agent enables the unmanaged application to self-enroll for certificate-based security without requiring full management enrollment. The agent can automatically obtain certificates and configure security settings, allowing the unmanaged application to participate in secure communication with minimal intervention. This self-service capability simplifies integration while maintaining security standards.
3Reliability
If traditional certificate enrollment is used requiring full management enrollment, then strong authentication is established, but unmanaged applications are excluded from secure communication
Solution Approach 1:
The management agent serves as an intermediary that handles certificate enrollment and authentication on behalf of the unmanaged application. This allows the unmanaged application to obtain strong cryptographic authentication without requiring full management enrollment. The agent manages the certificate lifecycle, including enrollment, storage, and usage, maintaining strong authentication while enabling participation from unmanaged applications.
Data Source
AI summary
Disclosed are various approaches for secure inter-application communication with unmanaged applications using certificate enrollment. A certificate signing request can be received from an unmanaged application via an inter-application communication method supported by an operating system of a computing device, and an identity of the unmanaged application can be verified. The certificate signing request can be provided to a certifying authority, and a certificate can be received from the certifying authority. The certificate can be provided to the unmanaged application.


